{
  "type": "URL",
  "indicator": "https://www.microsoft.com/en",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.microsoft.com/en",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "alexa",
        "message": "Alexa rank: #19",
        "name": "Listed on Alexa"
      },
      {
        "source": "akamai",
        "message": "Akamai rank: #4",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "whitelist",
        "message": "Whitelisted domain microsoft.com",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain microsoft.com",
        "name": "Whitelisted domain"
      },
      {
        "source": "newssite",
        "message": "Whitelisted news domain microsoft.com",
        "name": "Whitelisted newssite network domain"
      }
    ],
    "base_indicator": {
      "id": 3881749041,
      "indicator": "https://www.microsoft.com/en",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "69f3f6fc9ae9b2297964a5a4",
          "name": "VirusTotal report          for Test.docx + Other Civic Findings/CVE Linkings",
          "description": "1. CivicPlus.com Threat IndicatorsVT Status: Red Flagged [120+ references, 200+android APKS and tracking configs[js]].Suspicious MD5: 3f307fecb41ea75bb946e8fde73a3c36b548243411783c036a1e7ae6605e8223.Suspicious SHA1: 0ef5ceebb6efa99e12e888a993e56d557dff07fd.Behavioral Pattern: Multiple versions flagged with No Expiration (indicates persistent or hard-coded malicious components in related files).2. HitmanPro Findings (Feb 2025)File Action: Detected as Malware/Suspicious in C:\\Windows\\Installer and user data areas.Note: Typical of behavioral scanning identifying code injection or untrusted signatures, often flagged alongside browser data.3. SSO Autodesk Anomalies (Q1 2025)SAML Assertion Failure: Incorrect objectGUID mapping on IdP side, sending user.objectid as literal string instead of unique identifier. Potential credential abuse or IdP misconfiguration - Attached [Reportscivicplus_vt_red_flag_feb2025.loghmp_scan_022025] + test.docx which shows signs that resemble a test recall email.",
          "modified": "2026-05-31T05:19:13.706000",
          "created": "2026-05-01T00:42:36.613000",
          "tags": [
            "medium",
            "windows",
            "high",
            "alerts",
            "yara detections",
            "worm",
            "https domain",
            "tls sni",
            "io control",
            "installs",
            "virustotal",
            "copy",
            "explorer",
            "malware",
            "config by town",
            "civicplus",
            "beyond surveillance",
            "significant overreach"
          ],
          "references": [
            "multiple_versions\tSHA1 of 3f307fecb41ea75bb946e8fde73a3c36b548243411783c036a1e7ae6605e8223\tNo Expiration",
            "",
            "CVE-2025-10898/10899/10900: Out-of-Bounds Write vulnerabilities found in parsed MODEL files.",
            "More elaborate 'text' exploits now exist that allow texts are now being distributed via ai drops in chats in the form of what would appear to be a hyperlink. This is a new genre of elevation in exploit.",
            "The 'test' email aligns perfectly with CVE-2022-30190, as indicated in my findings"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1010,
            "FileHash-SHA1": 437,
            "FileHash-SHA256": 2319,
            "URL": 637,
            "email": 14,
            "hostname": 468,
            "domain": 101,
            "CVE": 9
          },
          "indicator_count": 4995,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "10 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "667af85fe8fea6365adaa65d",
          "name": "Norton & Norton Lifelock Products",
          "description": "Just taking a pak at some Norton-Related Problems\n(03.11.24): https://www.virustotal.com/graph/embed/g8619c830b2c24d849472aef95a362ce113e12cd6d68849e7a83c7eca387a378a?theme=dark",
          "modified": "2024-09-29T20:01:29.028000",
          "created": "2024-06-25T17:03:27.155000",
          "tags": [
            "entity",
            "please",
            "javascript",
            "xwwmwh4cg2hpw"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g8619c830b2c24d849472aef95a362ce113e12cd6d68849e7a83c7eca387a378a?theme=dark",
            "https://www.virustotal.com/gui/collection/aabd4abecf7099202ccbfbc1cec130ea266329ade38b040169399c6abf97a188/summary",
            "https://www.virustotal.com/gui/collection/aabd4abecf7099202ccbfbc1cec130ea266329ade38b040169399c6abf97a188/iocs",
            "https://www.virustotal.com/gui/collection/aabd4abecf7099202ccbfbc1cec130ea266329ade38b040169399c6abf97a188/graph",
            "08.30.24: e1ec7ebd4046143153dd28dd2b5a54cf34edd137c6288f4e56c6449f0753a986 (VT)",
