{
  "type": "URL",
  "indicator": "https://www.thaismileair.com/...",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.thaismileair.com/...",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 2867646878,
      "indicator": "https://www.thaismileair.com/...",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 13,
      "pulses": [
        {
          "id": "69a9cd444aa144401d0c4988",
          "name": "Pools Open",
          "description": "",
          "modified": "2026-04-15T19:21:28.851000",
          "created": "2026-03-05T18:36:52.014000",
          "tags": [
            "Timothy Pool",
            "Christopher Pool",
            "Pool's Closed"
          ],
          "references": [
            "Pool Closed",
            "Pool's Closed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Media",
            "ad fraud"
          ],
          "TLP": "white",
          "cloned_from": "5fa57698ac0f6638b7b9a8ba",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 8098,
            "URL": 23428,
            "hostname": 9592,
            "domain": 4727,
            "SSLCertFingerprint": 22,
            "FileHash-MD5": 696,
            "FileHash-SHA1": 457,
            "CIDR": 78,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 47103,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 50,
          "modified_text": "4 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "5fa57698ac0f6638b7b9a8ba",
          "name": "Pool's Closed",
          "description": "Two paupers from the meadow spring forth an upheaval of nasty sites on the world wide web.",
          "modified": "2025-12-27T05:02:34.910000",
          "created": "2020-11-06T16:15:20.139000",
          "tags": [
            "Timothy Pool",
            "Christopher Pool",
            "Pool's Closed"
          ],
          "references": [
            "Pool Closed",
            "Pool's Closed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Media",
            "ad fraud"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 61,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 4,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scnrscnr",
            "id": "126475",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_126475/resized/80/avatar_67ca5b7bae.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 8098,
            "URL": 23426,
            "hostname": 9590,
            "domain": 4727,
            "SSLCertFingerprint": 22,
            "FileHash-MD5": 696,
            "FileHash-SHA1": 457,
            "CIDR": 78,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 47099,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 133,
          "modified_text": "113 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65eb9b25110526c6b2a0ada5",
          "name": "VirTool:MSIL/CryptInject.CF!MTB | Rexxfield? Weird stuff",
          "description": "",
          "modified": "2024-03-08T23:11:33.426000",
          "created": "2024-03-08T23:11:33.426000",
          "tags": [
            "threat",
            "feeds ioc",
            "new ioc",
            "teams api",
            "contact",
            "paste",
            "iocs",
            "analyze",
            "ssl certificate",
            "whois record",
            "historical ssl",
            "resolutions",
            "referrer",
            "whois whois",
            "communicating",
            "contacted",
            "family",
            "roots",
            "lolkek",
            "redline stealer",
            "hacktool",
            "html info",
            "title rexxfield",
            "services",
            "identify",
            "meta tags",
            "rexxfield cyber",
            "investigation",
            "divi child",
            "site kit",
            "google",
            "united",
            "unknown",
            "as24940 hetzner",
            "germany unknown",
            "passive dns",
            "urls",
            "title",
            "moved",
            "scan endpoints",
            "all octoseek",
            "body",
            "cyber stalking",
            "pornographer",
            "urls url",
            "files",
            "ip address",
            "execution",
            "metro",
            "medium",
            "show",
            "search",
            "ids detections",
            "yara detections",
            "win32",
            "ppi useragent",
            "installcapital",
            "http",
            "packing t1045",
            "malware",
            "write",
            "obsession",
            "malvertizing",
            "masquerading",
            "ipv4",
            "pulse submit",
            "url analysis",
            "cookie",
            "status",
            "domain",
            "creation date",
            "trojan",
            "date",
            "expiration date",
            "name servers",
            "trojanclicker",
            "encrypt",
            "error",
            "ransomware",
            "malware generator",
            "meta",
            "for privacy",
            "aaaa",
            "komodo",
            "asnone united",
            "alfper",
            "as22612",
            "nxdomain",
            "gmt x",
            "ransom",
            "virtool",
            "log id",
            "gmtn",
            "digicert tls",
            "rsa sha256",
            "tls web",
            "full name",
            "digicert inc",
            "california",
            "false",
            "pulse pulses",
            "location united",
            "as16276",
            "as14061",
            "code",
            "next",
            "url http",
            "hostname",
            "files domain",
            "files related",
            "ghost rat",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "redlinestealer",
            "installcore",
            "installbrain",
            "emotet",
            "tofsee",
            "bradesco",
            "agent tesla",
            "trojanspy",
            "suppobox",
            "occamy",
            "dnspionage",
            "stealer",
            "networm",
            "as13414 twitter",
            "as32934",
            "script urls",
            "a domains",
            "worm",
            "entries",
            "meta http",
            "window",
            "select contact",
            "domain holder",
            "nexus category",
            "tackle company",
            "postal code",
            "component loop",
            "apache",
            "pragma",
            "value0",
            "ioc search",
            "threat analyzer",
            "hostnames",
            "dangerous",
            "target",
            "targeting",
            "hacker profile",
            "cybercrime",
            "fraud services",
            "strange",
            "tsara brashears",
            "michael roberts",
            "tracey richter",
            "voyeurism",
            "slander",
            "password",
            "hijacker"
          ],
          "references": [
            "https://rexxfield.com/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
            "www.akhaltsikhe.gov.ge [Germany?]",
            "screencasts.rexxfield.com",
            "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
            "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
            "94.130.71.173 [scanning host]",
            "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
            "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
            "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
            "Michael Roberts - murder suspect, victim, hacker, PI",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
            "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
            "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
            "a.nel.cloudflare.com / api.w.org",
            "miles.ns.cloudflare.com",
            "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki",
            "https://www.google.com/?authuser=0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "LolKek",
              "display_name": "LolKek",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "TrojanClicker",
              "display_name": "TrojanClicker",
              "target": null
            },
            {
              "id": "Win32:Malware-gen",
              "display_name": "Win32:Malware-gen",
              "target": null
            },
            {
              "id": "ALFPER:InstallCapital",
              "display_name": "ALFPER:InstallCapital",
              "target": null
            },
            {
              "id": "VirTool:MSIL/CryptInject.CF!MTB",
              "display_name": "VirTool:MSIL/CryptInject.CF!MTB",
              "target": "/malware/VirTool:MSIL/CryptInject.CF!MTB"
            },
            {
              "id": "Win.Malware.Downloadguide-6803841-0",
              "display_name": "Win.Malware.Downloadguide-6803841-0",
              "target": null
            },
            {
              "id": "Win.Packed.kkrunchy-7049457-1",
              "display_name": "Win.Packed.kkrunchy-7049457-1",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
              "display_name": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Upatre.A",
              "display_name": "TrojanDownloader:Win32/Upatre.A",
              "target": "/malware/TrojanDownloader:Win32/Upatre.A"
            },
            {
              "id": "Trojan:Win32/Qbot.R!MTB",
              "display_name": "Trojan:Win32/Qbot.R!MTB",
              "target": "/malware/Trojan:Win32/Qbot.R!MTB"
            },
            {
              "id": "ALF:HeraklezEval:Trojan:BAT/Musecador",
              "display_name": "ALF:HeraklezEval:Trojan:BAT/Musecador",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Wabot.A",
              "display_name": "Backdoor:Win32/Wabot.A",
              "target": "/malware/Backdoor:Win32/Wabot.A"
            },
            {
              "id": "Ransom:Win32/G And Crab!rfn",
              "display_name": "Ransom:Win32/G And Crab!rfn",
              "target": "/malware/Ransom:Win32/G And Crab!rfn"
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "Tofsee",
              "display_name": "Tofsee",
              "target": null
            },
            {
              "id": "#Lowfi:FOP:VirTool:Win32/Injector",
              "display_name": "#Lowfi:FOP:VirTool:Win32/Injector",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Worm:Win32/Fesber.A",
              "display_name": "Worm:Win32/Fesber.A",
              "target": "/malware/Worm:Win32/Fesber.A"
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
              "display_name": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
              "target": null
            },
            {
              "id": "InstallBrain",
              "display_name": "InstallBrain",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "Ghost RAT",
              "display_name": "Ghost RAT",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "TrojanSpy:Win32/Bradesco",
              "display_name": "TrojanSpy:Win32/Bradesco",
              "target": "/malware/TrojanSpy:Win32/Bradesco"
            },
            {
              "id": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
              "display_name": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1415",
              "name": "URL Scheme Hijacking",
              "display_name": "T1415 - URL Scheme Hijacking"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.003",
              "name": "Mail Protocols",
              "display_name": "T1071.003 - Mail Protocols"
            },
            {
              "id": "T1030",
              "name": "Data Transfer Size Limits",
              "display_name": "T1030 - Data Transfer Size Limits"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65a342310ab3d2c69778d608",
          "export_count": 53,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 143,
            "FileHash-SHA1": 130,
            "FileHash-SHA256": 1524,
            "URL": 3340,
            "domain": 1735,
            "hostname": 1398,
            "CVE": 1,
            "email": 6,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 8279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "772 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65eb98d47b74b50cf8ce6797",
          "name": "VirTool:Win32/AccessMe | Ghost RAT",
          "description": "",
          "modified": "2024-03-08T23:01:40.129000",
          "created": "2024-03-08T23:01:40.129000",
          "tags": [
            "threat",
            "feeds ioc",
            "new ioc",
            "teams api",
            "contact",
            "paste",
            "iocs",
            "analyze",
            "ssl certificate",
            "whois record",
            "historical ssl",
            "resolutions",
            "referrer",
            "whois whois",
            "communicating",
            "contacted",
            "family",
            "roots",
            "lolkek",
            "redline stealer",
            "hacktool",
            "html info",
            "title rexxfield",
            "services",
            "identify",
            "meta tags",
            "rexxfield cyber",
            "investigation",
            "divi child",
            "site kit",
            "google",
            "united",
            "unknown",
            "as24940 hetzner",
            "germany unknown",
            "passive dns",
            "urls",
            "title",
            "moved",
            "scan endpoints",
            "all octoseek",
            "body",
            "cyber stalking",
            "pornographer",
            "urls url",
            "files",
            "ip address",
            "execution",
            "metro",
            "medium",
            "show",
            "search",
            "ids detections",
            "yara detections",
            "win32",
            "ppi useragent",
            "installcapital",
            "http",
