{
  "type": "URL",
  "indicator": "https://www.turbo.net/enterprise",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.turbo.net/enterprise",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3617257014,
      "indicator": "https://www.turbo.net/enterprise",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "65eedf74b7bdda41057bef3e",
          "name": "Source Browse- DNS poisoning \u2022 Device CnC",
          "description": "Smear + Fear campaign. Parked domain schemes.   Swatting, social engineering, crime staging/framing.  Cyber bully,  shocking, false online content, posters, porn dumping,  injection, CnC devices, master keys, break  & enter. Victim becomes the accused. Framing.  Ability to close bank accounts, skim, call, text, email collection, redirect phone calls, create botnets, engineer malware, injection,divert tax refunds, divert funds, royalties, mail erase job history, attack, hospital, CnC event, IRS audits, fake documentaries, stalkers, attackers, death threats.  MD articulated outcome after being SA'd by their employee they vowed to protect.",
          "modified": "2024-04-10T09:00:27.994000",
          "created": "2024-03-11T10:39:48.949000",
          "tags": [
            "iocs",
            "all octoseek",
            "blacklist https",
            "gmbh version",
            "legal",
            "service privacy",
            "general full",
            "reverse dns",
            "san francisco",
            "asn13335",
            "cloudflarenet",
            "cloudflare",
            "domains",
            "service privacy",
            "modernizr",
            "domainpath name",
            "migrate",
            "phishing",
            "url https",
            "united",
            "line",
            "threat",
            "paste",
            "analyze",
            "value",
            "z6s3i string",
            "a7i string",
            "y3i string",
            "e0b function",
            "x8i string",
            "source level",
            "threat analyzer",
            "urls https",
            "domain",
            "webzilla",
            "cloudflar",
            "system",
            "hostnames",
            "sample",
            "security tls",
            "ecdheecdsa",
            "resource",
            "hash",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "veryhigh",
            "limited",
            "lsalford",
            "ocomodo ca",
            "cncomodo ecc",
            "secure server",
            "olet",
            "encrypt",
            "cnlet",
            "identity search",
            "group",
            "google https",
            "expired",
            "comodo",
            "tls web",
            "log id",
            "criteria id",
            "1663014711",
            "summary leaf",
            "timestamp entry",
            "log operator",
            "error",
            "name size",
            "parent",
            "directory",
            "displays",
            "targets",
            "smartfolder",
            "frame",
            "bookmarks",
            "splitcount",
            "nib files",
            "design",
            "boundsstr",
            "rows",
            "source browser",
            "ruby logo",
            "license",
            "python",
            "python software",
            "foundation",
            "apple inc",
            "php logo",
            "visit",
            "valid",
            "no na",
            "no no",
            "ip security",
            "ca id",
            "research group",
            "cnisrg root",
            "mozilla",
            "android",
            "binrm",
            "targetdisk",
            "create",
            "crlcachedir",
            "makefile",
            "dstroot",
            "keychainssrc",
            "srcroot",
            "crl cache",
            "install",
            "ev server",
            "authentication",
            "subject",
            "digicert https",
            "sectigo https",
            "certificate",
            "ca limited",
            "salford",
            "greater",
            "key usage",
            "access",
            "ca issuers",
            "ocsp",
            "x509v3 subject",
            "lets",
            "identifier",
            "411260982",
            "poison",
            "search",
            "status page",
            "impressum",
            "protocol h2",
            "main",
            "framing",
            "geoip",
            "as13335",
            "centos",
            "as32244",
            "liquidweb",
            "redirect",
            "as16509",
            "as133618",
            "z6s3i y3i",
            "as62597",
            "france unknown",
            "showing",
            "link",
            "z6s3i",
            "date",
            "unknown",
            "meta",
            "sha256",
            "google safe",
            "browsing",
            "hostname",
            "samples",
            "td td",
            "tr tr",
            "a td",
            "a domains",
            "passive dns",
            "a th",
            "urls",
            "as50295 triple",
            "triple mirrors",
            "contact",
            "moved",
            "show",
            "accept",
            "body",
            "microsoft",
            "e4609l",
            "urls http",
            "yoa https",
            "url http",
            "scan endpoints",
            "report spam",
            "created",
            "weeks ago",
            "pulse",
            "brashears",
            "xvideos",
            "capture",
            "expiration",
            "no expiration",
            "entries",
            "status",
            "as58110 ip",
            "for privacy",
            "aaaa",
            "creation date",
            "domain name",
            "germany unknown",
            "bq mar",
            "ipv4",
            "pulse pulses",
            "files",
            "artro",
            "files domain",
            "files related",
            "pulses otx",
            "pulses",
            "tags",
            "servers",
            "record value",
            "body doctype",
            "html public",
            "macintosh",
            "intel mac",
            "os x",
            "technology",
            "dns replication",
            "email",
            "server",
            "registrar abuse",
            "dnssec",
            "expiration date",
            "registrar iana",
            "admin country",
            "tech country",
            "registry admin",
            "url text",
            "facebook url",
            "google url",
            "google",
            "software",
            "asn15169",
            "ip https",
            "february",
            "request chain",
            "http",
            "referer",
            "aes128gcm",
            "pragma",
            "frankfurt",
            "germany",
            "asn213250",
            "itpsolutions",
            "full url",
            "software caddy",
            "express",
            "ubuntu",
            "as14061",
            "digitaloceanasn",
            "address as",
            "april",
            "facebook",
            "march",
            "hashes",
            "ip address",
            "as autonomous",
            "fastly",