            "08.30.24: Report ID: \t 6a27e451-df79-4f90-a022-9aa15cb58cea (Filescanio)"
          ],
          "public": 1,
          "adversary": "Norton Norton Lifelock Telus",
          "targeted_countries": [
            "Canada",
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Technology",
            "Telecommunications"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 50,
            "FileHash-SHA1": 54,
            "FileHash-SHA256": 831,
            "URL": 1120,
            "domain": 181,
            "hostname": 261
          },
          "indicator_count": 2497,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 131,
          "modified_text": "608 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a4d15c60edc83ca6bfc97e",
          "name": "Fraud Services, Updates, Network Worm, SpyWare - Misc Attack",
          "description": "",
          "modified": "2024-08-26T10:04:37.360000",
          "created": "2024-07-27T10:52:12.501000",
          "tags": [
            "united",
            "unknown",
            "a domains",
            "search",
            "creation date",
            "record value",
            "cyberlynk",
            "date",
            "expiration date",
            "title",
            "encrypt",
            "body",
            "as54113",
            "aaaa",
            "cname",
            "next",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr3",
            "validity",
            "subject public",
            "key info",
            "key algorithm",
            "files",
            "type name",
            "android",
            "server",
            "registrar abuse",
            "dnssec",
            "domain name",
            "contact phone",
            "registrar url",
            "registrar whois",
            "registrar",
            "llc registry",
            "code",
            "key identifier",
            "subject key",
            "identifier",
            "x509v3 key",
            "first",
            "dns replication",
            "historical ssl",
            "no data",
            "tag count",
            "fakedout threat",
            "analyzer threat",
            "url summary",
            "ip summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "heur",
            "cisco umbrella",
            "site",
            "malware",
            "safe site",
            "million",
            "alexa top",
            "malicious site",
            "phishing site",
            "suspected",
            "unsafe",
            "wacatac",
            "artemis",
            "iframe",
            "presenoker",
            "phishing",
            "opencandy",
            "downldr",
            "cleaner",
            "conduit",
            "riskware",
            "nircmd",
            "swrort",
            "tiggre",
            "agent",
            "filetour",
            "fusioncore",
            "unruy",
            "crack",
            "exploit",
            "cobalt strike",
            "xrat",
            "alexa",
            "acint",
            "systweak",
            "behav",
            "genkryptik",
            "blacknet rat",
            "stealer",
            "installpack",
            "azorult",
            "service",
            "runescape",
            "facebook",
            "bank",
            "download",
            "zbot",
            "xtrat",
            "installcore",
            "patcher",
            "adload",
            "win64",
            "class",
            "twitter",
            "accept",
            "malware site",
            "maltiverse",
            "ransomware",
            "phishingms",
            "anonymisation",
            "suppobox",
            "emotet",
            "revengerat",
            "downloader",
            "emailworm",
            "ramnit",
            "warbot",
            "citadel",
            "zeus",
            "simda",
            "keitaro",
            "virut",
            "team",
            "cultureneutral",
            "get na",
            "show",
            "delete c",
            "delete",
            "yara detections",
            "copy",
            "nivdort",
            "write",
            "trojanspy",
            "bayrob",
            "intel",
            "ms windows",
            "default",
            "pe32 executable",
            "document file",
            "v2 document",
            "pe32",
            "worm",
            "entries",
            "td td",
            "rufus",
            "mtb apr",
            "servers",
            "as39122",
            "span",
            "github pages",
            "passive dns",
            "formbook cnc",
            "checkin",
            "dridex",
            "request",
            "less see",
