{
  "type": "URL",
  "indicator": "https://www.youtube.com/watch",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.youtube.com/watch",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "alexa",
        "message": "Alexa rank: #2",
        "name": "Listed on Alexa"
      },
      {
        "source": "akamai",
        "message": "Akamai rank: #22",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "whitelist",
        "message": "Whitelisted domain youtube.com",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain youtube.com",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 2285630261,
      "indicator": "https://www.youtube.com/watch",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 11,
      "pulses": [
        {
          "id": "69ad4f70dd8cd3a4bae75670",
          "name": "krnaver.com- BL! 10 month of no sleep and all i could read was ralph nader #doh",
          "description": "Pulse\nPulses\n5\nPassive DNS\n39\nURLs\n12\nFiles\n1K\nAnalysis Overview\nIP Address\n104.17.232.29\nLocation\n\nUnited States\nASN\nAS13335 cloudflare\nNameservers\nns36.domaincontrol.com.\n, \nns35.domaincontrol.com.\nWHOIS\nRegistrar:\nXiamen Domains, Inc.,  \nCreation Date:\nNov 12, 2016\nRelated Pulses\nOTX User-Created Pulses (5)\nRelated Tags\nNone\nIndicator Facts\n1000 malicious files communicating\nHistorical OTX telemetry\nRunning webserver\n2 subdomains\nNumber of malicious files communicating with the domain or subdomains\nAntivirus Detections\nBackdoor:Win32/Venik.E!dha\n, \nBackdoor:Win32/Venik.I\n, \nBackdoor:Win32/Venik.J\n, \nWin.Trojan.Packed-123\nAV Detection Ratio\n1000\n / 1000",
          "modified": "2026-04-07T10:26:55.912000",
          "created": "2026-03-08T10:29:04.330000",
          "tags": [
            "backdoor",
            "pulse",
            "passive dns",
            "urls",
            "files",
            "ip address",
            "location united",
            "asn as13335",
            "whois registrar",
            "domains"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 321,
            "hostname": 85,
            "URL": 87,
            "FileHash-MD5": 151,
            "FileHash-SHA1": 151,
            "FileHash-SHA256": 152,
            "email": 6
          },
          "indicator_count": 953,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "56 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69aa3786e3fd41dfed869f60",
          "name": "Stealthy Bruteforce Evasion/ est every 3 hrs change if not provoked sooner",
          "description": "MITRE- Command and Control\tDefense Evasion\tPrivilege Escalation\nT1071 - Application Layer Protocol\nnetwork_http\nstealth_network\nT1055 - Process Injection\ncreates_suspended_process",
          "modified": "2026-04-05T02:39:58.334000",
          "created": "2026-03-06T02:10:14.833000",
          "tags": [
            "ascii text",
            "file size",
            "sha256",
            "mwdb",
            "bazaar",
            "sha3384",
            "crc32",
            "ssdeep"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "hostname": 55,
            "URL": 3
          },
          "indicator_count": 61,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "58 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69aa3a2a1577d2537fbb0b3f",
          "name": "DNS Configuration Mismatch",
          "description": "DNS Configuration Mismatch: 32 entries show outbound UDP Port 53 traffic to 8.8.8.8. This traffic is non-compliant with the user-defined resolver.\nUnauthorized Redirection: The telemetry confirms an active bypass of local system settings, indicating either hard-coded application behavior or network-level redirection.\nNetBIOS Broadcast Activity: Entries for Port 137 involving 172.16.1.1 and the broadcast address 172.16.1.255 indicate internal device discovery/name registration on the local subnet.\nExternal Cloud Handshake: A single session to 52.123.250.178 via Port 443 (HTTPS) establishes an encrypted connection to Microsoft/Azure infrastructure.\nAnomalous Traffic Density: The high ratio of unauthorized DNS queries relative to standard web traffic (32:1) suggests a potential Command & Control (C2) beaconing or DNS tunneling profile.",
          "modified": "2026-04-05T02:39:58.334000",
          "created": "2026-03-06T02:21:30.645000",
          "tags": [
            "ip address",
            "port"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 58,
            "URL": 5,