            "packet",
            "kb script",
            "b script",
            "october",
            "resource path",
            "size",
            "type mimetype",
            "redirect chain",
            "kb image",
            "b image",
            "cname",
            "as32244 liquid",
            "trojan",
            "high",
            "yara rule",
            "sniffs",
            "windows",
            "anomalous file",
            "medium",
            "guard",
            "filehash",
            "js user",
            "python connection",
            "brian sabey",
            "smithtech",
            "rexxfield",
            "connect facebook",
            "open",
            "emails",
            "next",
            "ssl certificate",
            "contacted",
            "whois record",
            "referrer",
            "historical ssl",
            "resolutions",
            "execution",
            "whois whois",
            "contacted urls",
            "linkid69157 url",
            "formbook",
            "spyware",
            "generic malware",
            "tag count",
            "sat jul",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "generic",
            "alerts",
            "icmp traffic",
            "cust exe",
            "depot tech",
            "office depot",
            "tech",
            "customer client",
            "june",
            "copy",
            "network_icmp",
            "inject-x64.exe",
            "tsara brashears",
            "apple ios",
            "hacktool",
            "download",
            "malware",
            "relic",
            "monitoring",
            "tofsee",
            "https://otx.alienvault.com/pulse/65acace20c18a7d6c5da2e27",
            "darklivity",
            "hijacker",
            "remote attackers",
            "cybercrime",
            "fear factor",
            "criminal gang",
            "jeffrey reimer",
            "miles it",
            "history killer",
            "apple",
            "apple control",
            "sreredrum",
            "men",
            "man",
            "hit"
          ],
          "references": [
            "videolal.com [Exploitation for privilege - Turns victim into target then spys, smears, embeds pornography in devices]",
            "videolal.com was first found hosted : https://rexxfield.com/ | https://crt.sh/?id=410492573 | https://crt.sh/?id=411260982",
            "https://opensource.apple.com/source/security_certificates/security_certificates-2/security_certificates.xcode/michael.pbxuser.auto.html",
            "https://opensource.apple.com/source/security_certificates/security_certificates-2/security_certificates.xcode/",
            "https://opensource.apple.com/source/security_certificates/security_certificates-2/security_certificates.xcode/project.pbxproj.auto.html",
            "https://opensource.apple.com/source/security_certificates/security_certificates-2/roots/",
            "https://crt.sh/?q=videolal.com",
            "https://opensource.apple.com/source/security_certificates/security_certificates-2/Makefile.auto.html",
            "https://opensource.apple.com/source/security_certificates/",
            "https://crt.sh/?q=videolal.com",
            "https://crt.sh/?graph=410492573&opt=nometadata",
            "https://crt.sh/?spkisha256=2c5ef644a15ed2d591aee707a125b2870da480a0bc16d78022a311c93aca5b15",
            "Tracey Richter smear included Brashears: http://video-lal.com/video/26kiRlUTTmGzje2/diabolical-women-tracey-richter-s1-e2?cpc=n",
            "Tracey Richter smear:  video-lal.com/videos/diabolical-sentencing.html",
            "Tracey Richter smear:  video-lal.com/video/26kiRlUTTmGzje2/diabolical-women-tracey-richter-s1-e2?cpc=n",
            "Tracey Richter smear: video-lal.com/video/fbcwPGTSo5lrA7e/tracey-richter-documentary?cpc=no",
            "Malware hosting: http://videolan.mirror.triple-it.nl/vlc-android/3.0.4/VLC-Android-3.0.4-ARMv7.apk",
            "video-lal.com/videos/sandra-richter-video.html",
            "Denver Attorney Frank Azar Smear: video-lal.com/videos/sherryce-emery-frank-azar-&-associates.html",
            "Brashears smear: video-lal.com/videos/tsara-brashears-dead-by-daylight.html",
            "http://tx-p2p-pull.video-voip.com.dorm.com/Accept-Language",
            "Crazy: video-lal.com/videos/michael-roberts.html",
            "https://urlscan.io/screenshots/e40cd846-7c34-45a5-9f79-fea139f5b1ee.png",
            "http://secure.applegiftcard.com \u2022 199.59.243.224: http://tx-p2p-pull.video-voip.com.dorm.com \u2022 199.59.243.224: http://wpad.dorm.com",
            "notonmytrack.info \u2022 http://notonmytrack.info \u2022 https://pochta-rf.ru/track74157857 \u2022 patch-tracker.gnewsense.org \u2022 mysql.snore.co",
            "Darren Meade: https://urlscan.io/result/e5f1d6fe-036e-4291-8595-0a33e5dacba5/#behaviour \u2022 alleged partner turned enemy of Michael Roberts",
            "http://usb.smithtech.us/projects/downloads/shortcutcreator4u3-setup.exe | smithsthermopadtool.com",
            "http://usb.smithtech.us/projects/downloads/shortcutcreator4u3-setup.exe \u2022",
            "Unclear given names authentic. Michael Roberts, Darren Mitchell Meade , M. Brian Sabey could be used interchangeably. Black hats w/pseudonyms.",
            "Smith tech may refer to Det. Ben Smith. HallRender; a media company, producing nonsensical, albeit convincing evidence of deeply fake content.",
            "Possibly false names given by individual involved. Brian Sabey Hall Render | Michael Roberts Rexxfield |  Darren Meade former partner of Roberts",
            "Responsible reopening Richter case via alleged Detective Ben Smith | Names Below  linked to porn spewing Videolan , Videolal, Video-lal (Honeypots?) |",
            "http://www.hallrender.com/attorney/brian-sabey |",
            "Sabey: https://www.google.com/search?q=tsara+brashears&client=ms-android-tmus-us-rvc3&sca_esv=52c806ab62ec5c59&cs=1&prmd=inv&filter=0&biw=347&bih=710&dpr=2.08#ip=1",
            "https://www.hallrender.com/attorney/brian-sabey",
            "https://www.hallrender.com/wp-content/uploads/2017/10/Sabey_Brian_web-150x150.png | www.hallrender.com | rexxfield.com",
            "http://usb.smithtech.us  \u2022 http://usb.smithtech.us/apps/downloads/NSISPortable.exe \u2022 http://usb.smithtech.us/apps/downloads/xplorer2.lite.portable.exe",
            "http://usb.smithtech.us/projects/downloads/\u2022 http://usb.smithtech.us/projects/downloads/psu.exe \u2022 smithsthermopadtool.com",
            "servicer.mgid.com \u2022 http://iv-u15.com/imbd-104-\u00e9\u00bb\u2019\u00e5\u00ae\u00ae\u00e3\u201a\u0152\u00e3\u0081\u201e-\u00e5\u00a4\u008f\u00e5\u00b0\u2018\u00e5\u00a5\u00b3-\u00e9\u00bb\u2019\u00e5\u00ae\u00ae\u00e3\u201a\u0152\u00e3\u0081\u201e-blu-ray \u2022 https://load77.exelator.com/pixel.gif",
            "brain-portal.net",
            "303 Status. Ide redirect from: https://otx.alienvault.com/pulse/65e843669f4ba77affa4b297",
            "https://otx.alienvault.com/pulse/65e85fd4842119fff4e327cf",
            "https://otx.alienvault.com/pulse/64cf438a574eae18716e5954",
            "https://otx.alienvault.com/pulse/64d018ee4623e8fcd386c2e1",
            "https://otx.alienvault.com/pulse/65418472eb20b10ee5510fde",