            "packing t1045",
            "malware",
            "write",
            "obsession",
            "malvertizing",
            "masquerading",
            "ipv4",
            "pulse submit",
            "url analysis",
            "cookie",
            "status",
            "domain",
            "creation date",
            "trojan",
            "date",
            "expiration date",
            "name servers",
            "trojanclicker",
            "encrypt",
            "error",
            "ransomware",
            "malware generator",
            "meta",
            "for privacy",
            "aaaa",
            "komodo",
            "asnone united",
            "alfper",
            "as22612",
            "nxdomain",
            "gmt x",
            "ransom",
            "virtool",
            "log id",
            "gmtn",
            "digicert tls",
            "rsa sha256",
            "tls web",
            "full name",
            "digicert inc",
            "california",
            "false",
            "pulse pulses",
            "location united",
            "as16276",
            "as14061",
            "code",
            "next",
            "url http",
            "hostname",
            "files domain",
            "files related",
            "ghost rat",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "redlinestealer",
            "installcore",
            "installbrain",
            "emotet",
            "tofsee",
            "bradesco",
            "agent tesla",
            "trojanspy",
            "suppobox",
            "occamy",
            "dnspionage",
            "stealer",
            "networm",
            "as13414 twitter",
            "as32934",
            "script urls",
            "a domains",
            "worm",
            "entries",
            "meta http",
            "window",
            "select contact",
            "domain holder",
            "nexus category",
            "tackle company",
            "postal code",
            "component loop",
            "apache",
            "pragma",
            "value0",
            "ioc search",
            "threat analyzer",
            "hostnames",
            "dangerous",
            "target",
            "targeting",
            "hacker profile",
            "cybercrime",
            "fraud services",
            "strange",
            "tsara brashears",
            "michael roberts",
            "tracey richter",
            "voyeurism",
            "slander",
            "password",
            "hijacker"
          ],
          "references": [
            "https://rexxfield.com/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
            "www.akhaltsikhe.gov.ge [Germany?]",
            "screencasts.rexxfield.com",
            "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
            "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
            "94.130.71.173 [scanning host]",
            "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
            "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
            "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
            "Michael Roberts - murder suspect, victim, hacker, PI",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
            "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
            "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
            "a.nel.cloudflare.com / api.w.org",
            "miles.ns.cloudflare.com",
            "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki",
            "https://www.google.com/?authuser=0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "LolKek",
              "display_name": "LolKek",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "TrojanClicker",
              "display_name": "TrojanClicker",
              "target": null
            },
            {
              "id": "Win32:Malware-gen",
              "display_name": "Win32:Malware-gen",
              "target": null
            },
            {
              "id": "ALFPER:InstallCapital",
              "display_name": "ALFPER:InstallCapital",
              "target": null
            },
            {
              "id": "VirTool:MSIL/CryptInject.CF!MTB",
              "display_name": "VirTool:MSIL/CryptInject.CF!MTB",
              "target": "/malware/VirTool:MSIL/CryptInject.CF!MTB"
            },
            {
              "id": "Win.Malware.Downloadguide-6803841-0",
              "display_name": "Win.Malware.Downloadguide-6803841-0",
              "target": null
            },
            {
              "id": "Win.Packed.kkrunchy-7049457-1",
              "display_name": "Win.Packed.kkrunchy-7049457-1",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
              "display_name": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Upatre.A",
              "display_name": "TrojanDownloader:Win32/Upatre.A",
              "target": "/malware/TrojanDownloader:Win32/Upatre.A"
            },
            {
              "id": "Trojan:Win32/Qbot.R!MTB",
              "display_name": "Trojan:Win32/Qbot.R!MTB",
              "target": "/malware/Trojan:Win32/Qbot.R!MTB"
            },
            {
              "id": "ALF:HeraklezEval:Trojan:BAT/Musecador",
              "display_name": "ALF:HeraklezEval:Trojan:BAT/Musecador",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Wabot.A",
              "display_name": "Backdoor:Win32/Wabot.A",
              "target": "/malware/Backdoor:Win32/Wabot.A"
            },
            {
              "id": "Ransom:Win32/G And Crab!rfn",
              "display_name": "Ransom:Win32/G And Crab!rfn",
              "target": "/malware/Ransom:Win32/G And Crab!rfn"
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "Tofsee",
              "display_name": "Tofsee",
              "target": null
            },
            {
              "id": "#Lowfi:FOP:VirTool:Win32/Injector",
              "display_name": "#Lowfi:FOP:VirTool:Win32/Injector",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Worm:Win32/Fesber.A",
              "display_name": "Worm:Win32/Fesber.A",
              "target": "/malware/Worm:Win32/Fesber.A"
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
              "display_name": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
              "target": null
            },
            {
              "id": "InstallBrain",
              "display_name": "InstallBrain",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "Ghost RAT",
              "display_name": "Ghost RAT",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "TrojanSpy:Win32/Bradesco",
              "display_name": "TrojanSpy:Win32/Bradesco",
              "target": "/malware/TrojanSpy:Win32/Bradesco"
            },
            {
              "id": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
              "display_name": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1415",
              "name": "URL Scheme Hijacking",
              "display_name": "T1415 - URL Scheme Hijacking"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.003",
              "name": "Mail Protocols",
              "display_name": "T1071.003 - Mail Protocols"
            },
            {
              "id": "T1030",
              "name": "Data Transfer Size Limits",
              "display_name": "T1030 - Data Transfer Size Limits"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65acace20c18a7d6c5da2e27",
          "export_count": 43,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 143,
            "FileHash-SHA1": 130,
            "FileHash-SHA256": 1524,
            "URL": 3340,
            "domain": 1735,
            "hostname": 1398,
            "CVE": 1,
            "email": 6,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 8279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "772 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65a342310ab3d2c69778d608",
          "name": "VirTool:MSIL/CryptInject.CF!MTB | Rexxfield? Weird stuff",
          "description": "Remotely accessed device. Alleges Relationship to OTX? What I know is what I've read. Michael Roberts of Rexxfield supposedly assists, attorneys, law enforcement & helps doctors cover their crimes, injects malicious code, honeypots the web, terrorizing SA victims/allegers. Roberts is allegedly a hacker mastermind who shows his face or one of the many profiles of a hacker group targeting Tsara Brashears and https://SafeBae.org. Brashears is linked in malicious websites, Roberts suspect with ex-wife Tracey Richter alleged murderer. This is all crazy, still;  Brashears is a real person in danger. I don't get it. I'm stupid",
          "modified": "2024-02-13T00:04:59.507000",
          "created": "2024-01-14T02:08:49.638000",
          "tags": [
            "threat",
            "feeds ioc",
            "new ioc",
            "teams api",
            "contact",
            "paste",
            "iocs",
            "analyze",
            "ssl certificate",
            "whois record",
            "historical ssl",
            "resolutions",
            "referrer",
            "whois whois",
            "communicating",
            "contacted",
            "family",
            "roots",
            "lolkek",
            "redline stealer",
            "hacktool",
            "html info",
            "title rexxfield",
            "services",
            "identify",
            "meta tags",
            "rexxfield cyber",
            "investigation",
            "divi child",
            "site kit",
            "google",
            "united",
            "unknown",
            "as24940 hetzner",
            "germany unknown",
            "passive dns",
            "urls",
            "title",
            "moved",
            "scan endpoints",
            "all octoseek",
            "body",
            "cyber stalking",
            "pornographer",
            "urls url",
            "files",
            "ip address",
            "execution",
            "metro",
            "medium",
            "show",
            "search",
            "ids detections",
            "yara detections",
            "win32",
            "ppi useragent",
            "installcapital",
            "http",
            "packing t1045",
            "malware",
            "write",
            "obsession",
            "malvertizing",
            "masquerading",
            "ipv4",
            "pulse submit",
            "url analysis",
            "cookie",
            "status",
            "domain",
            "creation date",
            "trojan",
            "date",
            "expiration date",
            "name servers",
            "trojanclicker",
            "encrypt",
            "error",
            "ransomware",
            "malware generator",
            "meta",
            "for privacy",
            "aaaa",
            "komodo",
            "asnone united",
            "alfper",
            "as22612",
            "nxdomain",
            "gmt x",
            "ransom",
            "virtool",
            "log id",
            "gmtn",
            "digicert tls",
            "rsa sha256",
            "tls web",
            "full name",
            "digicert inc",
            "california",
            "false",
            "pulse pulses",
            "location united",
            "as16276",
            "as14061",
            "code",
            "next",
            "url http",
            "hostname",
            "files domain",
            "files related",
            "ghost rat",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "redlinestealer",
            "installcore",
            "installbrain",
            "emotet",
            "tofsee",
            "bradesco",
            "agent tesla",
            "trojanspy",
            "suppobox",
            "occamy",
            "dnspionage",
            "stealer",
            "networm",
            "as13414 twitter",
            "as32934",
            "script urls",
            "a domains",
            "worm",
            "entries",
            "meta http",
            "window",
            "select contact",
            "domain holder",
            "nexus category",
            "tackle company",
            "postal code",
            "component loop",
            "apache",
            "pragma",
            "value0",
            "ioc search",
            "threat analyzer",
            "hostnames",
            "dangerous",
            "target",
            "targeting",
            "hacker profile",
            "cybercrime",
            "fraud services",
            "strange",
            "tsara brashears",
            "michael roberts",
            "tracey richter",
            "voyeurism",
            "slander",
            "password",
            "hijacker"
          ],
          "references": [
            "https://rexxfield.com/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
            "www.akhaltsikhe.gov.ge [Germany?]",
            "screencasts.rexxfield.com",
            "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
            "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
            "94.130.71.173 [scanning host]",
            "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
            "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
            "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
            "Michael Roberts - murder suspect, victim, hacker, PI",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
            "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
            "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
            "a.nel.cloudflare.com / api.w.org",
            "miles.ns.cloudflare.com",
            "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki",
            "https://www.google.com/?authuser=0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "LolKek",
              "display_name": "LolKek",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "TrojanClicker",
              "display_name": "TrojanClicker",