            "FileHash-MD5": 2,
            "FileHash-SHA256": 2,
            "domain": 2
          },
          "indicator_count": 69,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "58 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698c3273517158869e0ba780",
          "name": "Reputation Shielded C2 Pivot; High-Churn Wix Infrastructure with iCloud Exfil Adjacency",
          "description": "Researcher Note (Feb 11, 2026) IPv4 185.230.61.96 (AS58182 \u2013 Wix.com Ltd.), resolving to unalocated.61.wixsite.com, demonstrates indicators consistent with structured abuse of shared SaaS hosting for command-and-control operations. Passive DNS telemetry reflects 500+ historical domain bindings across 52 TLDs, suggesting deliberate namespace dispersion and rotational overlay management rather than static tenancy. Network detections include repeated FormBook HTTP GET check-ins, Pushdo loader beacon cadence, and Windows Network Diagnostics user-agent spoofing, collectively aligning with controlled tasking infrastructure. Associated artifacts (11/50 AV detections) cluster around credential-stealer and loader families, including FormBook and GandCrab lineage components. The behavioral profile supports assessment of reputation parasitism\u2014leveraging trusted hosting to inherit platform trust and evade domain-based enforcement controls. Confidence: Moderate-High. MITRE: T1071.001, T1105, T1036.",
          "modified": "2026-03-29T00:29:26.398000",
          "created": "2026-02-11T07:40:32.757000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "Tier-1 SaaS Reputation Parasitism Leveraging Wix Infrastructure",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 265,
            "domain": 294,
            "URL": 331,
            "email": 12,
            "CVE": 61,
            "FileHash-MD5": 73,
            "FileHash-SHA1": 64,
            "FileHash-SHA256": 74
          },
          "indicator_count": 1174,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 76,
          "modified_text": "65 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6988faa4f668aeeed6f86da8",
          "name": "zero trust",
          "description": "researcher credit: msudoSOS : CLBCatQ.DLL\tThe malware is hijacking your COM+ Class Catalog to hide as a System Service.\nCoMarshalInterface\tYour identity is being \"packaged\" and sent via the LTE Trial to the '' Edge.\npid 2356 / 2812\tThese are the active processes currently communicating with the 49.12.22.106 C2 server.",
          "modified": "2026-03-27T09:05:26.285000",
          "created": "2026-02-08T21:05:37.829000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ALF:HeraklezEval:Trojan:Win32/C2Lop",
              "display_name": "ALF:HeraklezEval:Trojan:Win32/C2Lop",
              "target": null
            },
            {
              "id": "#LowFi:HSTR:PyInstaller_Packaged_Script",
              "display_name": "#LowFi:HSTR:PyInstaller_Packaged_Script",
              "target": null
            },
            {
              "id": "#Exploit:Win32/BlofeldsCat",
              "display_name": "#Exploit:Win32/BlofeldsCat",
              "target": "/malware/#Exploit:Win32/BlofeldsCat"
            },
            {
              "id": "TEL:Exploit:HTML/PSWebkit",
              "display_name": "TEL:Exploit:HTML/PSWebkit",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 394,
            "hostname": 250,
            "CVE": 112,
            "URL": 190,
            "email": 25,
            "JA3": 1,
            "FileHash-MD5": 191,
            "FileHash-SHA1": 214,
            "FileHash-SHA256": 607
          },
          "indicator_count": 1984,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 82,
          "modified_text": "67 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698904c316bc7710b967d01d",
          "name": "Rare Tier 1 Persistence - Critical \"Patched\", Non Patched Vulnerabilities Remain bypassing Lockdown Mode",
          "description": "Researcher Note (Feb 08, 2026):\nThis artifact represents a sophisticated Cross-Protocol Mesh. Observations confirm that the Cymt/Nemucod wrapper is being utilized as a delivery vehicle for a Firmware-resident ELF binary (Mirai variant).\nThe persistence is notable for its ability to survive Full DFU Restores and Faraday-isolated states, likely due to JTAG-level interaction with the Power Management IC (Chip 4799). This is not a standard opportunistic infection; it is a targeted provisioning event leveraging IDMSA (Identity Management) bridges and Verizon/Akamai Edge infrastructure.\nThe integration with CalendarKit and Maps for geofenced execution suggests a highly coordinated surveillance objective. Forensic analysts should pay specific attention to the sizeofrawdata_antidbg anomalies, which indicate a focus on bypassing Apple Lockdown Mode and Secure Enclave. \nresearcher credit: msudoSOS",