            "https://otx.alienvault.com/pulse/64d65255c80d866add600bac",
            "https://otx.alienvault.com/pulse/65204565ac1e8bce4de26df3",
            "https://otx.alienvault.com/pulse/64cf438a574eae18716e5954",
            "https://otx.alienvault.com/pulse/65a342310ab3d2c69778d608",
            "Refuses to remove target from adult content \"tagging\""
          ],
          "public": 1,
          "adversary": "[Unnamed group]",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Artro",
              "display_name": "Artro",
              "target": null
            },
            {
              "id": "Generic",
              "display_name": "Generic",
              "target": null
            },
            {
              "id": "Win.Malware.Farfli-6824119-0",
              "display_name": "Win.Malware.Farfli-6824119-0",
              "target": null
            },
            {
              "id": "Win32:TrojanX-Gen[Trj]",
              "display_name": "Win32:TrojanX-Gen[Trj]",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1125",
              "name": "Video Capture",
              "display_name": "T1125 - Video Capture"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.003",
              "name": "Mail Protocols",
              "display_name": "T1071.003 - Mail Protocols"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059.006",
              "name": "Python",
              "display_name": "T1059.006 - Python"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1574.006",
              "name": "Dynamic Linker Hijacking",
              "display_name": "T1574.006 - Dynamic Linker Hijacking"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1444",
              "name": "Masquerade as Legitimate Application",
              "display_name": "T1444 - Masquerade as Legitimate Application"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1602.002",
              "name": "Network Device Configuration Dump",
              "display_name": "T1602.002 - Network Device Configuration Dump"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1156",
              "name": "Malicious Shell Modification",
              "display_name": "T1156 - Malicious Shell Modification"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 45,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 5328,
            "domain": 2339,
            "hostname": 2434,
            "FileHash-MD5": 1210,
            "FileHash-SHA1": 721,
            "FileHash-SHA256": 2784,
            "SSLCertFingerprint": 5,
            "CVE": 2,
            "URI": 2,
            "email": 10,
            "CIDR": 3
          },
          "indicator_count": 14838,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "781 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "658481716d9034bb0d52212d",
          "name": "Apple Attack | Floxif Spyware | Threat Network | Virus Network",
          "description": "Threat Network affecting and/or originating from Apple server. Malware attacks apple airpods, tv, apple store\napple trade, apple tv\napple watch, apple card, apple og?, apple server.\nSystemUpdate.dll issue. Device may partially attempt, device will show latest update, com[promised devices may have throttled update on attempt.\n\nFloxif:\nShort bio\nTrojan.Floxif is Malwarebytes\u2019 detection name for a file-changing Trojanthat targets Windows systems.\n\nSymptoms\nTrojan.Floxif can change legitimate files into infected files. Then the infected files act as a backdoor, giving the threat actor control over the machine.\n\nStaged data. Floxif primarily target Windows, Apple is less vulnerable to buy can be experience a Floxif attack.",
          "modified": "2024-01-20T14:03:29.247000",
          "created": "2023-12-21T18:18:25.746000",
          "tags": [
            "bitrep",
            "learn",
            "apple card",
            "apple",
            "apple store",
            "apple tv",
            "watch vision",
            "airpods tv",
            "apple watch",
            "buy apple",
            "apple trade",
            "footer",
            "media",
            "find",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "malicious site",
            "hostname",
            "hostnames",
            "detection list",
            "blacklist",
            "malware",
            "alexa",
            "ip address",
            "whois record",
            "ssl certificate",
            "iocs",
            "whois whois",
            "historical ssl",
            "communicating",
            "threat network",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "attack",
            "probe",
            "search",
            "threat",
            "paste",
            "contacted",
            "april",
            "threat roundup",
            "pe resource",
            "lcid1033",
            "smlen",
            "spn647",
            "bv6fet56ww",
            "february",
            "core",
            "name verdict",
            "falcon sandbox",
            "threat analyzer",
            "samples",
            "generic malware",
            "tag count",
            "malware generic",
            "tue dec",
            "threat report",
            "summary",
            "first",
            "http response",
            "final url",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "self",
            "server apple",
            "connection",
            "html info",
            "title apple",
            "meta tags",
            "indextab og",
            "apple og",
            "spyware",
            "plugins",
            "cab",
            "fraud urls",
            "data collection",
            "staged data",
            "privilege escalation",
            "defense evasion",
            "evasive",
            "stealthy",
            "serial number",
            "symantec time",
            "stamping",
            "algorithm",
            "thumbprint",
            "from",
            "symantec sha256",
            "sha256 code",
            "signing ca",
            "class",
            "vhash",
            "authentihash",
            "imphash",
            "rich pe",
            "ssdeep",
            "file type",
            "win32 dll",
            "magic pe32",
            "intel",
            "ms windows",
            "compiler",
            "vs2008",
            "rticon english",
            "vs2005",
            "chi2",
            "contained",
            "info compiler",
            "products",
            "header target",
            "machine intel",
            "utc entry",
            "floxif",
            "serving ip",
            "address",
            "headers nel",
            "dynamic expires",
            "gmt server",
            "file sharing",
            "personal data"
          ],
          "references": [
            "https://www.apple.com/qtactivex/qtplugin.cab",
            "https://www.hybrid-analysis.com/sample/f9fab0bda2e82393cdcbb235dd41b48e00552116101deb0215bc64032741dcad",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/. [ phishing, driver, malvertizing, targeting]",
            "http://www.screensaver.com/ruxitbeacon",
            "https://otx.alienvault.com/indicator/hostname/ac-netstorage.apple.com [front facing withu4ever.com dating app/fraud service stores Apple data]",
            "http://dns1.whitelist.camect.com    [interesting]",
