{
  "type": "URL",
  "indicator": "https://www.tzcpzs.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.tzcpzs.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3966385940,
      "indicator": "https://www.tzcpzs.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "6a0a0e71af8047801da346a8",
          "name": "Credit: Skocherhan \"gh0st shadows\" clone [ty sk]",
          "description": "",
          "modified": "2026-05-20T08:57:02.834000",
          "created": "2026-05-17T18:52:33.147000",
          "tags": [],
          "references": [
            "114.114.114.114"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6a09f8a35ce1c4ed81629523",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 520,
            "hostname": 534,
            "URL": 487,
            "IPv4": 17,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 16,
            "CIDR": 2,
            "email": 2
          },
          "indicator_count": 1586,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "13 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a09f8a35ce1c4ed81629523",
          "name": "gh0st shadows",
          "description": "msudosos, have a look",
          "modified": "2026-05-17T17:19:31.602000",
          "created": "2026-05-17T17:19:31.602000",
          "tags": [],
          "references": [
            "114.114.114.114"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 342,
            "hostname": 405,
            "URL": 437
          },
          "indicator_count": 1184,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "15 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66dfa5a84844f3703fea6b84",
          "name": "Maktub Locker Ransomware",
          "description": "Maktub Locker Ransomware is old, works and arrives to victims like typical ransomware. I .  I'm can't make a valuable contribution regarding link that  populates fbi.gov node without security header. . Tulach -114.114.114.114 is at the center of most of the vulnerabilities I've researched. I've removed Tsara Brashears and name and organizations relating Brian Sabey from pulse. VT Alexo auto populated in tags. Internet search shows he referenced link and 'black suits' I did not research VT-Alexo and I don't know his significance to the Ransomware link [link appears 1st in references]. \nThere has been so much government, healthcare, legal, and law enforcement entanglement and/or/likely impersonation regarding a main issue I've been researching. Lost in this moment...",
          "modified": "2024-10-09T21:01:40.228000",
          "created": "2024-09-10T01:49:28.437000",
          "tags": [
            "axeljg",
            "kulinskiarkadi",
            "ip hostname",
            "reverse ip",
            "united",
            "regopenkeyexw",
            "cryptexportkey",
            "regsetvalueexa",
            "ip address",
            "medium",
            "regdword",
            "t1047",
            "instrumentation",
            "rpcs",
            "high",
            "win32",
            "malware",
            "showing",
            "entries disa",
            "entrypoint",
            "fbi.gov",
            "alexo",
            "germany",
            "united states",
            "brian sabey",
            "thebrotherssabey",
            "alexo virustotal",
            "yara detections",
            "ids detections",
            "contacted",
            "show",
            "medium windows",
            "alerts",
            "maktub locker",
            "tsara brashness dead",
            "aig",
            "soc",
            "pe32",
            "intel",
            "ms windows",
            "ms visual",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "pe32 compiler",
            "compiler",
            "vs2008",
            "vs2005",
            "contained",
            "info compiler",
            "products",
            "vs2008 sp1",
            "header intel",