          "modified": "2026-03-27T09:05:26.285000",
          "created": "2026-02-08T21:48:49.147000",
          "tags": [
            "#supportsitewebsiteabuse #rootcertificatefailure #cryptographicf"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 909,
            "URL": 1779,
            "CVE": 126,
            "domain": 659,
            "email": 23,
            "JA3": 1,
            "FileHash-MD5": 230,
            "FileHash-SHA1": 227,
            "FileHash-SHA256": 934,
            "CIDR": 13
          },
          "indicator_count": 4901,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 76,
          "modified_text": "67 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ada442ba9893ca65ae8b87",
          "name": "VirusTotal report\n                    for base.apk",
          "description": "We are going to be the ones leaning on Fury. To win this, I don't need to be heavy, I need to be fast and quick.",
          "modified": "2026-03-08T16:30:58.152000",
          "created": "2026-03-08T16:30:58.152000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1406",
              "name": "Obfuscated Files or Information",
              "display_name": "T1406 - Obfuscated Files or Information"
            },
            {
              "id": "T1409",
              "name": "Access Stored Application Data",
              "display_name": "T1409 - Access Stored Application Data"
            },
            {
              "id": "T1421",
              "name": "System Network Connections Discovery",
              "display_name": "T1421 - System Network Connections Discovery"
            },
            {
              "id": "T1422",
              "name": "System Network Configuration Discovery",
              "display_name": "T1422 - System Network Configuration Discovery"
            },
            {
              "id": "T1424",
              "name": "Process Discovery",
              "display_name": "T1424 - Process Discovery"
            },
            {
              "id": "T1426",
              "name": "System Information Discovery",
              "display_name": "T1426 - System Information Discovery"
            },
            {
              "id": "T1430",
              "name": "Location Tracking",
              "display_name": "T1430 - Location Tracking"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "URL": 47,
            "domain": 10,
            "hostname": 21
          },
          "indicator_count": 81,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "86 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66e00320d65236e032faa26a",
          "name": "Global- Injection | Phone service modification campaign - Cryprsoft",
          "description": "Malicious\u00bb http://www.forensickb.com/2013/03/file-entropy-explained.html | Cryptsoft | ET ,\nVirus:Win32/Sality.AT ,\nWin32:Kukacka , TrojanSpy:Win32/Nivdort.AJ , Worm:Win32/Mydoom.O!backdoor , \nWorm:Win32/Bloored , TrojanSpy:Win32/Invader.S!MSR , \nText: Mydoom spreading via SMTP 29 192.168.56.110 198.133.159.125 2018340 ET TROJAN Win32.Sality-GR Checkin 192.168.56.110 52.28.249.128 2018340 ET TROJAN Win32.Sality-GR Checkin 192.168.56.110 166.78.145.90 2016803 ET TROJAN Known Sinkhole Response Header 166.78.145.90 192.168.56.110 2018\nATT&CK | Query Registry , Modify Existing Service , Scheduled Task/Job , Process Injection , Registry Run Keys / Startup Folder , System Information Discovery , Disabling Security Tools , Modify Registry",
          "modified": "2024-10-10T08:03:36.798000",
          "created": "2024-09-10T08:28:16.120000",
          "tags": [
            "amazonaws",
            "employment scam",
            "pe resource",
            "united",
            "as15169 google",
            "aaaa",
            "unknown",
            "search",
            "as44273 host",
            "passive dns",
            "all scoreblue",
            "worm",
            "files",
            "error",
            "code",
            "emails",
            "ireland",
            "poland",
            "high",
            "yara detections",