            "https://www.jbits.courts.state.co    [interesting]",
            "http://www.sos.state.co/                   [interesting]",
            "https://www.virustotal.com/gui/file/b883f5fab23c459f41dee72e3f89fc19734fa2f505cb5bee192960f4a0f94062/summary",
            "https://www.virustotal.com/gui/url/2cb82dbaba5c1a7ea415992f28e2d35d06187a8cfc59691b43c1589e072b2c24/summary",
            "Crowdsourced YARA  Rulesets",
            "Matches rule Malware_Floxif_mpsvc_dll from ruleset gen_floxif by Florian Roth (Nextron Systems",
            "Matches rule Windows_Virus_Floxif_493d1897 from ruleset Windows_Virus_Floxif by Elastic Security",
            "Matches rule SUSP_XORed_MSDOS_Stub_Message from ruleset gen_xor_hunting by Florian Roth",
            "https://www.malwarebytes.com/blog/detections/trojan-floxif",
            "20.190.160.2         Microsoft  [exploit_source]",
            "20.190.160.67       Microsoft  [exploit_source]",
            "20.190.160.73       Microsoft  [exploit_source]",
            "watson.events.data.microsoft.com      [traffic manager]",
            "http://watson.microsoft.com/StageOne/rundll32_exe/6_1_7600_16385/4a5bc637StackHash_2264/0_0_0_0/00000000/c0000005/63df0a5b.htm?LCID=1033&OS=6.1.7601.2.00010100.1.0.1.17514&SM=LEN&SPN=647&BV=6FET56WW&MID=54046387-FC68-43CA-9068-077C0A157181.   [stack hash]",
            "watson.telemetry.microsoft.us   [Data traffic manager]",
            "www.anyxxxtube.net [tracking]",
            "https://shitting.takefile.link/4cgeojxano82/2375.Kty10122__scatting__Shit-Porn.net_.mp4.html [file sharing, personal network storage and backup]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Malware",
              "display_name": "Malware",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Apple",
              "display_name": "Apple",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 609,
            "FileHash-SHA1": 361,
            "FileHash-SHA256": 1977,
            "domain": 460,
            "hostname": 992,
            "URL": 3115
          },
          "indicator_count": 7514,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "862 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63c8aad8061341d5fe0d2779",
          "name": "http://www.turbo.net",
          "description": "",
          "modified": "2023-02-18T02:02:05.208000",
          "created": "2023-01-19T02:28:40.802000",
          "tags": [
            "its all about the www",
            "4.53.147.210"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 195,
            "FileHash-SHA256": 275,
            "hostname": 39,
            "domain": 3,
            "FileHash-MD5": 18,
            "FileHash-SHA1": 17
          },
          "indicator_count": 547,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1199 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63c89fc0ebfc33dd4647631a",
          "name": "https://eye.sb03.netstart.spoon.net - hmmm",
          "description": "://myaccount.google.com/u/1/accountlinking?hl=en-GB",
          "modified": "2023-01-19T01:41:20.595000",
          "created": "2023-01-19T01:41:20.595000",
          "tags": [
            "retrieve registration code",
            "registration code retrieval",
            "faq center",
            "contact support team",
            "customer support",
            "proudct support",
            "support center",
            "code retrieve",
            "contact support",
            "team ask",
            "frequently",
            "://myaccount.google.com/u/1/accountlinking?hl=en-GB",
            "https://eye.sb03.netstart.spoon.net"
          ],
          "references": [
            "http://api.wondershare.com/resource/00",
            "If you want to use Wondershare Technology, you may need to sign up to our Member Zone or use our support centre to find out what to do with your computer or mobile phone, or to get help from our customer service.",
            "mobile.pipe.aria.microsoft.comstart.spoon.net",
            "://myaccount.google.com/u/1/accountlinking?hl=en-GB",
            "https://eye.sb03.netstart.spoon.net"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 82,
            "FileHash-SHA256": 34,
            "hostname": 13,
            "domain": 1
          },
          "indicator_count": 130,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1229 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://usb.smithtech.us/projects/downloads/shortcutcreator4u3-setup.exe | smithsthermopadtool.com",
        "video-lal.com/videos/sandra-richter-video.html",
        "https://otx.alienvault.com/pulse/65e85fd4842119fff4e327cf",
        "https://www.virustotal.com/gui/file/b883f5fab23c459f41dee72e3f89fc19734fa2f505cb5bee192960f4a0f94062/summary",
        "http://usb.smithtech.us/projects/downloads/\u2022 http://usb.smithtech.us/projects/downloads/psu.exe \u2022 smithsthermopadtool.com",
        "videolal.com was first found hosted : https://rexxfield.com/ | https://crt.sh/?id=410492573 | https://crt.sh/?id=411260982",
        "https://eye.sb03.netstart.spoon.net",
        "Brashears smear: video-lal.com/videos/tsara-brashears-dead-by-daylight.html",
        "Tracey Richter smear included Brashears: http://video-lal.com/video/26kiRlUTTmGzje2/diabolical-women-tracey-richter-s1-e2?cpc=n",
        "http://www.screensaver.com/ruxitbeacon",
        "Possibly false names given by individual involved. Brian Sabey Hall Render | Michael Roberts Rexxfield |  Darren Meade former partner of Roberts",
        "http://www.hallrender.com/attorney/brian-sabey |",
        "Matches rule SUSP_XORed_MSDOS_Stub_Message from ruleset gen_xor_hunting by Florian Roth",
        "https://www.hallrender.com/attorney/brian-sabey",
        "20.190.160.73       Microsoft  [exploit_source]",
        "https://crt.sh/?spkisha256=2c5ef644a15ed2d591aee707a125b2870da480a0bc16d78022a311c93aca5b15",
        "http://tx-p2p-pull.video-voip.com.dorm.com/Accept-Language",
        "mobile.pipe.aria.microsoft.comstart.spoon.net",
        "https://www.hybrid-analysis.com/sample/f9fab0bda2e82393cdcbb235dd41b48e00552116101deb0215bc64032741dcad",
        "http://www.sos.state.co/                   [interesting]",
        "https://otx.alienvault.com/pulse/64d018ee4623e8fcd386c2e1",
        "servicer.mgid.com \u2022 http://iv-u15.com/imbd-104-\u00e9\u00bb\u2019\u00e5\u00ae\u00ae\u00e3\u201a\u0152\u00e3\u0081\u201e-\u00e5\u00a4\u008f\u00e5\u00b0\u2018\u00e5\u00a5\u00b3-\u00e9\u00bb\u2019\u00e5\u00ae\u00ae\u00e3\u201a\u0152\u00e3\u0081\u201e-blu-ray \u2022 https://load77.exelator.com/pixel.gif",
        "http://usb.smithtech.us/projects/downloads/shortcutcreator4u3-setup.exe \u2022",
        "https://otx.alienvault.com/pulse/65418472eb20b10ee5510fde",
        "www.anyxxxtube.net [tracking]",
        "https://opensource.apple.com/source/security_certificates/security_certificates-2/security_certificates.xcode/project.pbxproj.auto.html",
        "Crazy: video-lal.com/videos/michael-roberts.html",
        "Responsible reopening Richter case via alleged Detective Ben Smith | Names Below  linked to porn spewing Videolan , Videolal, Video-lal (Honeypots?) |",
        "brain-portal.net",
        "Refuses to remove target from adult content \"tagging\"",
        "https://otx.alienvault.com/pulse/64cf438a574eae18716e5954",