              "target": null
            },
            {
              "id": "Win32:Malware-gen",
              "display_name": "Win32:Malware-gen",
              "target": null
            },
            {
              "id": "ALFPER:InstallCapital",
              "display_name": "ALFPER:InstallCapital",
              "target": null
            },
            {
              "id": "VirTool:MSIL/CryptInject.CF!MTB",
              "display_name": "VirTool:MSIL/CryptInject.CF!MTB",
              "target": "/malware/VirTool:MSIL/CryptInject.CF!MTB"
            },
            {
              "id": "Win.Malware.Downloadguide-6803841-0",
              "display_name": "Win.Malware.Downloadguide-6803841-0",
              "target": null
            },
            {
              "id": "Win.Packed.kkrunchy-7049457-1",
              "display_name": "Win.Packed.kkrunchy-7049457-1",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
              "display_name": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Upatre.A",
              "display_name": "TrojanDownloader:Win32/Upatre.A",
              "target": "/malware/TrojanDownloader:Win32/Upatre.A"
            },
            {
              "id": "Trojan:Win32/Qbot.R!MTB",
              "display_name": "Trojan:Win32/Qbot.R!MTB",
              "target": "/malware/Trojan:Win32/Qbot.R!MTB"
            },
            {
              "id": "ALF:HeraklezEval:Trojan:BAT/Musecador",
              "display_name": "ALF:HeraklezEval:Trojan:BAT/Musecador",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Wabot.A",
              "display_name": "Backdoor:Win32/Wabot.A",
              "target": "/malware/Backdoor:Win32/Wabot.A"
            },
            {
              "id": "Ransom:Win32/G And Crab!rfn",
              "display_name": "Ransom:Win32/G And Crab!rfn",
              "target": "/malware/Ransom:Win32/G And Crab!rfn"
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "Tofsee",
              "display_name": "Tofsee",
              "target": null
            },
            {
              "id": "#Lowfi:FOP:VirTool:Win32/Injector",
              "display_name": "#Lowfi:FOP:VirTool:Win32/Injector",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Worm:Win32/Fesber.A",
              "display_name": "Worm:Win32/Fesber.A",
              "target": "/malware/Worm:Win32/Fesber.A"
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
              "display_name": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
              "target": null
            },
            {
              "id": "InstallBrain",
              "display_name": "InstallBrain",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "Ghost RAT",
              "display_name": "Ghost RAT",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "TrojanSpy:Win32/Bradesco",
              "display_name": "TrojanSpy:Win32/Bradesco",
              "target": "/malware/TrojanSpy:Win32/Bradesco"
            },
            {
              "id": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
              "display_name": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1415",
              "name": "URL Scheme Hijacking",
              "display_name": "T1415 - URL Scheme Hijacking"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.003",
              "name": "Mail Protocols",
              "display_name": "T1071.003 - Mail Protocols"
            },
            {
              "id": "T1030",
              "name": "Data Transfer Size Limits",
              "display_name": "T1030 - Data Transfer Size Limits"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 26,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 143,
            "FileHash-SHA1": 130,
            "FileHash-SHA256": 1524,
            "URL": 3340,
            "domain": 1735,
            "hostname": 1398,
            "CVE": 1,
            "email": 6,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 8279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 219,
          "modified_text": "796 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65acace20c18a7d6c5da2e27",
          "name": "VirTool:Win32/AccessMe | Ghost RAT",
          "description": "",
          "modified": "2024-02-13T00:04:59.507000",
          "created": "2024-01-21T05:34:26.800000",
          "tags": [
            "threat",
            "feeds ioc",
            "new ioc",
            "teams api",
            "contact",
            "paste",
            "iocs",
            "analyze",
            "ssl certificate",
            "whois record",
            "historical ssl",
            "resolutions",
            "referrer",
            "whois whois",
            "communicating",
            "contacted",
            "family",
            "roots",
            "lolkek",
            "redline stealer",
            "hacktool",
            "html info",
            "title rexxfield",
            "services",
            "identify",
            "meta tags",
            "rexxfield cyber",
            "investigation",
            "divi child",
            "site kit",
            "google",
            "united",
            "unknown",
            "as24940 hetzner",
            "germany unknown",
            "passive dns",
            "urls",
            "title",
            "moved",
            "scan endpoints",
            "all octoseek",
            "body",
            "cyber stalking",
            "pornographer",
            "urls url",
            "files",
            "ip address",
            "execution",
            "metro",
            "medium",
            "show",
            "search",
            "ids detections",
            "yara detections",
            "win32",
            "ppi useragent",
            "installcapital",
            "http",
            "packing t1045",
            "malware",
            "write",
            "obsession",
            "malvertizing",
            "masquerading",
            "ipv4",
            "pulse submit",
            "url analysis",
            "cookie",
            "status",
            "domain",
            "creation date",
            "trojan",
            "date",
            "expiration date",
            "name servers",
            "trojanclicker",
            "encrypt",
            "error",
            "ransomware",
            "malware generator",
            "meta",
            "for privacy",
            "aaaa",
            "komodo",
            "asnone united",
            "alfper",
            "as22612",
            "nxdomain",
            "gmt x",
            "ransom",
            "virtool",
            "log id",
            "gmtn",
            "digicert tls",
            "rsa sha256",
            "tls web",
            "full name",
            "digicert inc",
            "california",
            "false",
            "pulse pulses",
            "location united",
            "as16276",
            "as14061",
            "code",
            "next",
            "url http",
            "hostname",
            "files domain",
            "files related",
            "ghost rat",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "redlinestealer",
            "installcore",
            "installbrain",
            "emotet",
            "tofsee",
            "bradesco",
            "agent tesla",
            "trojanspy",
            "suppobox",
            "occamy",
            "dnspionage",
            "stealer",
            "networm",
            "as13414 twitter",
            "as32934",
            "script urls",
            "a domains",
            "worm",
            "entries",
            "meta http",
            "window",
            "select contact",
            "domain holder",
            "nexus category",
            "tackle company",
            "postal code",
            "component loop",
            "apache",
            "pragma",
            "value0",
            "ioc search",
            "threat analyzer",
            "hostnames",
            "dangerous",
            "target",
            "targeting",
            "hacker profile",
            "cybercrime",
            "fraud services",
            "strange",
            "tsara brashears",
            "michael roberts",
            "tracey richter",
            "voyeurism",
            "slander",
            "password",
            "hijacker"
          ],
          "references": [
            "https://rexxfield.com/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
            "www.akhaltsikhe.gov.ge [Germany?]",
            "screencasts.rexxfield.com",
            "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
            "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
            "94.130.71.173 [scanning host]",
            "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
            "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
            "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
            "Michael Roberts - murder suspect, victim, hacker, PI",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
            "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
            "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
            "a.nel.cloudflare.com / api.w.org",
            "miles.ns.cloudflare.com",
            "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki",
            "https://www.google.com/?authuser=0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "LolKek",
              "display_name": "LolKek",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "TrojanClicker",
              "display_name": "TrojanClicker",
              "target": null
            },
            {
              "id": "Win32:Malware-gen",
              "display_name": "Win32:Malware-gen",
              "target": null
            },
            {
              "id": "ALFPER:InstallCapital",
              "display_name": "ALFPER:InstallCapital",
              "target": null
            },
            {
              "id": "VirTool:MSIL/CryptInject.CF!MTB",
              "display_name": "VirTool:MSIL/CryptInject.CF!MTB",
              "target": "/malware/VirTool:MSIL/CryptInject.CF!MTB"
            },
            {
              "id": "Win.Malware.Downloadguide-6803841-0",
              "display_name": "Win.Malware.Downloadguide-6803841-0",
              "target": null
            },
            {
              "id": "Win.Packed.kkrunchy-7049457-1",
              "display_name": "Win.Packed.kkrunchy-7049457-1",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
              "display_name": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Upatre.A",
              "display_name": "TrojanDownloader:Win32/Upatre.A",
              "target": "/malware/TrojanDownloader:Win32/Upatre.A"
            },
            {
              "id": "Trojan:Win32/Qbot.R!MTB",
              "display_name": "Trojan:Win32/Qbot.R!MTB",
              "target": "/malware/Trojan:Win32/Qbot.R!MTB"
            },
            {
              "id": "ALF:HeraklezEval:Trojan:BAT/Musecador",
              "display_name": "ALF:HeraklezEval:Trojan:BAT/Musecador",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Wabot.A",
              "display_name": "Backdoor:Win32/Wabot.A",
              "target": "/malware/Backdoor:Win32/Wabot.A"
            },
            {
              "id": "Ransom:Win32/G And Crab!rfn",
              "display_name": "Ransom:Win32/G And Crab!rfn",
              "target": "/malware/Ransom:Win32/G And Crab!rfn"
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "Tofsee",
              "display_name": "Tofsee",
              "target": null
            },
            {
              "id": "#Lowfi:FOP:VirTool:Win32/Injector",
              "display_name": "#Lowfi:FOP:VirTool:Win32/Injector",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Worm:Win32/Fesber.A",
              "display_name": "Worm:Win32/Fesber.A",
              "target": "/malware/Worm:Win32/Fesber.A"
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
              "display_name": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
              "target": null
            },
            {
              "id": "InstallBrain",
              "display_name": "InstallBrain",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "Ghost RAT",
              "display_name": "Ghost RAT",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "TrojanSpy:Win32/Bradesco",
              "display_name": "TrojanSpy:Win32/Bradesco",
              "target": "/malware/TrojanSpy:Win32/Bradesco"
            },
            {
              "id": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
              "display_name": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1415",
              "name": "URL Scheme Hijacking",
              "display_name": "T1415 - URL Scheme Hijacking"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.003",
              "name": "Mail Protocols",
              "display_name": "T1071.003 - Mail Protocols"
            },
            {
              "id": "T1030",
              "name": "Data Transfer Size Limits",
              "display_name": "T1030 - Data Transfer Size Limits"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65a342310ab3d2c69778d608",
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 143,
            "FileHash-SHA1": 130,
            "FileHash-SHA256": 1524,
            "URL": 3340,
            "domain": 1735,
            "hostname": 1398,
            "CVE": 1,
            "email": 6,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 8279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 219,
          "modified_text": "796 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65afc9cf333bbda03a18e03c",
          "name": "VirTool:Win32/AccessMe | Ghost RAT",
          "description": "",
          "modified": "2024-02-13T00:04:59.507000",
          "created": "2024-01-23T14:14:39.725000",
          "tags": [
            "threat",
            "feeds ioc",
            "new ioc",
            "teams api",
            "contact",