            "http request",
            "status",
            "name servers",
            "certificate",
            "urls",
            "div div",
            "header click",
            "meta",
            "homepage",
            "form",
            "date hash",
            "avast avg",
            "backdoor",
            "mtb jul",
            "as36459",
            "scan endpoints",
            "all scoreblue",
            "ipv4",
            "pulse pulses",
            "sha256",
            "sha1",
            "ascii text",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "misc attack",
            "pattern match",
            "null",
            "hybrid",
            "refresh",
            "general",
            "local",
            "click",
            "strings",
            "error",
            "tools",
            "look",
            "verify",
            "restart",
            "contact",
            "suspicious",
            "windows nt",
            "apache",
            "path",
            "pragma",
            "footer",
            "as8068",
            "as8075",
            "as15169 google",
            "as16552 tiggee",
            "virtool",
            "related pulses",
            "file samples",
            "files matching",
            "showing",
            "domain",
            "as22612",
            "as397240",
            "as19527 google",
            "moved",
            "gmt server",
            "as20940",
            "as4230 claro",
            "trojan",
            "ninite",
            "as2914 ntt",
            "win32",
            "brazil unknown",
            "brazil",
            "invalid url",
            "trojandropper",
            "body html",
            "head title",
            "asnone united",
            "as23393"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Brazil",
            "India"
          ],
          "malware_families": [
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 46,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1034,
            "domain": 1210,
            "email": 13,
            "hostname": 1031,
            "FileHash-SHA1": 685,
            "FileHash-SHA256": 1036,
            "FileHash-MD5": 927,
            "CVE": 10
          },
          "indicator_count": 5946,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 234,
          "modified_text": "643 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "multiple_versions\tSHA1 of 3f307fecb41ea75bb946e8fde73a3c36b548243411783c036a1e7ae6605e8223\tNo Expiration",
        "https://www.virustotal.com/graph/embed/g8619c830b2c24d849472aef95a362ce113e12cd6d68849e7a83c7eca387a378a?theme=dark",
        "08.30.24: Report ID: \t 6a27e451-df79-4f90-a022-9aa15cb58cea (Filescanio)",
        "https://www.virustotal.com/gui/collection/aabd4abecf7099202ccbfbc1cec130ea266329ade38b040169399c6abf97a188/summary",
        "https://www.virustotal.com/gui/collection/aabd4abecf7099202ccbfbc1cec130ea266329ade38b040169399c6abf97a188/graph",
        "CVE-2025-10898/10899/10900: Out-of-Bounds Write vulnerabilities found in parsed MODEL files.",
        "https://www.virustotal.com/gui/collection/aabd4abecf7099202ccbfbc1cec130ea266329ade38b040169399c6abf97a188/iocs",
        "More elaborate 'text' exploits now exist that allow texts are now being distributed via ai drops in chats in the form of what would appear to be a hyperlink. This is a new genre of elevation in exploit.",
        "08.30.24: e1ec7ebd4046143153dd28dd2b5a54cf34edd137c6288f4e56c6449f0753a986 (VT)",
        "The 'test' email aligns perfectly with CVE-2022-30190, as indicated in my findings"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "Norton Norton Lifelock Telus"
          ],
          "malware_families": [
            "Dridex"
          ],
          "industries": [
            "Technology",
            "Telecommunications"
          ],
          "unique_indicators": 10586
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/microsoft.com",
    "whois": "http://whois.domaintools.com/microsoft.com",
    "domain": "microsoft.com",
    "hostname": "www.microsoft.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "69f3f6fc9ae9b2297964a5a4",
      "name": "VirusTotal report          for Test.docx + Other Civic Findings/CVE Linkings",