        "http://usb.smithtech.us  \u2022 http://usb.smithtech.us/apps/downloads/NSISPortable.exe \u2022 http://usb.smithtech.us/apps/downloads/xplorer2.lite.portable.exe",
        "Crowdsourced YARA  Rulesets",
        "://myaccount.google.com/u/1/accountlinking?hl=en-GB",
        "https://crt.sh/?q=videolal.com",
        "Matches rule Windows_Virus_Floxif_493d1897 from ruleset Windows_Virus_Floxif by Elastic Security",
        "303 Status. Ide redirect from: https://otx.alienvault.com/pulse/65e843669f4ba77affa4b297",
        "https://otx.alienvault.com/pulse/64d65255c80d866add600bac",
        "Denver Attorney Frank Azar Smear: video-lal.com/videos/sherryce-emery-frank-azar-&-associates.html",
        "http://dns1.whitelist.camect.com    [interesting]",
        "watson.telemetry.microsoft.us   [Data traffic manager]",
        "http://secure.applegiftcard.com \u2022 199.59.243.224: http://tx-p2p-pull.video-voip.com.dorm.com \u2022 199.59.243.224: http://wpad.dorm.com",
        "20.190.160.67       Microsoft  [exploit_source]",
        "Tracey Richter smear:  video-lal.com/video/26kiRlUTTmGzje2/diabolical-women-tracey-richter-s1-e2?cpc=n",
        "https://www.virustotal.com/gui/url/2cb82dbaba5c1a7ea415992f28e2d35d06187a8cfc59691b43c1589e072b2c24/summary",
        "notonmytrack.info \u2022 http://notonmytrack.info \u2022 https://pochta-rf.ru/track74157857 \u2022 patch-tracker.gnewsense.org \u2022 mysql.snore.co",
        "https://www.hallrender.com/wp-content/uploads/2017/10/Sabey_Brian_web-150x150.png | www.hallrender.com | rexxfield.com",
        "https://www.jbits.courts.state.co    [interesting]",
        "Smith tech may refer to Det. Ben Smith. HallRender; a media company, producing nonsensical, albeit convincing evidence of deeply fake content.",
        "https://www.malwarebytes.com/blog/detections/trojan-floxif",
        "20.190.160.2         Microsoft  [exploit_source]",
        "Sabey: https://www.google.com/search?q=tsara+brashears&client=ms-android-tmus-us-rvc3&sca_esv=52c806ab62ec5c59&cs=1&prmd=inv&filter=0&biw=347&bih=710&dpr=2.08#ip=1",
        "If you want to use Wondershare Technology, you may need to sign up to our Member Zone or use our support centre to find out what to do with your computer or mobile phone, or to get help from our customer service.",
        "https://opensource.apple.com/source/security_certificates/security_certificates-2/security_certificates.xcode/michael.pbxuser.auto.html",
        "https://crt.sh/?graph=410492573&opt=nometadata",
        "Darren Meade: https://urlscan.io/result/e5f1d6fe-036e-4291-8595-0a33e5dacba5/#behaviour \u2022 alleged partner turned enemy of Michael Roberts",
        "https://otx.alienvault.com/pulse/65204565ac1e8bce4de26df3",
        "Matches rule Malware_Floxif_mpsvc_dll from ruleset gen_floxif by Florian Roth (Nextron Systems",
        "https://opensource.apple.com/source/security_certificates/security_certificates-2/security_certificates.xcode/",
        "Tracey Richter smear: video-lal.com/video/fbcwPGTSo5lrA7e/tracey-richter-documentary?cpc=no",
        "https://www.apple.com/qtactivex/qtplugin.cab",
        "https://otx.alienvault.com/pulse/65a342310ab3d2c69778d608",
        "Tracey Richter smear:  video-lal.com/videos/diabolical-sentencing.html",
        "https://otx.alienvault.com/indicator/hostname/ac-netstorage.apple.com [front facing withu4ever.com dating app/fraud service stores Apple data]",
        "Unclear given names authentic. Michael Roberts, Darren Mitchell Meade , M. Brian Sabey could be used interchangeably. Black hats w/pseudonyms.",
        "watson.events.data.microsoft.com      [traffic manager]",
        "videolal.com [Exploitation for privilege - Turns victim into target then spys, smears, embeds pornography in devices]",
        "http://watson.microsoft.com/StageOne/rundll32_exe/6_1_7600_16385/4a5bc637StackHash_2264/0_0_0_0/00000000/c0000005/63df0a5b.htm?LCID=1033&OS=6.1.7601.2.00010100.1.0.1.17514&SM=LEN&SPN=647&BV=6FET56WW&MID=54046387-FC68-43CA-9068-077C0A157181.   [stack hash]",
        "https://shitting.takefile.link/4cgeojxano82/2375.Kty10122__scatting__Shit-Porn.net_.mp4.html [file sharing, personal network storage and backup]",
        "https://opensource.apple.com/source/security_certificates/",
        "Malware hosting: http://videolan.mirror.triple-it.nl/vlc-android/3.0.4/VLC-Android-3.0.4-ARMv7.apk",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/. [ phishing, driver, malvertizing, targeting]",
        "https://urlscan.io/screenshots/e40cd846-7c34-45a5-9f79-fea139f5b1ee.png",
        "https://opensource.apple.com/source/security_certificates/security_certificates-2/roots/",
        "http://api.wondershare.com/resource/00",
        "https://opensource.apple.com/source/security_certificates/security_certificates-2/Makefile.auto.html"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "[Unnamed group]"
          ],
          "malware_families": [
            "Win.malware.farfli-6824119-0",
            "Malware",
            "Artro",
            "Tulach",
            "Generic",
            "Apple",
            "Win32:trojanx-gen[trj]"
          ],
          "industries": [],
          "unique_indicators": 23120
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/turbo.net",
    "whois": "http://whois.domaintools.com/turbo.net",
    "domain": "turbo.net",
    "hostname": "www.turbo.net"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "65eedf74b7bdda41057bef3e",
      "name": "Source Browse- DNS poisoning \u2022 Device CnC",
      "description": "Smear + Fear campaign. Parked domain schemes.   Swatting, social engineering, crime staging/framing.  Cyber bully,  shocking, false online content, posters, porn dumping,  injection, CnC devices, master keys, break  & enter. Victim becomes the accused. Framing.  Ability to close bank accounts, skim, call, text, email collection, redirect phone calls, create botnets, engineer malware, injection,divert tax refunds, divert funds, royalties, mail erase job history, attack, hospital, CnC event, IRS audits, fake documentaries, stalkers, attackers, death threats.  MD articulated outcome after being SA'd by their employee they vowed to protect.",
      "modified": "2024-04-10T09:00:27.994000",
      "created": "2024-03-11T10:39:48.949000",
      "tags": [
        "iocs",
        "all octoseek",
        "blacklist https",
        "gmbh version",
        "legal",
        "service privacy",
        "general full",
        "reverse dns",
        "san francisco",
        "asn13335",
        "cloudflarenet",
        "cloudflare",
        "domains",
        "service privacy",
        "modernizr",
        "domainpath name",
        "migrate",
        "phishing",
        "url https",
        "united",
        "line",
        "threat",
        "paste",
        "analyze",
        "value",
        "z6s3i string",
        "a7i string",
        "y3i string",
        "e0b function",
        "x8i string",
        "source level",
        "threat analyzer",
        "urls https",
        "domain",
        "webzilla",
        "cloudflar",
        "system",
        "hostnames",
        "sample",
        "security tls",
        "ecdheecdsa",
        "resource",
        "hash",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "veryhigh",
        "limited",
        "lsalford",