            "paste",
            "iocs",
            "analyze",
            "ssl certificate",
            "whois record",
            "historical ssl",
            "resolutions",
            "referrer",
            "whois whois",
            "communicating",
            "contacted",
            "family",
            "roots",
            "lolkek",
            "redline stealer",
            "hacktool",
            "html info",
            "title rexxfield",
            "services",
            "identify",
            "meta tags",
            "rexxfield cyber",
            "investigation",
            "divi child",
            "site kit",
            "google",
            "united",
            "unknown",
            "as24940 hetzner",
            "germany unknown",
            "passive dns",
            "urls",
            "title",
            "moved",
            "scan endpoints",
            "all octoseek",
            "body",
            "cyber stalking",
            "pornographer",
            "urls url",
            "files",
            "ip address",
            "execution",
            "metro",
            "medium",
            "show",
            "search",
            "ids detections",
            "yara detections",
            "win32",
            "ppi useragent",
            "installcapital",
            "http",
            "packing t1045",
            "malware",
            "write",
            "obsession",
            "malvertizing",
            "masquerading",
            "ipv4",
            "pulse submit",
            "url analysis",
            "cookie",
            "status",
            "domain",
            "creation date",
            "trojan",
            "date",
            "expiration date",
            "name servers",
            "trojanclicker",
            "encrypt",
            "error",
            "ransomware",
            "malware generator",
            "meta",
            "for privacy",
            "aaaa",
            "komodo",
            "asnone united",
            "alfper",
            "as22612",
            "nxdomain",
            "gmt x",
            "ransom",
            "virtool",
            "log id",
            "gmtn",
            "digicert tls",
            "rsa sha256",
            "tls web",
            "full name",
            "digicert inc",
            "california",
            "false",
            "pulse pulses",
            "location united",
            "as16276",
            "as14061",
            "code",
            "next",
            "url http",
            "hostname",
            "files domain",
            "files related",
            "ghost rat",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "redlinestealer",
            "installcore",
            "installbrain",
            "emotet",
            "tofsee",
            "bradesco",
            "agent tesla",
            "trojanspy",
            "suppobox",
            "occamy",
            "dnspionage",
            "stealer",
            "networm",
            "as13414 twitter",
            "as32934",
            "script urls",
            "a domains",
            "worm",
            "entries",
            "meta http",
            "window",
            "select contact",
            "domain holder",
            "nexus category",
            "tackle company",
            "postal code",
            "component loop",
            "apache",
            "pragma",
            "value0",
            "ioc search",
            "threat analyzer",
            "hostnames",
            "dangerous",
            "target",
            "targeting",
            "hacker profile",
            "cybercrime",
            "fraud services",
            "strange",
            "tsara brashears",
            "michael roberts",
            "tracey richter",
            "voyeurism",
            "slander",
            "password",
            "hijacker"
          ],
          "references": [
            "https://rexxfield.com/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
            "www.akhaltsikhe.gov.ge [Germany?]",
            "screencasts.rexxfield.com",
            "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
            "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
            "94.130.71.173 [scanning host]",
            "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
            "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
            "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
            "Michael Roberts - murder suspect, victim, hacker, PI",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
            "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
            "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
            "a.nel.cloudflare.com / api.w.org",
            "miles.ns.cloudflare.com",
            "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki",
            "https://www.google.com/?authuser=0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "LolKek",
              "display_name": "LolKek",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "TrojanClicker",
              "display_name": "TrojanClicker",
              "target": null
            },
            {
              "id": "Win32:Malware-gen",
              "display_name": "Win32:Malware-gen",
              "target": null
            },
            {
              "id": "ALFPER:InstallCapital",
              "display_name": "ALFPER:InstallCapital",
              "target": null
            },
            {
              "id": "VirTool:MSIL/CryptInject.CF!MTB",
              "display_name": "VirTool:MSIL/CryptInject.CF!MTB",
              "target": "/malware/VirTool:MSIL/CryptInject.CF!MTB"
            },
            {
              "id": "Win.Malware.Downloadguide-6803841-0",
              "display_name": "Win.Malware.Downloadguide-6803841-0",
              "target": null
            },
            {
              "id": "Win.Packed.kkrunchy-7049457-1",
              "display_name": "Win.Packed.kkrunchy-7049457-1",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
              "display_name": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Upatre.A",
              "display_name": "TrojanDownloader:Win32/Upatre.A",
              "target": "/malware/TrojanDownloader:Win32/Upatre.A"
            },
            {
              "id": "Trojan:Win32/Qbot.R!MTB",
              "display_name": "Trojan:Win32/Qbot.R!MTB",
              "target": "/malware/Trojan:Win32/Qbot.R!MTB"
            },
            {
              "id": "ALF:HeraklezEval:Trojan:BAT/Musecador",
              "display_name": "ALF:HeraklezEval:Trojan:BAT/Musecador",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Wabot.A",
              "display_name": "Backdoor:Win32/Wabot.A",
              "target": "/malware/Backdoor:Win32/Wabot.A"
            },
            {
              "id": "Ransom:Win32/G And Crab!rfn",
              "display_name": "Ransom:Win32/G And Crab!rfn",
              "target": "/malware/Ransom:Win32/G And Crab!rfn"
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "Tofsee",
              "display_name": "Tofsee",
              "target": null
            },
            {
              "id": "#Lowfi:FOP:VirTool:Win32/Injector",
              "display_name": "#Lowfi:FOP:VirTool:Win32/Injector",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Worm:Win32/Fesber.A",
              "display_name": "Worm:Win32/Fesber.A",
              "target": "/malware/Worm:Win32/Fesber.A"
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
              "display_name": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
              "target": null
            },
            {
              "id": "InstallBrain",
              "display_name": "InstallBrain",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "Ghost RAT",
              "display_name": "Ghost RAT",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "TrojanSpy:Win32/Bradesco",
              "display_name": "TrojanSpy:Win32/Bradesco",
              "target": "/malware/TrojanSpy:Win32/Bradesco"
            },
            {
              "id": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
              "display_name": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1415",
              "name": "URL Scheme Hijacking",
              "display_name": "T1415 - URL Scheme Hijacking"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.003",
              "name": "Mail Protocols",
              "display_name": "T1071.003 - Mail Protocols"
            },
            {
              "id": "T1030",
              "name": "Data Transfer Size Limits",
              "display_name": "T1030 - Data Transfer Size Limits"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65acace20c18a7d6c5da2e27",
          "export_count": 26,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 143,
            "FileHash-SHA1": 130,
            "FileHash-SHA256": 1524,
            "URL": 3340,
            "domain": 1735,
            "hostname": 1398,
            "CVE": 1,
            "email": 6,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 8279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "796 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a161f0681f4ff3d67feb",
          "name": "Pool's Closed (by @scnrscnr)",
          "description": "",
          "modified": "2023-12-06T16:29:21.844000",
          "created": "2023-12-06T16:29:21.844000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7844,
            "FileHash-MD5": 562,
            "FileHash-SHA1": 429,
            "URL": 22749,
            "hostname": 9461,
            "domain": 4578,
            "SSLCertFingerprint": 20,
            "CIDR": 32,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 45680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a145926a5676de0e2a1a",
          "name": "Pool's Closed (by @scnrscnr)",
          "description": "",
          "modified": "2023-12-06T16:28:53.979000",
          "created": "2023-12-06T16:28:53.979000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7844,
            "FileHash-MD5": 562,
            "FileHash-SHA1": 429,
            "URL": 22749,
            "hostname": 9461,
            "domain": 4578,
            "SSLCertFingerprint": 20,
            "CIDR": 32,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 45680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707b9630308cb99a817277",
          "name": "Pool's Closed",
          "description": "",
          "modified": "2023-12-06T13:48:06.514000",
          "created": "2023-12-06T13:48:06.514000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7844,
            "FileHash-MD5": 562,
            "FileHash-SHA1": 429,
            "URL": 22749,
            "hostname": 9461,
            "domain": 4578,
            "SSLCertFingerprint": 20,
            "CIDR": 32,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 45680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64f37719db054ccde25aa9df",
          "name": "Pool's Closed (by @scnrscnr)",
          "description": "",
          "modified": "2023-09-02T17:55:37.269000",
          "created": "2023-09-02T17:55:37.269000",
          "tags": [
            "Timothy Pool",
            "Christopher Pool",
            "Pool's Closed"
          ],
          "references": [
            "Pool Closed",
            "Pool's Closed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Media",
            "ad fraud"
          ],
          "TLP": "white",
          "cloned_from": "5fa57698ac0f6638b7b9a8ba",
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7851,
            "URL": 23098,
            "hostname": 9521,
            "domain": 4595,
            "SSLCertFingerprint": 22,
            "FileHash-MD5": 564,
            "FileHash-SHA1": 432,
            "CIDR": 32,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 46120,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "960 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64f3771616d9a9891947e4df",
          "name": "Pool's Closed (by @scnrscnr)",
          "description": "",
          "modified": "2023-09-02T17:55:34.095000",
          "created": "2023-09-02T17:55:34.095000",
          "tags": [
            "Timothy Pool",
            "Christopher Pool",
            "Pool's Closed"
          ],
          "references": [
            "Pool Closed",
            "Pool's Closed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Media",
            "ad fraud"
          ],
          "TLP": "white",
          "cloned_from": "5fa57698ac0f6638b7b9a8ba",
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7851,
            "URL": 23098,
            "hostname": 9521,
            "domain": 4595,
            "SSLCertFingerprint": 22,
            "FileHash-MD5": 564,
            "FileHash-SHA1": 432,
            "CIDR": 32,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 46120,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "960 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "628437db120de2ab2ecb49fe",
          "name": "The \u201cconti leak page\u201d - likely conti",
          "description": "Conti leak page https://share.vx-underground.org/Conti/ is likely conti",
          "modified": "2022-06-16T00:01:26.112000",
          "created": "2022-05-18T00:03:39.947000",
          "tags": [
            "woff2",
            "woff",
            "truetype",
            "gelionbold",
            "gelionsemibold",
            "gelionmedium",
            "gelionregular",
            "gelionlight",
            "gelionthin",
            "xe",
            "object",
            "error",
            "element",
            "typeof t",
            "browser",
            "ofunction",
            "typeof e",
            "typeof r",
            "tthis",
            "applepay",
            "date",
            "null",
            "accept",
            "license",
            "or conditions",
            "post",
            "array",
            "copyright",
            "apache license",
            "version",