      "description": "1. CivicPlus.com Threat IndicatorsVT Status: Red Flagged [120+ references, 200+android APKS and tracking configs[js]].Suspicious MD5: 3f307fecb41ea75bb946e8fde73a3c36b548243411783c036a1e7ae6605e8223.Suspicious SHA1: 0ef5ceebb6efa99e12e888a993e56d557dff07fd.Behavioral Pattern: Multiple versions flagged with No Expiration (indicates persistent or hard-coded malicious components in related files).2. HitmanPro Findings (Feb 2025)File Action: Detected as Malware/Suspicious in C:\\Windows\\Installer and user data areas.Note: Typical of behavioral scanning identifying code injection or untrusted signatures, often flagged alongside browser data.3. SSO Autodesk Anomalies (Q1 2025)SAML Assertion Failure: Incorrect objectGUID mapping on IdP side, sending user.objectid as literal string instead of unique identifier. Potential credential abuse or IdP misconfiguration - Attached [Reportscivicplus_vt_red_flag_feb2025.loghmp_scan_022025] + test.docx which shows signs that resemble a test recall email.",
      "modified": "2026-05-31T05:19:13.706000",
      "created": "2026-05-01T00:42:36.613000",
      "tags": [
        "medium",
        "windows",
        "high",
        "alerts",
        "yara detections",
        "worm",
        "https domain",
        "tls sni",
        "io control",
        "installs",
        "virustotal",
        "copy",
        "explorer",
        "malware",
        "config by town",
        "civicplus",
        "beyond surveillance",
        "significant overreach"
      ],
      "references": [
        "multiple_versions\tSHA1 of 3f307fecb41ea75bb946e8fde73a3c36b548243411783c036a1e7ae6605e8223\tNo Expiration",
        "",
        "CVE-2025-10898/10899/10900: Out-of-Bounds Write vulnerabilities found in parsed MODEL files.",
        "More elaborate 'text' exploits now exist that allow texts are now being distributed via ai drops in chats in the form of what would appear to be a hyperlink. This is a new genre of elevation in exploit.",
        "The 'test' email aligns perfectly with CVE-2022-30190, as indicated in my findings"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1010,
        "FileHash-SHA1": 437,
        "FileHash-SHA256": 2319,
        "URL": 637,
        "email": 14,
        "hostname": 468,
        "domain": 101,
        "CVE": 9
      },
      "indicator_count": 4995,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "10 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "667af85fe8fea6365adaa65d",
      "name": "Norton & Norton Lifelock Products",
      "description": "Just taking a pak at some Norton-Related Problems\n(03.11.24): https://www.virustotal.com/graph/embed/g8619c830b2c24d849472aef95a362ce113e12cd6d68849e7a83c7eca387a378a?theme=dark",
      "modified": "2024-09-29T20:01:29.028000",
      "created": "2024-06-25T17:03:27.155000",
      "tags": [
        "entity",
        "please",
        "javascript",
        "xwwmwh4cg2hpw"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/g8619c830b2c24d849472aef95a362ce113e12cd6d68849e7a83c7eca387a378a?theme=dark",
        "https://www.virustotal.com/gui/collection/aabd4abecf7099202ccbfbc1cec130ea266329ade38b040169399c6abf97a188/summary",
        "https://www.virustotal.com/gui/collection/aabd4abecf7099202ccbfbc1cec130ea266329ade38b040169399c6abf97a188/iocs",
        "https://www.virustotal.com/gui/collection/aabd4abecf7099202ccbfbc1cec130ea266329ade38b040169399c6abf97a188/graph",
        "08.30.24: e1ec7ebd4046143153dd28dd2b5a54cf34edd137c6288f4e56c6449f0753a986 (VT)",
        "08.30.24: Report ID: \t 6a27e451-df79-4f90-a022-9aa15cb58cea (Filescanio)"
      ],
      "public": 1,
      "adversary": "Norton Norton Lifelock Telus",
      "targeted_countries": [
        "Canada",
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Technology",
        "Telecommunications"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 50,
        "FileHash-SHA1": 54,
        "FileHash-SHA256": 831,
        "URL": 1120,
        "domain": 181,
        "hostname": 261
      },
      "indicator_count": 2497,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 131,
      "modified_text": "608 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66a4d15c60edc83ca6bfc97e",
      "name": "Fraud Services, Updates, Network Worm, SpyWare - Misc Attack",
      "description": "",
      "modified": "2024-08-26T10:04:37.360000",
      "created": "2024-07-27T10:52:12.501000",
      "tags": [
        "united",
        "unknown",
        "a domains",
        "search",
        "creation date",
        "record value",
        "cyberlynk",
        "date",
        "expiration date",
        "title",
        "encrypt",
        "body",
        "as54113",
        "aaaa",
        "cname",
        "next",
        "algorithm",
        "data",
        "v3 serial",
        "number",
        "cus olet",
        "encrypt cnr3",
        "validity",
        "subject public",
        "key info",
        "key algorithm",
        "files",
        "type name",
        "android",
        "server",
        "registrar abuse",
        "dnssec",
        "domain name",
        "contact phone",
        "registrar url",
        "registrar whois",
        "registrar",
        "llc registry",