            "name md5",
            "type",
            "language",
            "virus",
            "urls",
            "javascript",
            "b file",
            "files",
            "file type",
            "rich text",
            "format",
            "found",
            "downloads",
            "injection t1055",
            "spawns",
            "t1497 may",
            "https",
            "mitre att",
            "ta0002 shared",
            "modules t1129",
            "window",
            "get file",
            "check mutex",
            "print debug",
            "get disk",
            "check",
            "enumerate gui",
            "create mutex",
            "query",
            "enumerate",
            "create shortcut",
            "capture",
            "get http",
            "windows nt",
            "request",
            "response",
            "number",
            "algorithm",
            "ja3s",
            "cus cnr3",
            "subject",
            "http requests",
            "samplepath",
            "runtime modules",
            "referrer",
            "threat network",
            "infrastructure",
            "historical ssl",
            "approach",
            "ta413",
            "tibetan targets",
            "vy binh",
            "march",
            "tulach",
            "114.114.114.114",
            "libreoffice.org",
            "as174 cogent",
            "china unknown",
            "china",
            "passive dns",
            "entries",
            "scan endpoints",
            "all scoreblue",
            "ipv4",
            "pulse pulses",
            "twitter",
            "problems",
            "domainabuse",
            "creation date",
            "search",
            "domain",
            "domain name",
            "expiration date",
            "nanjing",
            "date",
            "all search",
            "trojan",
            "trojan features",
            "related pulses",
            "file samples",
            "files matching",
            "sort"
          ],
          "references": [
            "Ransomware\u00bbTrojanDownloader:Win32/Dalexis | FileHash-SHA256  01da63fd3b935be956657d8f7212e976c553a6e040d5db9592fab807441b3e32",
            "Antivirus Detections Win32:Filecoder-AD\\ [Trj] ,  Win.Malware.Cabby-6803812-0 ,  TrojanDownloader:Win32/Dalexis!rfn!rfn",
            "IDS Detections: Maktub Locker TOR Status Check TOR Consensus Data Requested TOR 1.0 Server Key Retrieval Tor Get Server Request TLS Handshake",
            "Domains Contacted: fbi.gov",
            "IP\u2019s Contacted:  104.16.149.244  128.31.0.39  131.188.40.189  14.200.177.98  148.251.79.57",
            "IP\u2019s Contacted: 185.220.100.255  199.249.230.142  199.254.238.52 23.128.248.20  45.58.156.76",
            "tulach.cc| 114.114.114.114 [public1.114dns.com] | thebrotherssabey | bian sabey under multiple WP & DGA domains , various titles , various roles",
            "External Hosts Top Country United States, Germany | IP Hostname: 104.16.149.244: fbi.gov | United States: AS13335 cloudflare",
            "Type Indicator Reason:  IPv4 104.16.149.244 In CDN range: provider=cloudflare  IPv4 131.188.40.189 IP Associated with Tor Exit Nodes",
            "Type Indicator Reason:  IPv4 192.168.56.108 Private IP Address:  IPv4 46.20.35.112 IP Associated with Tor Exit Nodes:  Domain: fbi.gov",
            "PE Anomalies: entropy_based | Yara Detections: Yara Detections stack_string | Stack_String: stack_string E\u000fEEEE\u000fEEEE\u000fEEEE\u000fEEEE\u000fEE\u000fEE\u000fEE\u000fEE\u000f",
            "DISA Entrypoint: call 0x41259b jmp 0x40b3ac int3 int3 int3 int3 int3 int3 int3 int3",
            "https://otx.alienvault.com/otxapi/indicators/file/screenshot/01da63fd3b935be956657d8f7212e976c553a6e040d5db9592fab807441b3e32",
            "Alerts: dead_host network_icmp nolookup_communication modifies_proxy_wpad network_cnc_http network_http packer_entropy",