        "ocomodo ca",
        "cncomodo ecc",
        "secure server",
        "olet",
        "encrypt",
        "cnlet",
        "identity search",
        "group",
        "google https",
        "expired",
        "comodo",
        "tls web",
        "log id",
        "criteria id",
        "1663014711",
        "summary leaf",
        "timestamp entry",
        "log operator",
        "error",
        "name size",
        "parent",
        "directory",
        "displays",
        "targets",
        "smartfolder",
        "frame",
        "bookmarks",
        "splitcount",
        "nib files",
        "design",
        "boundsstr",
        "rows",
        "source browser",
        "ruby logo",
        "license",
        "python",
        "python software",
        "foundation",
        "apple inc",
        "php logo",
        "visit",
        "valid",
        "no na",
        "no no",
        "ip security",
        "ca id",
        "research group",
        "cnisrg root",
        "mozilla",
        "android",
        "binrm",
        "targetdisk",
        "create",
        "crlcachedir",
        "makefile",
        "dstroot",
        "keychainssrc",
        "srcroot",
        "crl cache",
        "install",
        "ev server",
        "authentication",
        "subject",
        "digicert https",
        "sectigo https",
        "certificate",
        "ca limited",
        "salford",
        "greater",
        "key usage",
        "access",
        "ca issuers",
        "ocsp",
        "x509v3 subject",
        "lets",
        "identifier",
        "411260982",
        "poison",
        "search",
        "status page",
        "impressum",
        "protocol h2",
        "main",
        "framing",
        "geoip",
        "as13335",
        "centos",
        "as32244",
        "liquidweb",
        "redirect",
        "as16509",
        "as133618",
        "z6s3i y3i",
        "as62597",
        "france unknown",
        "showing",
        "link",
        "z6s3i",
        "date",
        "unknown",
        "meta",
        "sha256",
        "google safe",
        "browsing",
        "hostname",
        "samples",
        "td td",
        "tr tr",
        "a td",
        "a domains",
        "passive dns",
        "a th",
        "urls",
        "as50295 triple",
        "triple mirrors",
        "contact",
        "moved",
        "show",
        "accept",
        "body",
        "microsoft",
        "e4609l",
        "urls http",
        "yoa https",
        "url http",
        "scan endpoints",
        "report spam",
        "created",
        "weeks ago",
        "pulse",
        "brashears",
        "xvideos",
        "capture",
        "expiration",
        "no expiration",
        "entries",
        "status",
        "as58110 ip",
        "for privacy",
        "aaaa",
        "creation date",
        "domain name",
        "germany unknown",
        "bq mar",
        "ipv4",
        "pulse pulses",
        "files",
        "artro",
        "files domain",
        "files related",
        "pulses otx",
        "pulses",
        "tags",
        "servers",
        "record value",
        "body doctype",
        "html public",
        "macintosh",
        "intel mac",
        "os x",
        "technology",
        "dns replication",
        "email",
        "server",
        "registrar abuse",
        "dnssec",
        "expiration date",
        "registrar iana",
        "admin country",
        "tech country",
        "registry admin",
        "url text",
        "facebook url",
        "google url",
        "google",
        "software",
        "asn15169",
        "ip https",
        "february",
        "request chain",
        "http",
        "referer",
        "aes128gcm",
        "pragma",
        "frankfurt",
        "germany",
        "asn213250",
        "itpsolutions",
        "full url",
        "software caddy",
        "express",
        "ubuntu",
        "as14061",
        "digitaloceanasn",
        "address as",
        "april",
        "facebook",
        "march",
        "hashes",
        "ip address",
        "as autonomous",
        "fastly",
        "packet",
        "kb script",
        "b script",
        "october",
        "resource path",
        "size",
        "type mimetype",
        "redirect chain",
        "kb image",
        "b image",
        "cname",
        "as32244 liquid",
        "trojan",
        "high",
        "yara rule",
        "sniffs",
        "windows",
        "anomalous file",
        "medium",
        "guard",
        "filehash",
        "js user",
        "python connection",
        "brian sabey",
        "smithtech",
        "rexxfield",
        "connect facebook",
        "open",
        "emails",
        "next",
        "ssl certificate",
        "contacted",
        "whois record",
        "referrer",
        "historical ssl",
        "resolutions",
        "execution",
        "whois whois",
        "contacted urls",
        "linkid69157 url",
        "formbook",
        "spyware",
        "generic malware",
        "tag count",
        "sat jul",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "generic",
        "alerts",
        "icmp traffic",
        "cust exe",
        "depot tech",
        "office depot",
        "tech",
        "customer client",
        "june",
        "copy",
        "network_icmp",
        "inject-x64.exe",
        "tsara brashears",
        "apple ios",
        "hacktool",
        "download",
        "malware",
        "relic",
        "monitoring",
        "tofsee",
        "https://otx.alienvault.com/pulse/65acace20c18a7d6c5da2e27",
        "darklivity",
        "hijacker",
        "remote attackers",
        "cybercrime",
        "fear factor",
        "criminal gang",
        "jeffrey reimer",
        "miles it",
        "history killer",
        "apple",
        "apple control",
        "sreredrum",
        "men",
        "man",
        "hit"
      ],
      "references": [
        "videolal.com [Exploitation for privilege - Turns victim into target then spys, smears, embeds pornography in devices]",
        "videolal.com was first found hosted : https://rexxfield.com/ | https://crt.sh/?id=410492573 | https://crt.sh/?id=411260982",
        "https://opensource.apple.com/source/security_certificates/security_certificates-2/security_certificates.xcode/michael.pbxuser.auto.html",
        "https://opensource.apple.com/source/security_certificates/security_certificates-2/security_certificates.xcode/",
        "https://opensource.apple.com/source/security_certificates/security_certificates-2/security_certificates.xcode/project.pbxproj.auto.html",
        "https://opensource.apple.com/source/security_certificates/security_certificates-2/roots/",
        "https://crt.sh/?q=videolal.com",
        "https://opensource.apple.com/source/security_certificates/security_certificates-2/Makefile.auto.html",
        "https://opensource.apple.com/source/security_certificates/",
        "https://crt.sh/?q=videolal.com",
        "https://crt.sh/?graph=410492573&opt=nometadata",
        "https://crt.sh/?spkisha256=2c5ef644a15ed2d591aee707a125b2870da480a0bc16d78022a311c93aca5b15",
        "Tracey Richter smear included Brashears: http://video-lal.com/video/26kiRlUTTmGzje2/diabolical-women-tracey-richter-s1-e2?cpc=n",