            "virus",
            "msvisualcpp2003",
            "high process",
            "injection t1055",
            "t1055",
            "icmp traffic",
            "pe file",
            "service",
            "win32",
            "copy",
            "tools",
            "cryptsoft",
            "nxdomain",
            "a br",
            "key management",
            "meta",
            "open",
            "twitter",
            "a domains",
            "cryptsoft src",
            "meet cryptsoft",
            "products a",
            "authority",
            "record value",
            "contact",
            "metro",
            "log id",
            "gmtn",
            "go daddy",
            "tls web",
            "arizona",
            "scottsdale",
            "ca issuers",
            "false",
            "windows nt",
            "msie",
            "read c",
            "ms windows",
            "intel",
            "et trojan",
            "pe32",
            "zip archive",
            "write",
            "possible",
            "malware",
            "beethoven",
            "et",
            "body",
            "scan endpoints",
            "category",
            "file samples",
            "files matching",
            "date hash",
            "phishing",
            "show",
            "t1045",
            "nrv2x",
            "lzma",
            "laszlo molnar",
            "john reiser",
            "antivirus",
            "xp sp2",
            "sp2 working",
            "alerts",
            "contacted",
            "0pgtwhu",
            "filehash",
            "february",
            "crack.zip",
            "as396982 google",
            "urls",
            "domain",
            "hostname",
            "next",
            "belgium unknown",
            "status",
            "name servers",
            "creation date",
            "date",
            "servers",
            "entries",
            "trojan",
            "ipv4",
            "pulse pulses",
            "ransom",
            "gandcrab",
            "active",
            "parking crews"
          ],
          "references": [
            "Researched: http://www.forensickb.com/2013/03/file-entropy-explained.html",
            "https://otx.alienvault.com/otxapi/indicators/url/screenshot/http://www.forensickb.com/2013/03/file-entropy-explained.html",
            "www.crackedmindstechnologies.com",
            "IDS Detections: Tempedreve Checkin Hiloti Style GET to PHP with invalid terse MSIE headers W32/Bayrob Attempted Checkin 2",
            "Observed GandCrab Ransomware Domain (carder .bit in DNS Lookup) Worm.Mydoom Checkin",
            "IDS Detections:  User-Agent (explwer) Hiloti/Mufanom Downloader Checkin Win32/Unruy.R Checkin Ransom.Win32.Birele.gsg Checkin Observed GandCrab Ransomware Domain (ransomware .bit in DNS Lookup)",
            "IDS Detections: Worm.Mydoom Checkin User-Agent (explwer) Hiloti/Mufanom Downloader Checkin Win32/Unruy.R Checkin",
            "IDS Detections: Ransom.Win32.Birele.gsg Checkin Observed GandCrab Ransomware Domain (ransomware .bit in DNS Lookup)",
            "relay.cryptsoft.com | smtp.cryptsoft.com\t| ghs.google.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Romania",
            "Netherlands",
            "Poland",
            "Belgium",
            "Germany",
            "Spain",
            "Italy",
            "Czechia",
            "Austria",
            "Bulgaria",
            "Canada",
            "United Arab Emirates"
          ],
          "malware_families": [
            {
              "id": "Virus:Win32/Sality.AT",
              "display_name": "Virus:Win32/Sality.AT",
              "target": "/malware/Virus:Win32/Sality.AT"
            },
            {
              "id": "Win32:Kukacka",
              "display_name": "Win32:Kukacka",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            },
            {
              "id": "Worm:Win32/Mydoom.O!backdoor",
              "display_name": "Worm:Win32/Mydoom.O!backdoor",
              "target": "/malware/Worm:Win32/Mydoom.O!backdoor"
            },
            {
              "id": "Worm:Win32/Bloored.E",
              "display_name": "Worm:Win32/Bloored.E",
              "target": "/malware/Worm:Win32/Bloored.E"
            },
            {
              "id": "GandCrab",
              "display_name": "GandCrab",
              "target": null
            },
            {
              "id": "TrojanSpy:Win32/Nivdort.AJ",