            "Alerts: allocates_rwx creates_hidden_file dropper has_wmi protection_rx antivm_network_adapters raises_exception",
            "Alerts: queries_programs wmi_antivm checks_debugger generates_crypto_key recon_fingerprint pe_unknown_resource_name",
            "Interesting Strings: http://ns.adobe.com/xap/1.0/mm/ http://ns.adobe.com/xap/1.0/  http://ns.adobe.com/xap/1.0/sType/ResourceRef",
            "Interesting Strings: http://www.w3.org/1999/02/22",
            "Virus: \"ba30376f915afa868763f84299fae5d2.virus.rtf - LibreOffice Writer\"",
            "Cryptographical plain text c\ufffdh\u000f\u00107\ufffd\ufffd1Q\ufffd\u0286\ufffd\u0254E\ufffdW\u0014\ufffd\u0382\ufffd Rw\ufffde\ufffd\ufffd%\u000b\ufffd\ufffd\ufffdreudt\ufffd\ufffd\ufffd",
            "IDS: Matches rule ET JA3 Hash - Possible Malware - Dridex",
            "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic Groups: 129, 750, 824, 439, 282, 820, 21 , 63, 896, 91, 11, 202, 684 919,31 ,156, 743",
            "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic Groups: 869, 42, 6, 443, 85, 416, 688, 117, 217, 217, 443, 709, 703, 879, 338, 682",
            "Matches rule Wow6432Node CurrentVersion Autorun Keys Modification by Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)",
            "IDS: Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
            "IDS: Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
            "IDS:  Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
            "IDS: Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
            "IDS: Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
            "IDS: Matches rule (http_inspect) white space before or between HTTP messages Matches rule SURICATA HTTP Request abnormal Content-Encoding",
            "Sigma: Matches rule Failed Code Integrity Checks by Thomas Patzke Matches rule Process Creation Using Sysnative Folder by Max Altgelt",
            "YARA Signature Match - THOR APT Scanner - RULE_AUTHOR: Florian Roth",
            "RULE: MAL_Agent_May20_1 RULE_SET: Livehunt - Default22 Indicators RULE_TYPE: VALHALLA rule feed only \u26a1- RULE_AUTHOR: Florian Roth",
            "RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_Agent_May20_1 DESCRIPTION:",
            "Detects malware used in activity noticed  05/2020 likely related to Chinese actor",
            "REFERENCE: ACSC IOCs May 2020 pivoting RULE_AUTHOR: Florian Roth",
            "https://www.nextron-systems.com/notes-on-virustotal-matches/",
            "114.114.114.114 IDS Detections DYNAMIC_DNS Query to a *.ns1.name Domain Query to a *.top domain - Likely Hostile Observed DNS Query to .work",
            "IP 114.114.114.114 Antivirus Detections: !#SIGATTR:IEProxyChange ,  ALF:Backdoor:Win64/Meterpreter.AB!MTB ,",
            "IP 114.114.114.114 Antivirus Detections: ALF:PUA:Block:VrBrothers.R!MTB ,  ALF:Trojan:MSIL/AgentTesla.KM ,  ALFPER:RefLoadApiHash ,",
            "IP 114.114.114.114 Antivirus Detections: Backdoor:Linux/Dofloo.A!MTB ,  Backdoor:Linux/Gafgyt.AF!MTB ,  Can't access file ,",
            "IP 114.114.114.114 Antivirus Detections: Trojan:Win32/Magania.DSK!MTB , TEL:SIGATTR:CreateRemoteThread",
            "IP 114.114.114.114 Domain 114dns.com: PegasusPlus",
            "Emails: pegasusplus@gmail.com Name: Zhao Zhenping Name Servers: NS1000.114DNS.COM Org: Nanjing XinFeng Network Technologies, Inc.",
            "Address:\tRoom 301, Building 3B, Startup park, High Tech park, Shiyang Road 56, Baixia District, Nanjing, Jiangsu, China City nan jing shi Country",
            "https://blog.malwarebytes.org/intelligence/2016/03/maktub-locker-beautiful-and-dangerous/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "China"
          ],
          "malware_families": [
            {
              "id": "Maktub Locker",