        "Tracey Richter smear:  video-lal.com/videos/diabolical-sentencing.html",
        "Tracey Richter smear:  video-lal.com/video/26kiRlUTTmGzje2/diabolical-women-tracey-richter-s1-e2?cpc=n",
        "Tracey Richter smear: video-lal.com/video/fbcwPGTSo5lrA7e/tracey-richter-documentary?cpc=no",
        "Malware hosting: http://videolan.mirror.triple-it.nl/vlc-android/3.0.4/VLC-Android-3.0.4-ARMv7.apk",
        "video-lal.com/videos/sandra-richter-video.html",
        "Denver Attorney Frank Azar Smear: video-lal.com/videos/sherryce-emery-frank-azar-&-associates.html",
        "Brashears smear: video-lal.com/videos/tsara-brashears-dead-by-daylight.html",
        "http://tx-p2p-pull.video-voip.com.dorm.com/Accept-Language",
        "Crazy: video-lal.com/videos/michael-roberts.html",
        "https://urlscan.io/screenshots/e40cd846-7c34-45a5-9f79-fea139f5b1ee.png",
        "http://secure.applegiftcard.com \u2022 199.59.243.224: http://tx-p2p-pull.video-voip.com.dorm.com \u2022 199.59.243.224: http://wpad.dorm.com",
        "notonmytrack.info \u2022 http://notonmytrack.info \u2022 https://pochta-rf.ru/track74157857 \u2022 patch-tracker.gnewsense.org \u2022 mysql.snore.co",
        "Darren Meade: https://urlscan.io/result/e5f1d6fe-036e-4291-8595-0a33e5dacba5/#behaviour \u2022 alleged partner turned enemy of Michael Roberts",
        "http://usb.smithtech.us/projects/downloads/shortcutcreator4u3-setup.exe | smithsthermopadtool.com",
        "http://usb.smithtech.us/projects/downloads/shortcutcreator4u3-setup.exe \u2022",
        "Unclear given names authentic. Michael Roberts, Darren Mitchell Meade , M. Brian Sabey could be used interchangeably. Black hats w/pseudonyms.",
        "Smith tech may refer to Det. Ben Smith. HallRender; a media company, producing nonsensical, albeit convincing evidence of deeply fake content.",
        "Possibly false names given by individual involved. Brian Sabey Hall Render | Michael Roberts Rexxfield |  Darren Meade former partner of Roberts",
        "Responsible reopening Richter case via alleged Detective Ben Smith | Names Below  linked to porn spewing Videolan , Videolal, Video-lal (Honeypots?) |",
        "http://www.hallrender.com/attorney/brian-sabey |",
        "Sabey: https://www.google.com/search?q=tsara+brashears&client=ms-android-tmus-us-rvc3&sca_esv=52c806ab62ec5c59&cs=1&prmd=inv&filter=0&biw=347&bih=710&dpr=2.08#ip=1",
        "https://www.hallrender.com/attorney/brian-sabey",
        "https://www.hallrender.com/wp-content/uploads/2017/10/Sabey_Brian_web-150x150.png | www.hallrender.com | rexxfield.com",
        "http://usb.smithtech.us  \u2022 http://usb.smithtech.us/apps/downloads/NSISPortable.exe \u2022 http://usb.smithtech.us/apps/downloads/xplorer2.lite.portable.exe",
        "http://usb.smithtech.us/projects/downloads/\u2022 http://usb.smithtech.us/projects/downloads/psu.exe \u2022 smithsthermopadtool.com",
        "servicer.mgid.com \u2022 http://iv-u15.com/imbd-104-\u00e9\u00bb\u2019\u00e5\u00ae\u00ae\u00e3\u201a\u0152\u00e3\u0081\u201e-\u00e5\u00a4\u008f\u00e5\u00b0\u2018\u00e5\u00a5\u00b3-\u00e9\u00bb\u2019\u00e5\u00ae\u00ae\u00e3\u201a\u0152\u00e3\u0081\u201e-blu-ray \u2022 https://load77.exelator.com/pixel.gif",
        "brain-portal.net",
        "303 Status. Ide redirect from: https://otx.alienvault.com/pulse/65e843669f4ba77affa4b297",
        "https://otx.alienvault.com/pulse/65e85fd4842119fff4e327cf",
        "https://otx.alienvault.com/pulse/64cf438a574eae18716e5954",
        "https://otx.alienvault.com/pulse/64d018ee4623e8fcd386c2e1",
        "https://otx.alienvault.com/pulse/65418472eb20b10ee5510fde",
        "https://otx.alienvault.com/pulse/64d65255c80d866add600bac",
        "https://otx.alienvault.com/pulse/65204565ac1e8bce4de26df3",
        "https://otx.alienvault.com/pulse/64cf438a574eae18716e5954",
        "https://otx.alienvault.com/pulse/65a342310ab3d2c69778d608",
        "Refuses to remove target from adult content \"tagging\""
      ],
      "public": 1,
      "adversary": "[Unnamed group]",
      "targeted_countries": [
        "Australia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Artro",
          "display_name": "Artro",
          "target": null
        },
        {
          "id": "Generic",
          "display_name": "Generic",
          "target": null
        },
        {
          "id": "Win.Malware.Farfli-6824119-0",
          "display_name": "Win.Malware.Farfli-6824119-0",
          "target": null
        },
        {
          "id": "Win32:TrojanX-Gen[Trj]",
          "display_name": "Win32:TrojanX-Gen[Trj]",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1125",
          "name": "Video Capture",
          "display_name": "T1125 - Video Capture"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.003",
          "name": "Mail Protocols",
          "display_name": "T1071.003 - Mail Protocols"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059.006",
          "name": "Python",
          "display_name": "T1059.006 - Python"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1574.006",
          "name": "Dynamic Linker Hijacking",
          "display_name": "T1574.006 - Dynamic Linker Hijacking"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1444",
          "name": "Masquerade as Legitimate Application",
          "display_name": "T1444 - Masquerade as Legitimate Application"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        },
        {
          "id": "T1602.002",
          "name": "Network Device Configuration Dump",
          "display_name": "T1602.002 - Network Device Configuration Dump"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1156",
          "name": "Malicious Shell Modification",
          "display_name": "T1156 - Malicious Shell Modification"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 45,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 5328,
        "domain": 2339,
        "hostname": 2434,
        "FileHash-MD5": 1210,
        "FileHash-SHA1": 721,
        "FileHash-SHA256": 2784,
        "SSLCertFingerprint": 5,
        "CVE": 2,
        "URI": 2,
        "email": 10,
        "CIDR": 3
      },
      "indicator_count": 14838,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "781 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "658481716d9034bb0d52212d",
      "name": "Apple Attack | Floxif Spyware | Threat Network | Virus Network",
      "description": "Threat Network affecting and/or originating from Apple server. Malware attacks apple airpods, tv, apple store\napple trade, apple tv\napple watch, apple card, apple og?, apple server.\nSystemUpdate.dll issue. Device may partially attempt, device will show latest update, com[promised devices may have throttled update on attempt.\n\nFloxif:\nShort bio\nTrojan.Floxif is Malwarebytes\u2019 detection name for a file-changing Trojanthat targets Windows systems.\n\nSymptoms\nTrojan.Floxif can change legitimate files into infected files. Then the infected files act as a backdoor, giving the threat actor control over the machine.\n\nStaged data. Floxif primarily target Windows, Apple is less vulnerable to buy can be experience a Floxif attack.",
      "modified": "2024-01-20T14:03:29.247000",
      "created": "2023-12-21T18:18:25.746000",
      "tags": [
        "bitrep",
        "learn",
        "apple card",
        "apple",
        "apple store",