              "display_name": "TrojanSpy:Win32/Nivdort.AJ",
              "target": "/malware/TrojanSpy:Win32/Nivdort.AJ"
            },
            {
              "id": "TrojanSpy:Win32/Invader.S!MSR",
              "display_name": "TrojanSpy:Win32/Invader.S!MSR",
              "target": "/malware/TrojanSpy:Win32/Invader.S!MSR"
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1089",
              "name": "Disabling Security Tools",
              "display_name": "T1089 - Disabling Security Tools"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            }
          ],
          "industries": [
            "Telecommunications"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 220,
            "FileHash-MD5": 626,
            "FileHash-SHA1": 539,
            "FileHash-SHA256": 1335,
            "domain": 501,
            "hostname": 617,
            "email": 4,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 3844,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "600 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "657099cf5e89b0e746c45d1a",
          "name": "bad header p3p csv from 2020 - basically some shady youtube shit and torrents \ud83d\udc81",
          "description": "",
          "modified": "2023-12-06T15:57:03.643000",
          "created": "2023-12-06T15:57:03.643000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 123,
            "hostname": 72,
            "domain": 56,
            "URL": 2513,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 2766,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "909 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64482a3f2b107b380abdc5f7",
          "name": "bad header p3p csv from 2020 - basically some shady youtube shit and torrents \ud83d\udc81",
          "description": "File upload: https://otx.alienvault.com/indicator/file/6b383976427a4a9e932ac6516af5a6198d4f6828f63beac882107596203903b8",
          "modified": "2023-04-25T20:09:10.655000",
          "created": "2023-04-25T19:30:07.973000",
          "tags": [
            "united",
            "america",
            "privacy",
            "netherlands",
            "meppel",
            "viet nam",
            "vnpt corp",
            "array",
            "tuyen quang",
            "hanoi",
            "https://otx.alienvault.com/indicator/file/6b383976427a4a9e932ac6"
          ],
          "references": [
            "p3p-policy-commonto.1000klist.pulsedive_1605829585.csv",
            "https://otx.alienvault.com/indicator/file/6b383976427a4a9e932ac6516af5a6198d4f6828f63beac882107596203903b8",
            "youtube torrents"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3788,
            "hostname": 125,
            "domain": 66,
            "FileHash-SHA256": 306,
            "IPv4": 13,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 4300,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1133 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "623234d546c4b6558c6a5de8",
          "name": "pelosi.house.gov_03.02.2022",
          "description": "",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T19:04:53.397000",
          "tags": [],
          "references": [
            "pelosi.house1df.pdf",
            "pelosi.house.gov_03.02.2022.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 65,
            "URL": 227,
            "FileHash-SHA256": 550,
            "domain": 34,
            "FileHash-MD5": 33,
            "CIDR": 2,
            "FileHash-SHA1": 1
          },
          "indicator_count": 912,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 405,
          "modified_text": "1509 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "pelosi.house1df.pdf",
        "pelosi.house.gov_03.02.2022.pdf",
        "https://otx.alienvault.com/indicator/file/6b383976427a4a9e932ac6516af5a6198d4f6828f63beac882107596203903b8",
        "Observed GandCrab Ransomware Domain (carder .bit in DNS Lookup) Worm.Mydoom Checkin",
        "IDS Detections:  User-Agent (explwer) Hiloti/Mufanom Downloader Checkin Win32/Unruy.R Checkin Ransom.Win32.Birele.gsg Checkin Observed GandCrab Ransomware Domain (ransomware .bit in DNS Lookup)",
        "www.crackedmindstechnologies.com",
        "IDS Detections: Worm.Mydoom Checkin User-Agent (explwer) Hiloti/Mufanom Downloader Checkin Win32/Unruy.R Checkin",
        "https://otx.alienvault.com/otxapi/indicators/url/screenshot/http://www.forensickb.com/2013/03/file-entropy-explained.html",