            "this code",
            "is provided",
            "on an",
            "symbol",
            "typeerror",
            "iterator",
            "string",
            "facebook pixel",
            "pixel code",
            "facebook",
            "service",
            "phonenumber",
            "regexp",
            "function",
            "shadowsizzle",
            "domdata",
            "hexchars",
            "promise",
            "typeof n",
            "agent",
            "launcher",
            "this",
            "android",
            "class",
            "fail",
            "shift",
            "bind",
            "trident",
            "getclass",
            "body",
            "widget",
            "edge",
            "dataname",
            "intercom",
            "typeof symbol",
            "apple",
            "webkiti",
            "criosi",
            "javascript"
          ],
          "references": [
            "xfe-URL-share.vx-underground.org_Conti-stix2-2.1-export.json",
            "https://app.uizard.io/p/c69fa2aa",
            "https://widget.intercom.io/widget/e1nqrt2k",
            "https://cdn.eu.pendo.io/agent/static/82b060a2-2cf8-472e-55d4-bd0833416335/pendo.js",
            "https://connect.facebook.net/signals/plugins/identity.js?v=2.9.60",
            "xfe-URL-vx-underground.org_Conti_-stix2-2.1-export.json",
            "xfe-URL-uizard.io-stix2-2.1-export.json",
            "https://public.profitwell.com/js/profitwell.js?auth=80939adc88898a29e714f6dd3d25e8ba",
            "https://js.stripe.com/v3",
            "https://app.uizard.io/fonts.css?cache=2022-04-29-12-55-57",
            "xfe-URL-Js.stripe.net-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Xe",
              "display_name": "Xe",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 707,
            "URL": 3480,
            "FileHash-SHA256": 438,
            "domain": 458,
            "email": 2,
            "FileHash-MD5": 49
          },
          "indicator_count": 5134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "1403 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
        "https://app.uizard.io/p/c69fa2aa",
        "xfe-URL-share.vx-underground.org_Conti-stix2-2.1-export.json",
        "xfe-URL-uizard.io-stix2-2.1-export.json",
        "miles.ns.cloudflare.com",
        "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
        "xfe-URL-Js.stripe.net-stix2-2.1-export.json",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
        "https://connect.facebook.net/signals/plugins/identity.js?v=2.9.60",
        "xfe-URL-vx-underground.org_Conti_-stix2-2.1-export.json",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
        "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
        "94.130.71.173 [scanning host]",
        "https://rexxfield.com/",
        "https://app.uizard.io/fonts.css?cache=2022-04-29-12-55-57",
        "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
        "https://js.stripe.com/v3",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
        "Michael Roberts - murder suspect, victim, hacker, PI",
        "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
        "screencasts.rexxfield.com",
        "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
        "a.nel.cloudflare.com / api.w.org",
        "https://www.google.com/?authuser=0",
        "www.akhaltsikhe.gov.ge [Germany?]",
        "https://public.profitwell.com/js/profitwell.js?auth=80939adc88898a29e714f6dd3d25e8ba",
        "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
        "Pool Closed",
        "Pool's Closed",
        "https://cdn.eu.pendo.io/agent/static/82b060a2-2cf8-472e-55d4-bd0833416335/pendo.js",
        "https://widget.intercom.io/widget/e1nqrt2k",
        "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Lolkek",
            "Win32:malware-gen",
            "Redline stealer",
            "Installcore",
            "Ransom:win32/g and crab!rfn",
            "Alf:heraklezeval:softwarebundler:win32/prepscram",
            "Installbrain",
            "Backdoor:win32/wabot.a",
            "Occamy",
            "Trojanspy:win32/bradesco",
            "Hacktool",
            "#lowfi:fop:virtool:win32/injector",
            "Tofsee",
            "Xe",
            "Ghost rat",
            "Worm:win32/fesber.a",
            "Alf:heraklezeval:trojanclicker:js/faceliker",
            "Suppobox",
            "Win.malware.downloadguide-6803841-0",
            "Alfper:installcapital",
            "Webtoolbar",
            "Trojanclicker",
            "Ransom:win32/wannacrypt.a!rsm",
            "Alf:heraklezeval:trojan:bat/musecador",
            "Trojan:win32/qbot.r!mtb",
            "Agent tesla",
            "#lowfi:hstr:trojanspy:win32/xtrat",
            "Cobalt strike",
            "Win.packed.kkrunchy-7049457-1",
            "Trojandownloader:win32/upatre.a",
            "Virtool:msil/cryptinject.cf!mtb",
            "Nanocore rat"
          ],
          "industries": [
            "Ad fraud",
            "Media"
          ],
          "unique_indicators": 60703
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/thaismileair.com",
    "whois": "http://whois.domaintools.com/thaismileair.com",
    "domain": "thaismileair.com",
    "hostname": "www.thaismileair.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 13,
  "pulses": [
    {
      "id": "69a9cd444aa144401d0c4988",
      "name": "Pools Open",
      "description": "",
      "modified": "2026-04-15T19:21:28.851000",
      "created": "2026-03-05T18:36:52.014000",
      "tags": [
        "Timothy Pool",
        "Christopher Pool",
        "Pool's Closed"
      ],
      "references": [
        "Pool Closed",
        "Pool's Closed"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [
        "Media",
        "ad fraud"
      ],
      "TLP": "white",
      "cloned_from": "5fa57698ac0f6638b7b9a8ba",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 8098,
        "URL": 23428,
        "hostname": 9592,
        "domain": 4727,
        "SSLCertFingerprint": 22,
        "FileHash-MD5": 696,
        "FileHash-SHA1": 457,
        "CIDR": 78,
        "email": 3,
        "CVE": 2
      },
      "indicator_count": 47103,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 50,
      "modified_text": "4 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "5fa57698ac0f6638b7b9a8ba",
      "name": "Pool's Closed",
      "description": "Two paupers from the meadow spring forth an upheaval of nasty sites on the world wide web.",
      "modified": "2025-12-27T05:02:34.910000",
      "created": "2020-11-06T16:15:20.139000",
      "tags": [
        "Timothy Pool",
        "Christopher Pool",
        "Pool's Closed"
      ],
      "references": [
        "Pool Closed",
        "Pool's Closed"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [
        "Media",
        "ad fraud"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 61,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 4,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scnrscnr",
        "id": "126475",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_126475/resized/80/avatar_67ca5b7bae.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 8098,
        "URL": 23426,
        "hostname": 9590,
        "domain": 4727,
        "SSLCertFingerprint": 22,
        "FileHash-MD5": 696,
        "FileHash-SHA1": 457,
        "CIDR": 78,
        "email": 3,
        "CVE": 2
      },
      "indicator_count": 47099,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 133,
      "modified_text": "113 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65eb9b25110526c6b2a0ada5",
      "name": "VirTool:MSIL/CryptInject.CF!MTB | Rexxfield? Weird stuff",
      "description": "",
      "modified": "2024-03-08T23:11:33.426000",
      "created": "2024-03-08T23:11:33.426000",
      "tags": [
        "threat",
        "feeds ioc",
        "new ioc",
        "teams api",
        "contact",
        "paste",
        "iocs",
        "analyze",
        "ssl certificate",
        "whois record",
        "historical ssl",
        "resolutions",
        "referrer",
        "whois whois",
        "communicating",
        "contacted",
        "family",
        "roots",
        "lolkek",
        "redline stealer",
        "hacktool",
        "html info",
        "title rexxfield",
        "services",
        "identify",
        "meta tags",
        "rexxfield cyber",
        "investigation",
        "divi child",
        "site kit",
        "google",
        "united",
        "unknown",
        "as24940 hetzner",
        "germany unknown",
        "passive dns",
        "urls",
        "title",
        "moved",
        "scan endpoints",
        "all octoseek",
        "body",
        "cyber stalking",
        "pornographer",
        "urls url",
        "files",
        "ip address",
        "execution",
        "metro",
        "medium",
        "show",
        "search",
        "ids detections",
        "yara detections",
        "win32",
        "ppi useragent",
        "installcapital",
        "http",
        "packing t1045",
        "malware",
        "write",
        "obsession",
        "malvertizing",
        "masquerading",
        "ipv4",
        "pulse submit",
        "url analysis",
        "cookie",
        "status",
        "domain",
        "creation date",
        "trojan",
        "date",
        "expiration date",
        "name servers",
        "trojanclicker",
        "encrypt",
        "error",
        "ransomware",
        "malware generator",
        "meta",
        "for privacy",
        "aaaa",
        "komodo",
        "asnone united",
        "alfper",
        "as22612",
        "nxdomain",
        "gmt x",
        "ransom",
        "virtool",
        "log id",
        "gmtn",
        "digicert tls",
        "rsa sha256",
        "tls web",
        "full name",
        "digicert inc",
        "california",
        "false",
        "pulse pulses",
        "location united",
        "as16276",
        "as14061",
        "code",
        "next",
        "url http",
        "hostname",
        "files domain",
        "files related",
        "ghost rat",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "redlinestealer",
        "installcore",
        "installbrain",
        "emotet",
        "tofsee",
        "bradesco",
        "agent tesla",
        "trojanspy",
        "suppobox",
        "occamy",
        "dnspionage",
        "stealer",
        "networm",
        "as13414 twitter",
        "as32934",
        "script urls",
        "a domains",
        "worm",
        "entries",
        "meta http",
        "window",
        "select contact",
        "domain holder",
        "nexus category",
        "tackle company",
        "postal code",
        "component loop",
        "apache",
        "pragma",
        "value0",
        "ioc search",
        "threat analyzer",
        "hostnames",
        "dangerous",
        "target",
        "targeting",
        "hacker profile",
        "cybercrime",
        "fraud services",
        "strange",
        "tsara brashears",
        "michael roberts",
        "tracey richter",
        "voyeurism",
        "slander",
        "password",
        "hijacker"
      ],
      "references": [
        "https://rexxfield.com/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
        "www.akhaltsikhe.gov.ge [Germany?]",
        "screencasts.rexxfield.com",
        "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
        "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
        "94.130.71.173 [scanning host]",
        "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
        "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
        "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
        "Michael Roberts - murder suspect, victim, hacker, PI",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
        "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
        "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
        "a.nel.cloudflare.com / api.w.org",
        "miles.ns.cloudflare.com",
        "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki",
        "https://www.google.com/?authuser=0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "LolKek",
          "display_name": "LolKek",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "TrojanClicker",
          "display_name": "TrojanClicker",
          "target": null
        },
        {
          "id": "Win32:Malware-gen",
          "display_name": "Win32:Malware-gen",
          "target": null
        },
        {
          "id": "ALFPER:InstallCapital",
          "display_name": "ALFPER:InstallCapital",
          "target": null
        },
        {
          "id": "VirTool:MSIL/CryptInject.CF!MTB",
          "display_name": "VirTool:MSIL/CryptInject.CF!MTB",
          "target": "/malware/VirTool:MSIL/CryptInject.CF!MTB"
        },
        {
          "id": "Win.Malware.Downloadguide-6803841-0",
          "display_name": "Win.Malware.Downloadguide-6803841-0",
          "target": null
        },
        {
          "id": "Win.Packed.kkrunchy-7049457-1",
          "display_name": "Win.Packed.kkrunchy-7049457-1",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
          "display_name": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Upatre.A",
          "display_name": "TrojanDownloader:Win32/Upatre.A",
          "target": "/malware/TrojanDownloader:Win32/Upatre.A"
        },
        {
          "id": "Trojan:Win32/Qbot.R!MTB",
          "display_name": "Trojan:Win32/Qbot.R!MTB",
          "target": "/malware/Trojan:Win32/Qbot.R!MTB"
        },
        {
          "id": "ALF:HeraklezEval:Trojan:BAT/Musecador",
          "display_name": "ALF:HeraklezEval:Trojan:BAT/Musecador",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Wabot.A",
          "display_name": "Backdoor:Win32/Wabot.A",
          "target": "/malware/Backdoor:Win32/Wabot.A"
        },
        {
          "id": "Ransom:Win32/G And Crab!rfn",