              "display_name": "Maktub Locker",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Dalexis!rfn!rfn",
              "display_name": "TrojanDownloader:Win32/Dalexis!rfn!rfn",
              "target": "/malware/TrojanDownloader:Win32/Dalexis!rfn!rfn"
            },
            {
              "id": "Trojan:Win32/Magania",
              "display_name": "Trojan:Win32/Magania",
              "target": "/malware/Trojan:Win32/Magania"
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1158",
              "name": "Hidden Files and Directories",
              "display_name": "T1158 - Hidden Files and Directories"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1125",
              "name": "Video Capture",
              "display_name": "T1125 - Video Capture"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            }
          ],
          "industries": [
            "Government",
            "Technology",
            "Telecommunications"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 182,
            "FileHash-SHA1": 199,
            "FileHash-SHA256": 2383,
            "domain": 395,
            "URL": 1382,
            "hostname": 699,
            "email": 2,
            "CVE": 1
          },
          "indicator_count": 5243,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 234,
          "modified_text": "600 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Ransomware\u00bbTrojanDownloader:Win32/Dalexis | FileHash-SHA256  01da63fd3b935be956657d8f7212e976c553a6e040d5db9592fab807441b3e32",
        "Address:\tRoom 301, Building 3B, Startup park, High Tech park, Shiyang Road 56, Baixia District, Nanjing, Jiangsu, China City nan jing shi Country",
        "114.114.114.114",
        "IP 114.114.114.114 Antivirus Detections: ALF:PUA:Block:VrBrothers.R!MTB ,  ALF:Trojan:MSIL/AgentTesla.KM ,  ALFPER:RefLoadApiHash ,",
        "IP 114.114.114.114 Antivirus Detections: Backdoor:Linux/Dofloo.A!MTB ,  Backdoor:Linux/Gafgyt.AF!MTB ,  Can't access file ,",
        "Type Indicator Reason:  IPv4 104.16.149.244 In CDN range: provider=cloudflare  IPv4 131.188.40.189 IP Associated with Tor Exit Nodes",
        "IP 114.114.114.114 Domain 114dns.com: PegasusPlus",
        "114.114.114.114 IDS Detections DYNAMIC_DNS Query to a *.ns1.name Domain Query to a *.top domain - Likely Hostile Observed DNS Query to .work",
        "IDS Detections: Maktub Locker TOR Status Check TOR Consensus Data Requested TOR 1.0 Server Key Retrieval Tor Get Server Request TLS Handshake",
        "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic Groups: 129, 750, 824, 439, 282, 820, 21 , 63, 896, 91, 11, 202, 684 919,31 ,156, 743",
        "https://www.nextron-systems.com/notes-on-virustotal-matches/",
        "IDS: Matches rule ET JA3 Hash - Possible Malware - Dridex",
        "IP\u2019s Contacted:  104.16.149.244  128.31.0.39  131.188.40.189  14.200.177.98  148.251.79.57",
        "IP\u2019s Contacted: 185.220.100.255  199.249.230.142  199.254.238.52 23.128.248.20  45.58.156.76",
        "IP 114.114.114.114 Antivirus Detections: !#SIGATTR:IEProxyChange ,  ALF:Backdoor:Win64/Meterpreter.AB!MTB ,",
        "YARA Signature Match - THOR APT Scanner - RULE_AUTHOR: Florian Roth",
        "Virus: \"ba30376f915afa868763f84299fae5d2.virus.rtf - LibreOffice Writer\"",
        "IDS:  Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
        "Sigma: Matches rule Failed Code Integrity Checks by Thomas Patzke Matches rule Process Creation Using Sysnative Folder by Max Altgelt",
        "DISA Entrypoint: call 0x41259b jmp 0x40b3ac int3 int3 int3 int3 int3 int3 int3 int3",
        "RULE: MAL_Agent_May20_1 RULE_SET: Livehunt - Default22 Indicators RULE_TYPE: VALHALLA rule feed only \u26a1- RULE_AUTHOR: Florian Roth",
        "REFERENCE: ACSC IOCs May 2020 pivoting RULE_AUTHOR: Florian Roth",
        "RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_Agent_May20_1 DESCRIPTION:",