        "relay.cryptsoft.com | smtp.cryptsoft.com\t| ghs.google.com",
        "IDS Detections: Tempedreve Checkin Hiloti Style GET to PHP with invalid terse MSIE headers W32/Bayrob Attempted Checkin 2",
        "p3p-policy-commonto.1000klist.pulsedive_1605829585.csv",
        "Researched: http://www.forensickb.com/2013/03/file-entropy-explained.html",
        "youtube torrents",
        "IDS Detections: Ransom.Win32.Birele.gsg Checkin Observed GandCrab Ransomware Domain (ransomware .bit in DNS Lookup)"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "Tier-1 SaaS Reputation Parasitism Leveraging Wix Infrastructure"
          ],
          "malware_families": [
            "Worm:win32/bloored.e",
            "Virus:win32/sality.at",
            "Trojanspy:win32/invader.s!msr",
            "#lowfi:hstr:pyinstaller_packaged_script",
            "#exploit:win32/blofeldscat",
            "Tel:exploit:html/pswebkit",
            "Alf:heraklezeval:trojan:win32/c2lop",
            "Win32:kukacka",
            "Worm:win32/mydoom.o!backdoor",
            "Trojanspy:win32/nivdort.aj",
            "Gandcrab",
            "Et"
          ],
          "industries": [
            "Telecommunications",
            "Government"
          ],
          "unique_indicators": 14679
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/youtube.com",
    "whois": "http://whois.domaintools.com/youtube.com",
    "domain": "youtube.com",
    "hostname": "www.youtube.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 11,
  "pulses": [
    {
      "id": "69ad4f70dd8cd3a4bae75670",
      "name": "krnaver.com- BL! 10 month of no sleep and all i could read was ralph nader #doh",
      "description": "Pulse\nPulses\n5\nPassive DNS\n39\nURLs\n12\nFiles\n1K\nAnalysis Overview\nIP Address\n104.17.232.29\nLocation\n\nUnited States\nASN\nAS13335 cloudflare\nNameservers\nns36.domaincontrol.com.\n, \nns35.domaincontrol.com.\nWHOIS\nRegistrar:\nXiamen Domains, Inc.,  \nCreation Date:\nNov 12, 2016\nRelated Pulses\nOTX User-Created Pulses (5)\nRelated Tags\nNone\nIndicator Facts\n1000 malicious files communicating\nHistorical OTX telemetry\nRunning webserver\n2 subdomains\nNumber of malicious files communicating with the domain or subdomains\nAntivirus Detections\nBackdoor:Win32/Venik.E!dha\n, \nBackdoor:Win32/Venik.I\n, \nBackdoor:Win32/Venik.J\n, \nWin.Trojan.Packed-123\nAV Detection Ratio\n1000\n / 1000",
      "modified": "2026-04-07T10:26:55.912000",
      "created": "2026-03-08T10:29:04.330000",
      "tags": [
        "backdoor",
        "pulse",
        "passive dns",
        "urls",
        "files",
        "ip address",
        "location united",
        "asn as13335",
        "whois registrar",
        "domains"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 321,
        "hostname": 85,
        "URL": 87,
        "FileHash-MD5": 151,
        "FileHash-SHA1": 151,
        "FileHash-SHA256": 152,
        "email": 6
      },
      "indicator_count": 953,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "56 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69aa3786e3fd41dfed869f60",
      "name": "Stealthy Bruteforce Evasion/ est every 3 hrs change if not provoked sooner",
      "description": "MITRE- Command and Control\tDefense Evasion\tPrivilege Escalation\nT1071 - Application Layer Protocol\nnetwork_http\nstealth_network\nT1055 - Process Injection\ncreates_suspended_process",
      "modified": "2026-04-05T02:39:58.334000",
      "created": "2026-03-06T02:10:14.833000",
      "tags": [
        "ascii text",
        "file size",
        "sha256",
        "mwdb",
        "bazaar",
        "sha3384",
        "crc32",
        "ssdeep"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 1,
        "hostname": 55,
        "URL": 3
      },
      "indicator_count": 61,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "58 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69aa3a2a1577d2537fbb0b3f",
      "name": "DNS Configuration Mismatch",
      "description": "DNS Configuration Mismatch: 32 entries show outbound UDP Port 53 traffic to 8.8.8.8. This traffic is non-compliant with the user-defined resolver.\nUnauthorized Redirection: The telemetry confirms an active bypass of local system settings, indicating either hard-coded application behavior or network-level redirection.\nNetBIOS Broadcast Activity: Entries for Port 137 involving 172.16.1.1 and the broadcast address 172.16.1.255 indicate internal device discovery/name registration on the local subnet.\nExternal Cloud Handshake: A single session to 52.123.250.178 via Port 443 (HTTPS) establishes an encrypted connection to Microsoft/Azure infrastructure.\nAnomalous Traffic Density: The high ratio of unauthorized DNS queries relative to standard web traffic (32:1) suggests a potential Command & Control (C2) beaconing or DNS tunneling profile.",