        "apple tv",
        "watch vision",
        "airpods tv",
        "apple watch",
        "buy apple",
        "apple trade",
        "footer",
        "media",
        "find",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "malicious site",
        "hostname",
        "hostnames",
        "detection list",
        "blacklist",
        "malware",
        "alexa",
        "ip address",
        "whois record",
        "ssl certificate",
        "iocs",
        "whois whois",
        "historical ssl",
        "communicating",
        "threat network",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "attack",
        "probe",
        "search",
        "threat",
        "paste",
        "contacted",
        "april",
        "threat roundup",
        "pe resource",
        "lcid1033",
        "smlen",
        "spn647",
        "bv6fet56ww",
        "february",
        "core",
        "name verdict",
        "falcon sandbox",
        "threat analyzer",
        "samples",
        "generic malware",
        "tag count",
        "malware generic",
        "tue dec",
        "threat report",
        "summary",
        "first",
        "http response",
        "final url",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "self",
        "server apple",
        "connection",
        "html info",
        "title apple",
        "meta tags",
        "indextab og",
        "apple og",
        "spyware",
        "plugins",
        "cab",
        "fraud urls",
        "data collection",
        "staged data",
        "privilege escalation",
        "defense evasion",
        "evasive",
        "stealthy",
        "serial number",
        "symantec time",
        "stamping",
        "algorithm",
        "thumbprint",
        "from",
        "symantec sha256",
        "sha256 code",
        "signing ca",
        "class",
        "vhash",
        "authentihash",
        "imphash",
        "rich pe",
        "ssdeep",
        "file type",
        "win32 dll",
        "magic pe32",
        "intel",
        "ms windows",
        "compiler",
        "vs2008",
        "rticon english",
        "vs2005",
        "chi2",
        "contained",
        "info compiler",
        "products",
        "header target",
        "machine intel",
        "utc entry",
        "floxif",
        "serving ip",
        "address",
        "headers nel",
        "dynamic expires",
        "gmt server",
        "file sharing",
        "personal data"
      ],
      "references": [
        "https://www.apple.com/qtactivex/qtplugin.cab",
        "https://www.hybrid-analysis.com/sample/f9fab0bda2e82393cdcbb235dd41b48e00552116101deb0215bc64032741dcad",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/. [ phishing, driver, malvertizing, targeting]",
        "http://www.screensaver.com/ruxitbeacon",
        "https://otx.alienvault.com/indicator/hostname/ac-netstorage.apple.com [front facing withu4ever.com dating app/fraud service stores Apple data]",
        "http://dns1.whitelist.camect.com    [interesting]",
        "https://www.jbits.courts.state.co    [interesting]",
        "http://www.sos.state.co/                   [interesting]",
        "https://www.virustotal.com/gui/file/b883f5fab23c459f41dee72e3f89fc19734fa2f505cb5bee192960f4a0f94062/summary",
        "https://www.virustotal.com/gui/url/2cb82dbaba5c1a7ea415992f28e2d35d06187a8cfc59691b43c1589e072b2c24/summary",
        "Crowdsourced YARA  Rulesets",
        "Matches rule Malware_Floxif_mpsvc_dll from ruleset gen_floxif by Florian Roth (Nextron Systems",
        "Matches rule Windows_Virus_Floxif_493d1897 from ruleset Windows_Virus_Floxif by Elastic Security",
        "Matches rule SUSP_XORed_MSDOS_Stub_Message from ruleset gen_xor_hunting by Florian Roth",
        "https://www.malwarebytes.com/blog/detections/trojan-floxif",
        "20.190.160.2         Microsoft  [exploit_source]",
        "20.190.160.67       Microsoft  [exploit_source]",
        "20.190.160.73       Microsoft  [exploit_source]",
        "watson.events.data.microsoft.com      [traffic manager]",
        "http://watson.microsoft.com/StageOne/rundll32_exe/6_1_7600_16385/4a5bc637StackHash_2264/0_0_0_0/00000000/c0000005/63df0a5b.htm?LCID=1033&OS=6.1.7601.2.00010100.1.0.1.17514&SM=LEN&SPN=647&BV=6FET56WW&MID=54046387-FC68-43CA-9068-077C0A157181.   [stack hash]",
        "watson.telemetry.microsoft.us   [Data traffic manager]",
        "www.anyxxxtube.net [tracking]",
        "https://shitting.takefile.link/4cgeojxano82/2375.Kty10122__scatting__Shit-Porn.net_.mp4.html [file sharing, personal network storage and backup]"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Malware",
          "display_name": "Malware",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "Apple",
          "display_name": "Apple",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 609,
        "FileHash-SHA1": 361,
        "FileHash-SHA256": 1977,
        "domain": 460,
        "hostname": 992,
        "URL": 3115
      },
      "indicator_count": 7514,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "862 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63c8aad8061341d5fe0d2779",
      "name": "http://www.turbo.net",
      "description": "",
      "modified": "2023-02-18T02:02:05.208000",
      "created": "2023-01-19T02:28:40.802000",
      "tags": [
        "its all about the www",
        "4.53.147.210"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 195,
        "FileHash-SHA256": 275,
        "hostname": 39,
        "domain": 3,
        "FileHash-MD5": 18,
        "FileHash-SHA1": 17
      },
      "indicator_count": 547,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "1199 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63c89fc0ebfc33dd4647631a",
      "name": "https://eye.sb03.netstart.spoon.net - hmmm",
      "description": "://myaccount.google.com/u/1/accountlinking?hl=en-GB",
      "modified": "2023-01-19T01:41:20.595000",
      "created": "2023-01-19T01:41:20.595000",
      "tags": [
        "retrieve registration code",
        "registration code retrieval",
        "faq center",
        "contact support team",
        "customer support",
        "proudct support",
        "support center",
        "code retrieve",
        "contact support",
        "team ask",
        "frequently",
        "://myaccount.google.com/u/1/accountlinking?hl=en-GB",
        "https://eye.sb03.netstart.spoon.net"
      ],
      "references": [
        "http://api.wondershare.com/resource/00",
        "If you want to use Wondershare Technology, you may need to sign up to our Member Zone or use our support centre to find out what to do with your computer or mobile phone, or to get help from our customer service.",
        "mobile.pipe.aria.microsoft.comstart.spoon.net",
        "://myaccount.google.com/u/1/accountlinking?hl=en-GB",
        "https://eye.sb03.netstart.spoon.net"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 82,
        "FileHash-SHA256": 34,
        "hostname": 13,
        "domain": 1
      },
      "indicator_count": 130,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "1229 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.turbo.net/enterprise",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.turbo.net/enterprise",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780284248.5546181
}