        "Detects malware used in activity noticed  05/2020 likely related to Chinese actor",
        "Cryptographical plain text c\ufffdh\u000f\u00107\ufffd\ufffd1Q\ufffd\u0286\ufffd\u0254E\ufffdW\u0014\ufffd\u0382\ufffd Rw\ufffde\ufffd\ufffd%\u000b\ufffd\ufffd\ufffdreudt\ufffd\ufffd\ufffd",
        "https://otx.alienvault.com/otxapi/indicators/file/screenshot/01da63fd3b935be956657d8f7212e976c553a6e040d5db9592fab807441b3e32",
        "PE Anomalies: entropy_based | Yara Detections: Yara Detections stack_string | Stack_String: stack_string E\u000fEEEE\u000fEEEE\u000fEEEE\u000fEEEE\u000fEE\u000fEE\u000fEE\u000fEE\u000f",
        "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic Groups: 869, 42, 6, 443, 85, 416, 688, 117, 217, 217, 443, 709, 703, 879, 338, 682",
        "Alerts: allocates_rwx creates_hidden_file dropper has_wmi protection_rx antivm_network_adapters raises_exception",
        "https://blog.malwarebytes.org/intelligence/2016/03/maktub-locker-beautiful-and-dangerous/",
        "Emails: pegasusplus@gmail.com Name: Zhao Zhenping Name Servers: NS1000.114DNS.COM Org: Nanjing XinFeng Network Technologies, Inc.",
        "Domains Contacted: fbi.gov",
        "Alerts: dead_host network_icmp nolookup_communication modifies_proxy_wpad network_cnc_http network_http packer_entropy",
        "tulach.cc| 114.114.114.114 [public1.114dns.com] | thebrotherssabey | bian sabey under multiple WP & DGA domains , various titles , various roles",
        "Interesting Strings: http://ns.adobe.com/xap/1.0/mm/ http://ns.adobe.com/xap/1.0/  http://ns.adobe.com/xap/1.0/sType/ResourceRef",
        "External Hosts Top Country United States, Germany | IP Hostname: 104.16.149.244: fbi.gov | United States: AS13335 cloudflare",
        "IDS: Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
        "Matches rule Wow6432Node CurrentVersion Autorun Keys Modification by Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)",
        "Alerts: queries_programs wmi_antivm checks_debugger generates_crypto_key recon_fingerprint pe_unknown_resource_name",
        "IDS: Matches rule (http_inspect) white space before or between HTTP messages Matches rule SURICATA HTTP Request abnormal Content-Encoding",
        "Type Indicator Reason:  IPv4 192.168.56.108 Private IP Address:  IPv4 46.20.35.112 IP Associated with Tor Exit Nodes:  Domain: fbi.gov",
        "Antivirus Detections Win32:Filecoder-AD\\ [Trj] ,  Win.Malware.Cabby-6803812-0 ,  TrojanDownloader:Win32/Dalexis!rfn!rfn",
        "Interesting Strings: http://www.w3.org/1999/02/22",
        "IP 114.114.114.114 Antivirus Detections: Trojan:Win32/Magania.DSK!MTB , TEL:SIGATTR:CreateRemoteThread"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Maktub locker",
            "Trojan:win32/magania",
            "Trojandownloader:win32/dalexis!rfn!rfn"
          ],
          "industries": [
            "Telecommunications",
            "Government",
            "Technology"
          ],
          "unique_indicators": 6518
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/tzcpzs.com",
    "whois": "http://whois.domaintools.com/tzcpzs.com",
    "domain": "tzcpzs.com",
    "hostname": "www.tzcpzs.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "6a0a0e71af8047801da346a8",
      "name": "Credit: Skocherhan \"gh0st shadows\" clone [ty sk]",
      "description": "",
      "modified": "2026-05-20T08:57:02.834000",
      "created": "2026-05-17T18:52:33.147000",
      "tags": [],
      "references": [
        "114.114.114.114"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "6a09f8a35ce1c4ed81629523",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 520,
        "hostname": 534,
        "URL": 487,
        "IPv4": 17,
        "FileHash-MD5": 4,
        "FileHash-SHA1": 4,
        "FileHash-SHA256": 16,
        "CIDR": 2,
        "email": 2
      },
      "indicator_count": 1586,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "13 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a09f8a35ce1c4ed81629523",