          "display_name": "Ransom:Win32/G And Crab!rfn",
          "target": "/malware/Ransom:Win32/G And Crab!rfn"
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "Tofsee",
          "display_name": "Tofsee",
          "target": null
        },
        {
          "id": "#Lowfi:FOP:VirTool:Win32/Injector",
          "display_name": "#Lowfi:FOP:VirTool:Win32/Injector",
          "target": null
        },
        {
          "id": "Nanocore RAT",
          "display_name": "Nanocore RAT",
          "target": null
        },
        {
          "id": "Worm:Win32/Fesber.A",
          "display_name": "Worm:Win32/Fesber.A",
          "target": "/malware/Worm:Win32/Fesber.A"
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
          "display_name": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
          "target": null
        },
        {
          "id": "InstallBrain",
          "display_name": "InstallBrain",
          "target": null
        },
        {
          "id": "InstallCore",
          "display_name": "InstallCore",
          "target": null
        },
        {
          "id": "Ghost RAT",
          "display_name": "Ghost RAT",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Occamy",
          "display_name": "Occamy",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "TrojanSpy:Win32/Bradesco",
          "display_name": "TrojanSpy:Win32/Bradesco",
          "target": "/malware/TrojanSpy:Win32/Bradesco"
        },
        {
          "id": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
          "display_name": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1415",
          "name": "URL Scheme Hijacking",
          "display_name": "T1415 - URL Scheme Hijacking"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1122",
          "name": "Component Object Model Hijacking",
          "display_name": "T1122 - Component Object Model Hijacking"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.003",
          "name": "Mail Protocols",
          "display_name": "T1071.003 - Mail Protocols"
        },
        {
          "id": "T1030",
          "name": "Data Transfer Size Limits",
          "display_name": "T1030 - Data Transfer Size Limits"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65a342310ab3d2c69778d608",
      "export_count": 53,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 143,
        "FileHash-SHA1": 130,
        "FileHash-SHA256": 1524,
        "URL": 3340,
        "domain": 1735,
        "hostname": 1398,
        "CVE": 1,
        "email": 6,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 8279,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "772 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65eb98d47b74b50cf8ce6797",
      "name": "VirTool:Win32/AccessMe | Ghost RAT",
      "description": "",
      "modified": "2024-03-08T23:01:40.129000",
      "created": "2024-03-08T23:01:40.129000",
      "tags": [
        "threat",
        "feeds ioc",
        "new ioc",
        "teams api",
        "contact",
        "paste",
        "iocs",
        "analyze",
        "ssl certificate",
        "whois record",
        "historical ssl",
        "resolutions",
        "referrer",
        "whois whois",
        "communicating",
        "contacted",
        "family",
        "roots",
        "lolkek",
        "redline stealer",
        "hacktool",
        "html info",
        "title rexxfield",
        "services",
        "identify",
        "meta tags",
        "rexxfield cyber",
        "investigation",
        "divi child",
        "site kit",
        "google",
        "united",
        "unknown",
        "as24940 hetzner",
        "germany unknown",
        "passive dns",
        "urls",
        "title",
        "moved",
        "scan endpoints",
        "all octoseek",
        "body",
        "cyber stalking",
        "pornographer",
        "urls url",
        "files",
        "ip address",
        "execution",
        "metro",
        "medium",
        "show",
        "search",
        "ids detections",
        "yara detections",
        "win32",
        "ppi useragent",
        "installcapital",
        "http",
        "packing t1045",
        "malware",
        "write",
        "obsession",
        "malvertizing",
        "masquerading",
        "ipv4",
        "pulse submit",
        "url analysis",
        "cookie",
        "status",
        "domain",
        "creation date",
        "trojan",
        "date",
        "expiration date",
        "name servers",
        "trojanclicker",
        "encrypt",
        "error",
        "ransomware",
        "malware generator",
        "meta",
        "for privacy",
        "aaaa",
        "komodo",
        "asnone united",
        "alfper",
        "as22612",
        "nxdomain",
        "gmt x",
        "ransom",
        "virtool",
        "log id",
        "gmtn",
        "digicert tls",
        "rsa sha256",
        "tls web",
        "full name",
        "digicert inc",
        "california",
        "false",
        "pulse pulses",
        "location united",
        "as16276",
        "as14061",
        "code",
        "next",
        "url http",
        "hostname",
        "files domain",
        "files related",
        "ghost rat",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "redlinestealer",
        "installcore",
        "installbrain",
        "emotet",
        "tofsee",
        "bradesco",
        "agent tesla",
        "trojanspy",
        "suppobox",
        "occamy",
        "dnspionage",
        "stealer",
        "networm",
        "as13414 twitter",
        "as32934",
        "script urls",
        "a domains",
        "worm",
        "entries",
        "meta http",
        "window",
        "select contact",
        "domain holder",
        "nexus category",
        "tackle company",
        "postal code",
        "component loop",
        "apache",
        "pragma",
        "value0",
        "ioc search",
        "threat analyzer",
        "hostnames",
        "dangerous",
        "target",
        "targeting",
        "hacker profile",
        "cybercrime",
        "fraud services",
        "strange",
        "tsara brashears",
        "michael roberts",
        "tracey richter",
        "voyeurism",
        "slander",
        "password",
        "hijacker"
      ],
      "references": [
        "https://rexxfield.com/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
        "www.akhaltsikhe.gov.ge [Germany?]",
        "screencasts.rexxfield.com",
        "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
        "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
        "94.130.71.173 [scanning host]",
        "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
        "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
        "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
        "Michael Roberts - murder suspect, victim, hacker, PI",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
        "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
        "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
        "a.nel.cloudflare.com / api.w.org",
        "miles.ns.cloudflare.com",
        "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki",
        "https://www.google.com/?authuser=0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "LolKek",
          "display_name": "LolKek",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "TrojanClicker",
          "display_name": "TrojanClicker",
          "target": null
        },
        {
          "id": "Win32:Malware-gen",
          "display_name": "Win32:Malware-gen",
          "target": null
        },
        {
          "id": "ALFPER:InstallCapital",
          "display_name": "ALFPER:InstallCapital",
          "target": null
        },
        {
          "id": "VirTool:MSIL/CryptInject.CF!MTB",
          "display_name": "VirTool:MSIL/CryptInject.CF!MTB",
          "target": "/malware/VirTool:MSIL/CryptInject.CF!MTB"
        },
        {
          "id": "Win.Malware.Downloadguide-6803841-0",
          "display_name": "Win.Malware.Downloadguide-6803841-0",
          "target": null
        },
        {
          "id": "Win.Packed.kkrunchy-7049457-1",
          "display_name": "Win.Packed.kkrunchy-7049457-1",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
          "display_name": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Upatre.A",
          "display_name": "TrojanDownloader:Win32/Upatre.A",
          "target": "/malware/TrojanDownloader:Win32/Upatre.A"
        },
        {
          "id": "Trojan:Win32/Qbot.R!MTB",
          "display_name": "Trojan:Win32/Qbot.R!MTB",
          "target": "/malware/Trojan:Win32/Qbot.R!MTB"
        },
        {
          "id": "ALF:HeraklezEval:Trojan:BAT/Musecador",
          "display_name": "ALF:HeraklezEval:Trojan:BAT/Musecador",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Wabot.A",
          "display_name": "Backdoor:Win32/Wabot.A",
          "target": "/malware/Backdoor:Win32/Wabot.A"
        },
        {
          "id": "Ransom:Win32/G And Crab!rfn",
          "display_name": "Ransom:Win32/G And Crab!rfn",
          "target": "/malware/Ransom:Win32/G And Crab!rfn"
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "Tofsee",
          "display_name": "Tofsee",
          "target": null
        },
        {
          "id": "#Lowfi:FOP:VirTool:Win32/Injector",
          "display_name": "#Lowfi:FOP:VirTool:Win32/Injector",
          "target": null
        },
        {
          "id": "Nanocore RAT",
          "display_name": "Nanocore RAT",
          "target": null
        },
        {
          "id": "Worm:Win32/Fesber.A",
          "display_name": "Worm:Win32/Fesber.A",
          "target": "/malware/Worm:Win32/Fesber.A"
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
          "display_name": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
          "target": null
        },
        {
          "id": "InstallBrain",
          "display_name": "InstallBrain",
          "target": null
        },
        {
          "id": "InstallCore",
          "display_name": "InstallCore",
          "target": null
        },
        {
          "id": "Ghost RAT",
          "display_name": "Ghost RAT",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Occamy",
          "display_name": "Occamy",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "TrojanSpy:Win32/Bradesco",
          "display_name": "TrojanSpy:Win32/Bradesco",
          "target": "/malware/TrojanSpy:Win32/Bradesco"
        },
        {
          "id": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
          "display_name": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1415",
          "name": "URL Scheme Hijacking",
          "display_name": "T1415 - URL Scheme Hijacking"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1122",
          "name": "Component Object Model Hijacking",
          "display_name": "T1122 - Component Object Model Hijacking"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.003",
          "name": "Mail Protocols",
          "display_name": "T1071.003 - Mail Protocols"
        },
        {
          "id": "T1030",
          "name": "Data Transfer Size Limits",
          "display_name": "T1030 - Data Transfer Size Limits"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65acace20c18a7d6c5da2e27",
      "export_count": 43,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 143,
        "FileHash-SHA1": 130,
        "FileHash-SHA256": 1524,
        "URL": 3340,
        "domain": 1735,
        "hostname": 1398,
        "CVE": 1,
        "email": 6,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 8279,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "772 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65a342310ab3d2c69778d608",
      "name": "VirTool:MSIL/CryptInject.CF!MTB | Rexxfield? Weird stuff",
      "description": "Remotely accessed device. Alleges Relationship to OTX? What I know is what I've read. Michael Roberts of Rexxfield supposedly assists, attorneys, law enforcement & helps doctors cover their crimes, injects malicious code, honeypots the web, terrorizing SA victims/allegers. Roberts is allegedly a hacker mastermind who shows his face or one of the many profiles of a hacker group targeting Tsara Brashears and https://SafeBae.org. Brashears is linked in malicious websites, Roberts suspect with ex-wife Tracey Richter alleged murderer. This is all crazy, still;  Brashears is a real person in danger. I don't get it. I'm stupid",
      "modified": "2024-02-13T00:04:59.507000",
      "created": "2024-01-14T02:08:49.638000",
      "tags": [
        "threat",
        "feeds ioc",
        "new ioc",
        "teams api",
        "contact",
        "paste",
        "iocs",
        "analyze",
        "ssl certificate",
        "whois record",
        "historical ssl",
        "resolutions",
        "referrer",
        "whois whois",
        "communicating",
        "contacted",
        "family",
        "roots",
        "lolkek",
        "redline stealer",
        "hacktool",
        "html info",
        "title rexxfield",
        "services",
        "identify",
        "meta tags",
        "rexxfield cyber",
        "investigation",
        "divi child",
        "site kit",
        "google",
        "united",
        "unknown",
        "as24940 hetzner",
        "germany unknown",
        "passive dns",
        "urls",
        "title",
        "moved",
        "scan endpoints",
        "all octoseek",
        "body",
        "cyber stalking",
        "pornographer",
        "urls url",
        "files",
        "ip address",
        "execution",
        "metro",
        "medium",
        "show",
        "search",
        "ids detections",
        "yara detections",
        "win32",
        "ppi useragent",
        "installcapital",
        "http",
        "packing t1045",
        "malware",
        "write",
        "obsession",
        "malvertizing",
        "masquerading",
        "ipv4",
        "pulse submit",