        "code",
        "key identifier",
        "subject key",
        "identifier",
        "x509v3 key",
        "first",
        "dns replication",
        "historical ssl",
        "no data",
        "tag count",
        "fakedout threat",
        "analyzer threat",
        "url summary",
        "ip summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "heur",
        "cisco umbrella",
        "site",
        "malware",
        "safe site",
        "million",
        "alexa top",
        "malicious site",
        "phishing site",
        "suspected",
        "unsafe",
        "wacatac",
        "artemis",
        "iframe",
        "presenoker",
        "phishing",
        "opencandy",
        "downldr",
        "cleaner",
        "conduit",
        "riskware",
        "nircmd",
        "swrort",
        "tiggre",
        "agent",
        "filetour",
        "fusioncore",
        "unruy",
        "crack",
        "exploit",
        "cobalt strike",
        "xrat",
        "alexa",
        "acint",
        "systweak",
        "behav",
        "genkryptik",
        "blacknet rat",
        "stealer",
        "installpack",
        "azorult",
        "service",
        "runescape",
        "facebook",
        "bank",
        "download",
        "zbot",
        "xtrat",
        "installcore",
        "patcher",
        "adload",
        "win64",
        "class",
        "twitter",
        "accept",
        "malware site",
        "maltiverse",
        "ransomware",
        "phishingms",
        "anonymisation",
        "suppobox",
        "emotet",
        "revengerat",
        "downloader",
        "emailworm",
        "ramnit",
        "warbot",
        "citadel",
        "zeus",
        "simda",
        "keitaro",
        "virut",
        "team",
        "cultureneutral",
        "get na",
        "show",
        "delete c",
        "delete",
        "yara detections",
        "copy",
        "nivdort",
        "write",
        "trojanspy",
        "bayrob",
        "intel",
        "ms windows",
        "default",
        "pe32 executable",
        "document file",
        "v2 document",
        "pe32",
        "worm",
        "entries",
        "td td",
        "rufus",
        "mtb apr",
        "servers",
        "as39122",
        "span",
        "github pages",
        "passive dns",
        "formbook cnc",
        "checkin",
        "dridex",
        "request",
        "less see",
        "http request",
        "status",
        "name servers",
        "certificate",
        "urls",
        "div div",
        "header click",
        "meta",
        "homepage",
        "form",
        "date hash",
        "avast avg",
        "backdoor",
        "mtb jul",
        "as36459",
        "scan endpoints",
        "all scoreblue",
        "ipv4",
        "pulse pulses",
        "sha256",
        "sha1",
        "ascii text",
        "et tor",
        "known tor",
        "relayrouter",
        "exit",
        "node traffic",
        "misc attack",
        "pattern match",
        "null",
        "hybrid",
        "refresh",
        "general",
        "local",
        "click",
        "strings",
        "error",
        "tools",
        "look",
        "verify",
        "restart",
        "contact",
        "suspicious",
        "windows nt",
        "apache",
        "path",
        "pragma",
        "footer",
        "as8068",
        "as8075",
        "as15169 google",
        "as16552 tiggee",
        "virtool",
        "related pulses",
        "file samples",
        "files matching",
        "showing",
        "domain",
        "as22612",
        "as397240",
        "as19527 google",
        "moved",
        "gmt server",
        "as20940",
        "as4230 claro",
        "trojan",
        "ninite",
        "as2914 ntt",
        "win32",
        "brazil unknown",
        "brazil",
        "invalid url",
        "trojandropper",
        "body html",
        "head title",
        "asnone united",
        "as23393"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Brazil",
        "India"
      ],
      "malware_families": [
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 46,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1034,
        "domain": 1210,
        "email": 13,
        "hostname": 1031,
        "FileHash-SHA1": 685,
        "FileHash-SHA256": 1036,
        "FileHash-MD5": 927,
        "CVE": 10
      },
      "indicator_count": 5946,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 234,
      "modified_text": "643 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.microsoft.com/en",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.microsoft.com/en",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780242959.314308
}