      "name": "gh0st shadows",
      "description": "msudosos, have a look",
      "modified": "2026-05-17T17:19:31.602000",
      "created": "2026-05-17T17:19:31.602000",
      "tags": [],
      "references": [
        "114.114.114.114"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 342,
        "hostname": 405,
        "URL": 437
      },
      "indicator_count": 1184,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 186,
      "modified_text": "15 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66dfa5a84844f3703fea6b84",
      "name": "Maktub Locker Ransomware",
      "description": "Maktub Locker Ransomware is old, works and arrives to victims like typical ransomware. I .  I'm can't make a valuable contribution regarding link that  populates fbi.gov node without security header. . Tulach -114.114.114.114 is at the center of most of the vulnerabilities I've researched. I've removed Tsara Brashears and name and organizations relating Brian Sabey from pulse. VT Alexo auto populated in tags. Internet search shows he referenced link and 'black suits' I did not research VT-Alexo and I don't know his significance to the Ransomware link [link appears 1st in references]. \nThere has been so much government, healthcare, legal, and law enforcement entanglement and/or/likely impersonation regarding a main issue I've been researching. Lost in this moment...",
      "modified": "2024-10-09T21:01:40.228000",
      "created": "2024-09-10T01:49:28.437000",
      "tags": [
        "axeljg",
        "kulinskiarkadi",
        "ip hostname",
        "reverse ip",
        "united",
        "regopenkeyexw",
        "cryptexportkey",
        "regsetvalueexa",
        "ip address",
        "medium",
        "regdword",
        "t1047",
        "instrumentation",
        "rpcs",
        "high",
        "win32",
        "malware",
        "showing",
        "entries disa",
        "entrypoint",
        "fbi.gov",
        "alexo",
        "germany",
        "united states",
        "brian sabey",
        "thebrotherssabey",
        "alexo virustotal",
        "yara detections",
        "ids detections",
        "contacted",
        "show",
        "medium windows",
        "alerts",
        "maktub locker",
        "tsara brashness dead",
        "aig",
        "soc",
        "pe32",
        "intel",
        "ms windows",
        "ms visual",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "pe32 compiler",
        "compiler",
        "vs2008",
        "vs2005",
        "contained",
        "info compiler",
        "products",
        "vs2008 sp1",
        "header intel",
        "name md5",
        "type",
        "language",
        "virus",
        "urls",
        "javascript",
        "b file",
        "files",
        "file type",
        "rich text",
        "format",
        "found",
        "downloads",
        "injection t1055",
        "spawns",
        "t1497 may",
        "https",
        "mitre att",
        "ta0002 shared",
        "modules t1129",
        "window",
        "get file",
        "check mutex",
        "print debug",
        "get disk",
        "check",
        "enumerate gui",
        "create mutex",
        "query",
        "enumerate",
        "create shortcut",
        "capture",
        "get http",
        "windows nt",
        "request",
        "response",
        "number",
        "algorithm",
        "ja3s",
        "cus cnr3",
        "subject",
        "http requests",
        "samplepath",
        "runtime modules",
        "referrer",
        "threat network",
        "infrastructure",
        "historical ssl",
        "approach",
        "ta413",
        "tibetan targets",
        "vy binh",
        "march",
        "tulach",
        "114.114.114.114",
        "libreoffice.org",
        "as174 cogent",
        "china unknown",
        "china",
        "passive dns",
        "entries",