        "url analysis",
        "cookie",
        "status",
        "domain",
        "creation date",
        "trojan",
        "date",
        "expiration date",
        "name servers",
        "trojanclicker",
        "encrypt",
        "error",
        "ransomware",
        "malware generator",
        "meta",
        "for privacy",
        "aaaa",
        "komodo",
        "asnone united",
        "alfper",
        "as22612",
        "nxdomain",
        "gmt x",
        "ransom",
        "virtool",
        "log id",
        "gmtn",
        "digicert tls",
        "rsa sha256",
        "tls web",
        "full name",
        "digicert inc",
        "california",
        "false",
        "pulse pulses",
        "location united",
        "as16276",
        "as14061",
        "code",
        "next",
        "url http",
        "hostname",
        "files domain",
        "files related",
        "ghost rat",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "redlinestealer",
        "installcore",
        "installbrain",
        "emotet",
        "tofsee",
        "bradesco",
        "agent tesla",
        "trojanspy",
        "suppobox",
        "occamy",
        "dnspionage",
        "stealer",
        "networm",
        "as13414 twitter",
        "as32934",
        "script urls",
        "a domains",
        "worm",
        "entries",
        "meta http",
        "window",
        "select contact",
        "domain holder",
        "nexus category",
        "tackle company",
        "postal code",
        "component loop",
        "apache",
        "pragma",
        "value0",
        "ioc search",
        "threat analyzer",
        "hostnames",
        "dangerous",
        "target",
        "targeting",
        "hacker profile",
        "cybercrime",
        "fraud services",
        "strange",
        "tsara brashears",
        "michael roberts",
        "tracey richter",
        "voyeurism",
        "slander",
        "password",
        "hijacker"
      ],
      "references": [
        "https://rexxfield.com/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
        "www.akhaltsikhe.gov.ge [Germany?]",
        "screencasts.rexxfield.com",
        "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
        "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
        "94.130.71.173 [scanning host]",
        "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
        "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
        "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
        "Michael Roberts - murder suspect, victim, hacker, PI",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
        "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
        "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
        "a.nel.cloudflare.com / api.w.org",
        "miles.ns.cloudflare.com",
        "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki",
        "https://www.google.com/?authuser=0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "LolKek",
          "display_name": "LolKek",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "TrojanClicker",
          "display_name": "TrojanClicker",
          "target": null
        },
        {
          "id": "Win32:Malware-gen",
          "display_name": "Win32:Malware-gen",
          "target": null
        },
        {
          "id": "ALFPER:InstallCapital",
          "display_name": "ALFPER:InstallCapital",
          "target": null
        },
        {
          "id": "VirTool:MSIL/CryptInject.CF!MTB",
          "display_name": "VirTool:MSIL/CryptInject.CF!MTB",
          "target": "/malware/VirTool:MSIL/CryptInject.CF!MTB"
        },
        {
          "id": "Win.Malware.Downloadguide-6803841-0",
          "display_name": "Win.Malware.Downloadguide-6803841-0",
          "target": null
        },
        {
          "id": "Win.Packed.kkrunchy-7049457-1",
          "display_name": "Win.Packed.kkrunchy-7049457-1",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
          "display_name": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Upatre.A",
          "display_name": "TrojanDownloader:Win32/Upatre.A",
          "target": "/malware/TrojanDownloader:Win32/Upatre.A"
        },
        {
          "id": "Trojan:Win32/Qbot.R!MTB",
          "display_name": "Trojan:Win32/Qbot.R!MTB",
          "target": "/malware/Trojan:Win32/Qbot.R!MTB"
        },
        {
          "id": "ALF:HeraklezEval:Trojan:BAT/Musecador",
          "display_name": "ALF:HeraklezEval:Trojan:BAT/Musecador",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Wabot.A",
          "display_name": "Backdoor:Win32/Wabot.A",
          "target": "/malware/Backdoor:Win32/Wabot.A"
        },
        {
          "id": "Ransom:Win32/G And Crab!rfn",
          "display_name": "Ransom:Win32/G And Crab!rfn",
          "target": "/malware/Ransom:Win32/G And Crab!rfn"
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "Tofsee",
          "display_name": "Tofsee",
          "target": null
        },
        {
          "id": "#Lowfi:FOP:VirTool:Win32/Injector",
          "display_name": "#Lowfi:FOP:VirTool:Win32/Injector",
          "target": null
        },
        {
          "id": "Nanocore RAT",
          "display_name": "Nanocore RAT",
          "target": null
        },
        {
          "id": "Worm:Win32/Fesber.A",
          "display_name": "Worm:Win32/Fesber.A",
          "target": "/malware/Worm:Win32/Fesber.A"
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
          "display_name": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
          "target": null
        },
        {
          "id": "InstallBrain",
          "display_name": "InstallBrain",
          "target": null
        },
        {
          "id": "InstallCore",
          "display_name": "InstallCore",
          "target": null
        },
        {
          "id": "Ghost RAT",
          "display_name": "Ghost RAT",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Occamy",
          "display_name": "Occamy",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "TrojanSpy:Win32/Bradesco",
          "display_name": "TrojanSpy:Win32/Bradesco",
          "target": "/malware/TrojanSpy:Win32/Bradesco"
        },
        {
          "id": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
          "display_name": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1415",
          "name": "URL Scheme Hijacking",
          "display_name": "T1415 - URL Scheme Hijacking"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1122",
          "name": "Component Object Model Hijacking",
          "display_name": "T1122 - Component Object Model Hijacking"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.003",
          "name": "Mail Protocols",
          "display_name": "T1071.003 - Mail Protocols"
        },
        {
          "id": "T1030",
          "name": "Data Transfer Size Limits",
          "display_name": "T1030 - Data Transfer Size Limits"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 26,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 143,
        "FileHash-SHA1": 130,
        "FileHash-SHA256": 1524,
        "URL": 3340,
        "domain": 1735,
        "hostname": 1398,
        "CVE": 1,
        "email": 6,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 8279,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 219,
      "modified_text": "796 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65acace20c18a7d6c5da2e27",
      "name": "VirTool:Win32/AccessMe | Ghost RAT",
      "description": "",
      "modified": "2024-02-13T00:04:59.507000",
      "created": "2024-01-21T05:34:26.800000",
      "tags": [
        "threat",
        "feeds ioc",
        "new ioc",
        "teams api",
        "contact",
        "paste",
        "iocs",
        "analyze",
        "ssl certificate",
        "whois record",
        "historical ssl",
        "resolutions",
        "referrer",
        "whois whois",
        "communicating",
        "contacted",
        "family",
        "roots",
        "lolkek",
        "redline stealer",
        "hacktool",
        "html info",
        "title rexxfield",
        "services",
        "identify",
        "meta tags",
        "rexxfield cyber",
        "investigation",
        "divi child",
        "site kit",
        "google",
        "united",
        "unknown",
        "as24940 hetzner",
        "germany unknown",
        "passive dns",
        "urls",
        "title",
        "moved",
        "scan endpoints",
        "all octoseek",
        "body",
        "cyber stalking",
        "pornographer",
        "urls url",
        "files",
        "ip address",
        "execution",
        "metro",
        "medium",
        "show",
        "search",
        "ids detections",
        "yara detections",
        "win32",
        "ppi useragent",
        "installcapital",
        "http",
        "packing t1045",
        "malware",
        "write",
        "obsession",
        "malvertizing",
        "masquerading",
        "ipv4",
        "pulse submit",
        "url analysis",
        "cookie",
        "status",
        "domain",
        "creation date",
        "trojan",
        "date",
        "expiration date",
        "name servers",
        "trojanclicker",
        "encrypt",
        "error",
        "ransomware",
        "malware generator",
        "meta",
        "for privacy",
        "aaaa",
        "komodo",
        "asnone united",
        "alfper",
        "as22612",
        "nxdomain",
        "gmt x",
        "ransom",
        "virtool",
        "log id",
        "gmtn",
        "digicert tls",
        "rsa sha256",
        "tls web",
        "full name",
        "digicert inc",
        "california",
        "false",
        "pulse pulses",
        "location united",
        "as16276",
        "as14061",
        "code",
        "next",
        "url http",
        "hostname",
        "files domain",
        "files related",
        "ghost rat",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "redlinestealer",
        "installcore",
        "installbrain",
        "emotet",
        "tofsee",
        "bradesco",
        "agent tesla",
        "trojanspy",
        "suppobox",
        "occamy",
        "dnspionage",
        "stealer",
        "networm",
        "as13414 twitter",
        "as32934",
        "script urls",
        "a domains",
        "worm",
        "entries",
        "meta http",
        "window",
        "select contact",
        "domain holder",
        "nexus category",
        "tackle company",
        "postal code",
        "component loop",
        "apache",
        "pragma",
        "value0",
        "ioc search",
        "threat analyzer",
        "hostnames",
        "dangerous",
        "target",
        "targeting",
        "hacker profile",
        "cybercrime",
        "fraud services",
        "strange",
        "tsara brashears",
        "michael roberts",
        "tracey richter",
        "voyeurism",
        "slander",
        "password",
        "hijacker"
      ],
      "references": [
        "https://rexxfield.com/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
        "www.akhaltsikhe.gov.ge [Germany?]",
        "screencasts.rexxfield.com",
        "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
        "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
        "94.130.71.173 [scanning host]",
        "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
        "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
        "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
        "Michael Roberts - murder suspect, victim, hacker, PI",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
        "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
        "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
        "a.nel.cloudflare.com / api.w.org",
        "miles.ns.cloudflare.com",
        "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki",
        "https://www.google.com/?authuser=0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "LolKek",
          "display_name": "LolKek",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "TrojanClicker",
          "display_name": "TrojanClicker",
          "target": null
        },
        {
          "id": "Win32:Malware-gen",
          "display_name": "Win32:Malware-gen",
          "target": null
        },
        {
          "id": "ALFPER:InstallCapital",
          "display_name": "ALFPER:InstallCapital",
          "target": null
        },
        {
          "id": "VirTool:MSIL/CryptInject.CF!MTB",
          "display_name": "VirTool:MSIL/CryptInject.CF!MTB",
          "target": "/malware/VirTool:MSIL/CryptInject.CF!MTB"
        },
        {
          "id": "Win.Malware.Downloadguide-6803841-0",
          "display_name": "Win.Malware.Downloadguide-6803841-0",
          "target": null
        },
        {
          "id": "Win.Packed.kkrunchy-7049457-1",
          "display_name": "Win.Packed.kkrunchy-7049457-1",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
          "display_name": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Upatre.A",
          "display_name": "TrojanDownloader:Win32/Upatre.A",
          "target": "/malware/TrojanDownloader:Win32/Upatre.A"
        },
        {
          "id": "Trojan:Win32/Qbot.R!MTB",
          "display_name": "Trojan:Win32/Qbot.R!MTB",
          "target": "/malware/Trojan:Win32/Qbot.R!MTB"
        },
        {
          "id": "ALF:HeraklezEval:Trojan:BAT/Musecador",
          "display_name": "ALF:HeraklezEval:Trojan:BAT/Musecador",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Wabot.A",
          "display_name": "Backdoor:Win32/Wabot.A",
          "target": "/malware/Backdoor:Win32/Wabot.A"
        },
        {
          "id": "Ransom:Win32/G And Crab!rfn",
          "display_name": "Ransom:Win32/G And Crab!rfn",
          "target": "/malware/Ransom:Win32/G And Crab!rfn"
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "Tofsee",
          "display_name": "Tofsee",