      "modified": "2026-04-05T02:39:58.334000",
      "created": "2026-03-06T02:21:30.645000",
      "tags": [
        "ip address",
        "port"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 58,
        "URL": 5,
        "FileHash-MD5": 2,
        "FileHash-SHA256": 2,
        "domain": 2
      },
      "indicator_count": 69,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "58 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698c3273517158869e0ba780",
      "name": "Reputation Shielded C2 Pivot; High-Churn Wix Infrastructure with iCloud Exfil Adjacency",
      "description": "Researcher Note (Feb 11, 2026) IPv4 185.230.61.96 (AS58182 \u2013 Wix.com Ltd.), resolving to unalocated.61.wixsite.com, demonstrates indicators consistent with structured abuse of shared SaaS hosting for command-and-control operations. Passive DNS telemetry reflects 500+ historical domain bindings across 52 TLDs, suggesting deliberate namespace dispersion and rotational overlay management rather than static tenancy. Network detections include repeated FormBook HTTP GET check-ins, Pushdo loader beacon cadence, and Windows Network Diagnostics user-agent spoofing, collectively aligning with controlled tasking infrastructure. Associated artifacts (11/50 AV detections) cluster around credential-stealer and loader families, including FormBook and GandCrab lineage components. The behavioral profile supports assessment of reputation parasitism\u2014leveraging trusted hosting to inherit platform trust and evade domain-based enforcement controls. Confidence: Moderate-High. MITRE: T1071.001, T1105, T1036.",
      "modified": "2026-03-29T00:29:26.398000",
      "created": "2026-02-11T07:40:32.757000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "Tier-1 SaaS Reputation Parasitism Leveraging Wix Infrastructure",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 265,
        "domain": 294,
        "URL": 331,
        "email": 12,
        "CVE": 61,
        "FileHash-MD5": 73,
        "FileHash-SHA1": 64,
        "FileHash-SHA256": 74
      },
      "indicator_count": 1174,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 76,
      "modified_text": "65 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6988faa4f668aeeed6f86da8",
      "name": "zero trust",
      "description": "researcher credit: msudoSOS : CLBCatQ.DLL\tThe malware is hijacking your COM+ Class Catalog to hide as a System Service.\nCoMarshalInterface\tYour identity is being \"packaged\" and sent via the LTE Trial to the '' Edge.\npid 2356 / 2812\tThese are the active processes currently communicating with the 49.12.22.106 C2 server.",
      "modified": "2026-03-27T09:05:26.285000",
      "created": "2026-02-08T21:05:37.829000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ALF:HeraklezEval:Trojan:Win32/C2Lop",
          "display_name": "ALF:HeraklezEval:Trojan:Win32/C2Lop",
          "target": null
        },
        {
          "id": "#LowFi:HSTR:PyInstaller_Packaged_Script",
          "display_name": "#LowFi:HSTR:PyInstaller_Packaged_Script",
          "target": null
        },
        {
          "id": "#Exploit:Win32/BlofeldsCat",
          "display_name": "#Exploit:Win32/BlofeldsCat",
          "target": "/malware/#Exploit:Win32/BlofeldsCat"
        },
        {
          "id": "TEL:Exploit:HTML/PSWebkit",
          "display_name": "TEL:Exploit:HTML/PSWebkit",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 394,
        "hostname": 250,
        "CVE": 112,
        "URL": 190,
        "email": 25,
        "JA3": 1,
        "FileHash-MD5": 191,
        "FileHash-SHA1": 214,
        "FileHash-SHA256": 607
      },
      "indicator_count": 1984,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 82,
      "modified_text": "67 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698904c316bc7710b967d01d",
      "name": "Rare Tier 1 Persistence - Critical \"Patched\", Non Patched Vulnerabilities Remain bypassing Lockdown Mode",