        "scan endpoints",
        "all scoreblue",
        "ipv4",
        "pulse pulses",
        "twitter",
        "problems",
        "domainabuse",
        "creation date",
        "search",
        "domain",
        "domain name",
        "expiration date",
        "nanjing",
        "date",
        "all search",
        "trojan",
        "trojan features",
        "related pulses",
        "file samples",
        "files matching",
        "sort"
      ],
      "references": [
        "Ransomware\u00bbTrojanDownloader:Win32/Dalexis | FileHash-SHA256  01da63fd3b935be956657d8f7212e976c553a6e040d5db9592fab807441b3e32",
        "Antivirus Detections Win32:Filecoder-AD\\ [Trj] ,  Win.Malware.Cabby-6803812-0 ,  TrojanDownloader:Win32/Dalexis!rfn!rfn",
        "IDS Detections: Maktub Locker TOR Status Check TOR Consensus Data Requested TOR 1.0 Server Key Retrieval Tor Get Server Request TLS Handshake",
        "Domains Contacted: fbi.gov",
        "IP\u2019s Contacted:  104.16.149.244  128.31.0.39  131.188.40.189  14.200.177.98  148.251.79.57",
        "IP\u2019s Contacted: 185.220.100.255  199.249.230.142  199.254.238.52 23.128.248.20  45.58.156.76",
        "tulach.cc| 114.114.114.114 [public1.114dns.com] | thebrotherssabey | bian sabey under multiple WP & DGA domains , various titles , various roles",
        "External Hosts Top Country United States, Germany | IP Hostname: 104.16.149.244: fbi.gov | United States: AS13335 cloudflare",
        "Type Indicator Reason:  IPv4 104.16.149.244 In CDN range: provider=cloudflare  IPv4 131.188.40.189 IP Associated with Tor Exit Nodes",
        "Type Indicator Reason:  IPv4 192.168.56.108 Private IP Address:  IPv4 46.20.35.112 IP Associated with Tor Exit Nodes:  Domain: fbi.gov",
        "PE Anomalies: entropy_based | Yara Detections: Yara Detections stack_string | Stack_String: stack_string E\u000fEEEE\u000fEEEE\u000fEEEE\u000fEEEE\u000fEE\u000fEE\u000fEE\u000fEE\u000f",
        "DISA Entrypoint: call 0x41259b jmp 0x40b3ac int3 int3 int3 int3 int3 int3 int3 int3",
        "https://otx.alienvault.com/otxapi/indicators/file/screenshot/01da63fd3b935be956657d8f7212e976c553a6e040d5db9592fab807441b3e32",
        "Alerts: dead_host network_icmp nolookup_communication modifies_proxy_wpad network_cnc_http network_http packer_entropy",
        "Alerts: allocates_rwx creates_hidden_file dropper has_wmi protection_rx antivm_network_adapters raises_exception",
        "Alerts: queries_programs wmi_antivm checks_debugger generates_crypto_key recon_fingerprint pe_unknown_resource_name",
        "Interesting Strings: http://ns.adobe.com/xap/1.0/mm/ http://ns.adobe.com/xap/1.0/  http://ns.adobe.com/xap/1.0/sType/ResourceRef",
        "Interesting Strings: http://www.w3.org/1999/02/22",
        "Virus: \"ba30376f915afa868763f84299fae5d2.virus.rtf - LibreOffice Writer\"",
        "Cryptographical plain text c\ufffdh\u000f\u00107\ufffd\ufffd1Q\ufffd\u0286\ufffd\u0254E\ufffdW\u0014\ufffd\u0382\ufffd Rw\ufffde\ufffd\ufffd%\u000b\ufffd\ufffd\ufffdreudt\ufffd\ufffd\ufffd",
        "IDS: Matches rule ET JA3 Hash - Possible Malware - Dridex",
        "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic Groups: 129, 750, 824, 439, 282, 820, 21 , 63, 896, 91, 11, 202, 684 919,31 ,156, 743",
        "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic Groups: 869, 42, 6, 443, 85, 416, 688, 117, 217, 217, 443, 709, 703, 879, 338, 682",
        "Matches rule Wow6432Node CurrentVersion Autorun Keys Modification by Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)",
        "IDS: Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
        "IDS: Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
        "IDS:  Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
        "IDS: Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
