{
  "type": "URL",
  "indicator": "https://www.joesecurity.org",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.joesecurity.org",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "whitelist",
        "message": "Whitelisted domain joesecurity.org",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3740027004,
      "indicator": "https://www.joesecurity.org",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "69d5f56a5f13dc6c5bd93c0e",
          "name": "WIN EXE. Run Sandboxed",
          "description": "The full text of the report on the Google server, published on 1 January 2018, has been published online by the internet service provider, ICann.com, for the first time in its history.",
          "modified": "2026-05-08T07:38:32.166000",
          "created": "2026-04-08T06:27:54.699000",
          "tags": [
            "win32",
            "as15169 google",
            "united",
            "status",
            "mtb jan",
            "mtb mar",
            "mtb feb",
            "name servers",
            "aaaa",
            "passive dns",
            "date",
            "trojan"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 283,
            "FileHash-SHA1": 279,
            "FileHash-SHA256": 620,
            "email": 6,
            "URL": 353,
            "domain": 198,
            "hostname": 287,
            "CVE": 16
          },
          "indicator_count": 2042,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "23 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66b8fe985a7460e0ee01be8a",
          "name": "r3.o.lencr.org",
          "description": "",
          "modified": "2024-08-11T18:14:13.378000",
          "created": "2024-08-11T18:10:32.276000",
          "tags": [
            "as20940",
            "united",
            "trojan",
            "search",
            "passive dns",
            "urls",
            "entries",
            "dashboard",
            "browse scan",
            "endpoints all",
            "date",
            "a domains",
            "aaaa",
            "record value",
            "scan endpoints",
            "all search",
            "otx octoseek",
            "domain related",
            "showing"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "64dc045f5344129c48c41826",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 664,
            "email": 13,
            "hostname": 1352,
            "FileHash-SHA256": 2550,
            "URL": 5422,
            "FileHash-MD5": 761,
            "FileHash-SHA1": 615
          },
          "indicator_count": 11377,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "658 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64dc045f5344129c48c41826",
          "name": "r3.o.lencr.org",
          "description": "Malware. R3.o.lencr.org is a browser-redirecting app aka browser hijacking, that attaches itself to main browser in devices. Ability to take control over some settings. Tracker. Scammers use Lencr.org/ LetsEncrypt in websites that have  malicious content and activities. \nMalicious Activity:\nALF:Trojan:Win32/Cassini_f9070846!ibt\nALFPER:CERT:SoftwareBundler:Win32/InstallMonetizer\nTrojan:Win32/Dorv.A!rfn\nTrojan:Win32/Prepscram\nTrojan:Win32/Zbot.SIBG!MTB\nTrojanDownloader:Win32/Banload\nTrojanDownloader:Win32/Upatre.D\nTrojanDownloader:Win32/Upatre.J\nWin.Downloader.Mailru-9797354-1\nWin.Dropper.Agent-185636\nRiskware\nMalicious Adware spamming \n\n(Auto Generated Description: A complete list of malicious files has been published on the website of Cloudflare.com, the company that provides access to the service for users who use its services to access their email addresses.)",
          "modified": "2023-09-15T04:05:29.096000",
          "created": "2023-08-15T23:03:59.403000",
          "tags": [
            "as20940",
            "united",
            "trojan",
            "search",
            "passive dns",
            "urls",
            "entries",
            "dashboard",
            "browse scan",
            "endpoints all",
            "date",
            "a domains",
            "aaaa",
            "record value",
            "scan endpoints",
            "all search",
            "otx octoseek",
            "domain related",
            "showing"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 664,
            "email": 13,
            "hostname": 1352,
            "FileHash-SHA256": 1750,
            "URL": 5422,
            "FileHash-MD5": 207,
            "FileHash-SHA1": 61
          },
          "indicator_count": 9469,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "989 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 7315
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/joesecurity.org",
    "whois": "http://whois.domaintools.com/joesecurity.org",
    "domain": "joesecurity.org",
    "hostname": "www.joesecurity.org"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "69d5f56a5f13dc6c5bd93c0e",
      "name": "WIN EXE. Run Sandboxed",
      "description": "The full text of the report on the Google server, published on 1 January 2018, has been published online by the internet service provider, ICann.com, for the first time in its history.",
      "modified": "2026-05-08T07:38:32.166000",
      "created": "2026-04-08T06:27:54.699000",
      "tags": [
        "win32",
        "as15169 google",
        "united",
        "status",
        "mtb jan",
        "mtb mar",
        "mtb feb",
        "name servers",
        "aaaa",
        "passive dns",
        "date",
        "trojan"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 283,
        "FileHash-SHA1": 279,
        "FileHash-SHA256": 620,
        "email": 6,
        "URL": 353,
        "domain": 198,
        "hostname": 287,
        "CVE": 16
      },
      "indicator_count": 2042,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "23 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66b8fe985a7460e0ee01be8a",
      "name": "r3.o.lencr.org",
      "description": "",
      "modified": "2024-08-11T18:14:13.378000",
      "created": "2024-08-11T18:10:32.276000",
      "tags": [
        "as20940",
        "united",
        "trojan",
        "search",
        "passive dns",
        "urls",
        "entries",
        "dashboard",
        "browse scan",
        "endpoints all",
        "date",
        "a domains",
        "aaaa",
        "record value",
        "scan endpoints",
        "all search",
        "otx octoseek",
        "domain related",
        "showing"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "64dc045f5344129c48c41826",
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 664,
        "email": 13,
        "hostname": 1352,
        "FileHash-SHA256": 2550,
        "URL": 5422,
        "FileHash-MD5": 761,
        "FileHash-SHA1": 615
      },
      "indicator_count": 11377,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "658 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "64dc045f5344129c48c41826",
      "name": "r3.o.lencr.org",
      "description": "Malware. R3.o.lencr.org is a browser-redirecting app aka browser hijacking, that attaches itself to main browser in devices. Ability to take control over some settings. Tracker. Scammers use Lencr.org/ LetsEncrypt in websites that have  malicious content and activities. \nMalicious Activity:\nALF:Trojan:Win32/Cassini_f9070846!ibt\nALFPER:CERT:SoftwareBundler:Win32/InstallMonetizer\nTrojan:Win32/Dorv.A!rfn\nTrojan:Win32/Prepscram\nTrojan:Win32/Zbot.SIBG!MTB\nTrojanDownloader:Win32/Banload\nTrojanDownloader:Win32/Upatre.D\nTrojanDownloader:Win32/Upatre.J\nWin.Downloader.Mailru-9797354-1\nWin.Dropper.Agent-185636\nRiskware\nMalicious Adware spamming \n\n(Auto Generated Description: A complete list of malicious files has been published on the website of Cloudflare.com, the company that provides access to the service for users who use its services to access their email addresses.)",
      "modified": "2023-09-15T04:05:29.096000",
      "created": "2023-08-15T23:03:59.403000",
      "tags": [
        "as20940",
        "united",
        "trojan",
        "search",
        "passive dns",
        "urls",
        "entries",
        "dashboard",
        "browse scan",
        "endpoints all",
        "date",
        "a domains",
        "aaaa",
        "record value",
        "scan endpoints",
        "all search",
        "otx octoseek",
        "domain related",
        "showing"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 664,
        "email": 13,
        "hostname": 1352,
        "FileHash-SHA256": 1750,
        "URL": 5422,
        "FileHash-MD5": 207,
        "FileHash-SHA1": 61
      },
      "indicator_count": 9469,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "989 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.joesecurity.org",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.joesecurity.org",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780286167.6736164
}