          "target": null
        },
        {
          "id": "#Lowfi:FOP:VirTool:Win32/Injector",
          "display_name": "#Lowfi:FOP:VirTool:Win32/Injector",
          "target": null
        },
        {
          "id": "Nanocore RAT",
          "display_name": "Nanocore RAT",
          "target": null
        },
        {
          "id": "Worm:Win32/Fesber.A",
          "display_name": "Worm:Win32/Fesber.A",
          "target": "/malware/Worm:Win32/Fesber.A"
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
          "display_name": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
          "target": null
        },
        {
          "id": "InstallBrain",
          "display_name": "InstallBrain",
          "target": null
        },
        {
          "id": "InstallCore",
          "display_name": "InstallCore",
          "target": null
        },
        {
          "id": "Ghost RAT",
          "display_name": "Ghost RAT",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Occamy",
          "display_name": "Occamy",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "TrojanSpy:Win32/Bradesco",
          "display_name": "TrojanSpy:Win32/Bradesco",
          "target": "/malware/TrojanSpy:Win32/Bradesco"
        },
        {
          "id": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
          "display_name": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1415",
          "name": "URL Scheme Hijacking",
          "display_name": "T1415 - URL Scheme Hijacking"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1122",
          "name": "Component Object Model Hijacking",
          "display_name": "T1122 - Component Object Model Hijacking"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.003",
          "name": "Mail Protocols",
          "display_name": "T1071.003 - Mail Protocols"
        },
        {
          "id": "T1030",
          "name": "Data Transfer Size Limits",
          "display_name": "T1030 - Data Transfer Size Limits"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65a342310ab3d2c69778d608",
      "export_count": 24,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 143,
        "FileHash-SHA1": 130,
        "FileHash-SHA256": 1524,
        "URL": 3340,
        "domain": 1735,
        "hostname": 1398,
        "CVE": 1,
        "email": 6,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 8279,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 219,
      "modified_text": "796 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65afc9cf333bbda03a18e03c",
      "name": "VirTool:Win32/AccessMe | Ghost RAT",
      "description": "",
      "modified": "2024-02-13T00:04:59.507000",
      "created": "2024-01-23T14:14:39.725000",
      "tags": [
        "threat",
        "feeds ioc",
        "new ioc",
        "teams api",
        "contact",
        "paste",
        "iocs",
        "analyze",
        "ssl certificate",
        "whois record",
        "historical ssl",
        "resolutions",
        "referrer",
        "whois whois",
        "communicating",
        "contacted",
        "family",
        "roots",
        "lolkek",
        "redline stealer",
        "hacktool",
        "html info",
        "title rexxfield",
        "services",
        "identify",
        "meta tags",
        "rexxfield cyber",
        "investigation",
        "divi child",
        "site kit",
        "google",
        "united",
        "unknown",
        "as24940 hetzner",
        "germany unknown",
        "passive dns",
        "urls",
        "title",
        "moved",
        "scan endpoints",
        "all octoseek",
        "body",
        "cyber stalking",
        "pornographer",
        "urls url",
        "files",
        "ip address",
        "execution",
        "metro",
        "medium",
        "show",
        "search",
        "ids detections",
        "yara detections",
        "win32",
        "ppi useragent",
        "installcapital",
        "http",
        "packing t1045",
        "malware",
        "write",
        "obsession",
        "malvertizing",
        "masquerading",
        "ipv4",
        "pulse submit",
        "url analysis",
        "cookie",
        "status",
        "domain",
        "creation date",
        "trojan",
        "date",
        "expiration date",
        "name servers",
        "trojanclicker",
        "encrypt",
        "error",
        "ransomware",
        "malware generator",
        "meta",
        "for privacy",
        "aaaa",
        "komodo",
        "asnone united",
        "alfper",
        "as22612",
        "nxdomain",
        "gmt x",
        "ransom",
        "virtool",
        "log id",
        "gmtn",
        "digicert tls",
        "rsa sha256",
        "tls web",
        "full name",
        "digicert inc",
        "california",
        "false",
        "pulse pulses",
        "location united",
        "as16276",
        "as14061",
        "code",
        "next",
        "url http",
        "hostname",
        "files domain",
        "files related",
        "ghost rat",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "redlinestealer",
        "installcore",
        "installbrain",
        "emotet",
        "tofsee",
        "bradesco",
        "agent tesla",
        "trojanspy",
        "suppobox",
        "occamy",
        "dnspionage",
        "stealer",
        "networm",
        "as13414 twitter",
        "as32934",
        "script urls",
        "a domains",
        "worm",
        "entries",
        "meta http",
        "window",
        "select contact",
        "domain holder",
        "nexus category",
        "tackle company",
        "postal code",
        "component loop",
        "apache",
        "pragma",
        "value0",
        "ioc search",
        "threat analyzer",
        "hostnames",
        "dangerous",
        "target",
        "targeting",
        "hacker profile",
        "cybercrime",
        "fraud services",
        "strange",
        "tsara brashears",
        "michael roberts",
        "tracey richter",
        "voyeurism",
        "slander",
        "password",
        "hijacker"
      ],
      "references": [
        "https://rexxfield.com/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian | OS & iOS Password and Password Cracker",
        "www.akhaltsikhe.gov.ge [Germany?]",
        "screencasts.rexxfield.com",
        "https://rexxfield.com [ hmmm...inc.legal] is Alienvault a subsidiary of Rexxfields unwarranted investigation/spy campaign? Confused",
        "https://www.akhaltsikhe.gov.ge/ | GMT Server LiteSpeed location",
        "94.130.71.173 [scanning host]",
        "http://www.objectaid.com/update/current/p2.index [AIN Phishing IOC's]",
        "https://www.couriermail.com.au/ipad/custody-bid-strands-family/news-story/23c2c9a5fc984edc04d29655c641f484",
        "Michael Roberts Australia, Germany, Iowa, New York Friend of Ben",
        "Michael Roberts - murder suspect, victim, hacker, PI",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [text, email, collection]",
        "https://ladys.one/xxx/a-tsara-brashears-zafira-porn",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net [BitCoinAussie ?]",
        "98cc05d9c12c214deadfe71af22cd3862e7417c0 [backdoor | PPI User-Agent (InstallCapital)]",
        "a.nel.cloudflare.com / api.w.org",
        "miles.ns.cloudflare.com",
        "https://otx.alienvault.com/indicator/url/https://media.toxtren.com/redirect.aspx?pid=272789&&bid=1971&&lpid=2119&&subid=18b8dh9scxi7sbl11f&&sref=inhousecpa&&inhousecpa=Kiev_Dima_BR_Setki",
        "https://www.google.com/?authuser=0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "LolKek",
          "display_name": "LolKek",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "TrojanClicker",
          "display_name": "TrojanClicker",
          "target": null
        },
        {
          "id": "Win32:Malware-gen",
          "display_name": "Win32:Malware-gen",
          "target": null
        },
        {
          "id": "ALFPER:InstallCapital",
          "display_name": "ALFPER:InstallCapital",
          "target": null
        },
        {
          "id": "VirTool:MSIL/CryptInject.CF!MTB",
          "display_name": "VirTool:MSIL/CryptInject.CF!MTB",
          "target": "/malware/VirTool:MSIL/CryptInject.CF!MTB"
        },
        {
          "id": "Win.Malware.Downloadguide-6803841-0",
          "display_name": "Win.Malware.Downloadguide-6803841-0",
          "target": null
        },
        {
          "id": "Win.Packed.kkrunchy-7049457-1",
          "display_name": "Win.Packed.kkrunchy-7049457-1",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
          "display_name": "ALF:HeraklezEval:SoftwareBundler:Win32/Prepscram",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Upatre.A",
          "display_name": "TrojanDownloader:Win32/Upatre.A",
          "target": "/malware/TrojanDownloader:Win32/Upatre.A"
        },
        {
          "id": "Trojan:Win32/Qbot.R!MTB",
          "display_name": "Trojan:Win32/Qbot.R!MTB",
          "target": "/malware/Trojan:Win32/Qbot.R!MTB"
        },
        {
          "id": "ALF:HeraklezEval:Trojan:BAT/Musecador",
          "display_name": "ALF:HeraklezEval:Trojan:BAT/Musecador",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Wabot.A",
          "display_name": "Backdoor:Win32/Wabot.A",
          "target": "/malware/Backdoor:Win32/Wabot.A"
        },
        {
          "id": "Ransom:Win32/G And Crab!rfn",
          "display_name": "Ransom:Win32/G And Crab!rfn",
          "target": "/malware/Ransom:Win32/G And Crab!rfn"
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "Tofsee",
          "display_name": "Tofsee",
          "target": null
        },
        {
          "id": "#Lowfi:FOP:VirTool:Win32/Injector",
          "display_name": "#Lowfi:FOP:VirTool:Win32/Injector",
          "target": null
        },
        {
          "id": "Nanocore RAT",
          "display_name": "Nanocore RAT",
          "target": null
        },
        {
          "id": "Worm:Win32/Fesber.A",
          "display_name": "Worm:Win32/Fesber.A",
          "target": "/malware/Worm:Win32/Fesber.A"
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
          "display_name": "#LowFi:HSTR:TrojanSpy:Win32/Xtrat",
          "target": null
        },
        {
          "id": "InstallBrain",
          "display_name": "InstallBrain",
          "target": null
        },
        {
          "id": "InstallCore",
          "display_name": "InstallCore",
          "target": null
        },
        {
          "id": "Ghost RAT",
          "display_name": "Ghost RAT",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Occamy",
          "display_name": "Occamy",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "TrojanSpy:Win32/Bradesco",
          "display_name": "TrojanSpy:Win32/Bradesco",
          "target": "/malware/TrojanSpy:Win32/Bradesco"
        },
        {
          "id": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
          "display_name": "ALF:HeraklezEval:TrojanClicker:JS/Faceliker",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1415",
          "name": "URL Scheme Hijacking",
          "display_name": "T1415 - URL Scheme Hijacking"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1122",
          "name": "Component Object Model Hijacking",
          "display_name": "T1122 - Component Object Model Hijacking"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.003",
          "name": "Mail Protocols",
          "display_name": "T1071.003 - Mail Protocols"
        },
        {
          "id": "T1030",
          "name": "Data Transfer Size Limits",
          "display_name": "T1030 - Data Transfer Size Limits"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65acace20c18a7d6c5da2e27",
      "export_count": 26,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 143,
        "FileHash-SHA1": 130,
        "FileHash-SHA256": 1524,
        "URL": 3340,
        "domain": 1735,
        "hostname": 1398,
        "CVE": 1,
        "email": 6,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 8279,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 225,
      "modified_text": "796 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a161f0681f4ff3d67feb",
      "name": "Pool's Closed (by @scnrscnr)",
      "description": "",
      "modified": "2023-12-06T16:29:21.844000",
      "created": "2023-12-06T16:29:21.844000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 7844,
        "FileHash-MD5": 562,
        "FileHash-SHA1": 429,
        "URL": 22749,
        "hostname": 9461,
        "domain": 4578,
        "SSLCertFingerprint": 20,
        "CIDR": 32,
        "email": 3,
        "CVE": 2
      },
      "indicator_count": 45680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a145926a5676de0e2a1a",
      "name": "Pool's Closed (by @scnrscnr)",
      "description": "",
      "modified": "2023-12-06T16:28:53.979000",
      "created": "2023-12-06T16:28:53.979000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 7844,
        "FileHash-MD5": 562,
        "FileHash-SHA1": 429,
        "URL": 22749,
        "hostname": 9461,
        "domain": 4578,
        "SSLCertFingerprint": 20,
        "CIDR": 32,
        "email": 3,
        "CVE": 2
      },
      "indicator_count": 45680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707b9630308cb99a817277",
      "name": "Pool's Closed",
      "description": "",
      "modified": "2023-12-06T13:48:06.514000",
      "created": "2023-12-06T13:48:06.514000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 7844,
        "FileHash-MD5": 562,
        "FileHash-SHA1": 429,
        "URL": 22749,
        "hostname": 9461,
        "domain": 4578,
        "SSLCertFingerprint": 20,
        "CIDR": 32,
        "email": 3,
        "CVE": 2
      },
      "indicator_count": 45680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.thaismileair.com/...",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.thaismileair.com/...",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776640878.8755276
}