        "IDS: Matches rule POLICY-OTHER HTTP request by IPv4 address attempt Matches rule POLICY-OTHER TOR traffic anonymizer server request Matches rule ET POLICY TOR Consensus Data Requested Matches rule ET P2P Tor Get Server Request Matches rule ET P2P TOR 1.0 Server Key Retrieval",
        "IDS: Matches rule (http_inspect) white space before or between HTTP messages Matches rule SURICATA HTTP Request abnormal Content-Encoding",
        "Sigma: Matches rule Failed Code Integrity Checks by Thomas Patzke Matches rule Process Creation Using Sysnative Folder by Max Altgelt",
        "YARA Signature Match - THOR APT Scanner - RULE_AUTHOR: Florian Roth",
        "RULE: MAL_Agent_May20_1 RULE_SET: Livehunt - Default22 Indicators RULE_TYPE: VALHALLA rule feed only \u26a1- RULE_AUTHOR: Florian Roth",
        "RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_Agent_May20_1 DESCRIPTION:",
        "Detects malware used in activity noticed  05/2020 likely related to Chinese actor",
        "REFERENCE: ACSC IOCs May 2020 pivoting RULE_AUTHOR: Florian Roth",
        "https://www.nextron-systems.com/notes-on-virustotal-matches/",
        "114.114.114.114 IDS Detections DYNAMIC_DNS Query to a *.ns1.name Domain Query to a *.top domain - Likely Hostile Observed DNS Query to .work",
        "IP 114.114.114.114 Antivirus Detections: !#SIGATTR:IEProxyChange ,  ALF:Backdoor:Win64/Meterpreter.AB!MTB ,",
        "IP 114.114.114.114 Antivirus Detections: ALF:PUA:Block:VrBrothers.R!MTB ,  ALF:Trojan:MSIL/AgentTesla.KM ,  ALFPER:RefLoadApiHash ,",
        "IP 114.114.114.114 Antivirus Detections: Backdoor:Linux/Dofloo.A!MTB ,  Backdoor:Linux/Gafgyt.AF!MTB ,  Can't access file ,",
        "IP 114.114.114.114 Antivirus Detections: Trojan:Win32/Magania.DSK!MTB , TEL:SIGATTR:CreateRemoteThread",
        "IP 114.114.114.114 Domain 114dns.com: PegasusPlus",
        "Emails: pegasusplus@gmail.com Name: Zhao Zhenping Name Servers: NS1000.114DNS.COM Org: Nanjing XinFeng Network Technologies, Inc.",
        "Address:\tRoom 301, Building 3B, Startup park, High Tech park, Shiyang Road 56, Baixia District, Nanjing, Jiangsu, China City nan jing shi Country",
        "https://blog.malwarebytes.org/intelligence/2016/03/maktub-locker-beautiful-and-dangerous/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "China"
      ],
      "malware_families": [
        {
          "id": "Maktub Locker",
          "display_name": "Maktub Locker",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Dalexis!rfn!rfn",
          "display_name": "TrojanDownloader:Win32/Dalexis!rfn!rfn",
          "target": "/malware/TrojanDownloader:Win32/Dalexis!rfn!rfn"
        },
        {
          "id": "Trojan:Win32/Magania",
          "display_name": "Trojan:Win32/Magania",
          "target": "/malware/Trojan:Win32/Magania"
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1158",
          "name": "Hidden Files and Directories",
          "display_name": "T1158 - Hidden Files and Directories"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1087",
          "name": "Account Discovery",
          "display_name": "T1087 - Account Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1125",
          "name": "Video Capture",
          "display_name": "T1125 - Video Capture"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        }
      ],
      "industries": [
        "Government",
        "Technology",
        "Telecommunications"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 24,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 182,
        "FileHash-SHA1": 199,
        "FileHash-SHA256": 2383,
        "domain": 395,
        "URL": 1382,
        "hostname": 699,
        "email": 2,
        "CVE": 1
      },
      "indicator_count": 5243,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 234,
      "modified_text": "600 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.tzcpzs.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.tzcpzs.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780401705.5635157
}