      "description": "Researcher Note (Feb 08, 2026):\nThis artifact represents a sophisticated Cross-Protocol Mesh. Observations confirm that the Cymt/Nemucod wrapper is being utilized as a delivery vehicle for a Firmware-resident ELF binary (Mirai variant).\nThe persistence is notable for its ability to survive Full DFU Restores and Faraday-isolated states, likely due to JTAG-level interaction with the Power Management IC (Chip 4799). This is not a standard opportunistic infection; it is a targeted provisioning event leveraging IDMSA (Identity Management) bridges and Verizon/Akamai Edge infrastructure.\nThe integration with CalendarKit and Maps for geofenced execution suggests a highly coordinated surveillance objective. Forensic analysts should pay specific attention to the sizeofrawdata_antidbg anomalies, which indicate a focus on bypassing Apple Lockdown Mode and Secure Enclave. \nresearcher credit: msudoSOS",
      "modified": "2026-03-27T09:05:26.285000",
      "created": "2026-02-08T21:48:49.147000",
      "tags": [
        "#supportsitewebsiteabuse #rootcertificatefailure #cryptographicf"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 909,
        "URL": 1779,
        "CVE": 126,
        "domain": 659,
        "email": 23,
        "JA3": 1,
        "FileHash-MD5": 230,
        "FileHash-SHA1": 227,
        "FileHash-SHA256": 934,
        "CIDR": 13
      },
      "indicator_count": 4901,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 76,
      "modified_text": "67 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69ada442ba9893ca65ae8b87",
      "name": "VirusTotal report\n                    for base.apk",
      "description": "We are going to be the ones leaning on Fury. To win this, I don't need to be heavy, I need to be fast and quick.",
      "modified": "2026-03-08T16:30:58.152000",
      "created": "2026-03-08T16:30:58.152000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1406",
          "name": "Obfuscated Files or Information",
          "display_name": "T1406 - Obfuscated Files or Information"
        },
        {
          "id": "T1409",
          "name": "Access Stored Application Data",
          "display_name": "T1409 - Access Stored Application Data"
        },
        {
          "id": "T1421",
          "name": "System Network Connections Discovery",
          "display_name": "T1421 - System Network Connections Discovery"
        },
        {
          "id": "T1422",
          "name": "System Network Configuration Discovery",
          "display_name": "T1422 - System Network Configuration Discovery"
        },
        {
          "id": "T1424",
          "name": "Process Discovery",
          "display_name": "T1424 - Process Discovery"
        },
        {
          "id": "T1426",
          "name": "System Information Discovery",
          "display_name": "T1426 - System Information Discovery"
        },
        {
          "id": "T1430",
          "name": "Location Tracking",
          "display_name": "T1430 - Location Tracking"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 1,
        "URL": 47,
        "domain": 10,
        "hostname": 21
      },
      "indicator_count": 81,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "86 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66e00320d65236e032faa26a",
      "name": "Global- Injection | Phone service modification campaign - Cryprsoft",
      "description": "Malicious\u00bb http://www.forensickb.com/2013/03/file-entropy-explained.html | Cryptsoft | ET ,\nVirus:Win32/Sality.AT ,\nWin32:Kukacka , TrojanSpy:Win32/Nivdort.AJ , Worm:Win32/Mydoom.O!backdoor , \nWorm:Win32/Bloored , TrojanSpy:Win32/Invader.S!MSR , \nText: Mydoom spreading via SMTP 29 192.168.56.110 198.133.159.125 2018340 ET TROJAN Win32.Sality-GR Checkin 192.168.56.110 52.28.249.128 2018340 ET TROJAN Win32.Sality-GR Checkin 192.168.56.110 166.78.145.90 2016803 ET TROJAN Known Sinkhole Response Header 166.78.145.90 192.168.56.110 2018\nATT&CK | Query Registry , Modify Existing Service , Scheduled Task/Job , Process Injection , Registry Run Keys / Startup Folder , System Information Discovery , Disabling Security Tools , Modify Registry",
      "modified": "2024-10-10T08:03:36.798000",
      "created": "2024-09-10T08:28:16.120000",
      "tags": [
        "amazonaws",
        "employment scam",
        "pe resource",
        "united",
        "as15169 google",
        "aaaa",
        "unknown",
        "search",
        "as44273 host",
        "passive dns",
        "all scoreblue",
        "worm",
        "files",
        "error",
        "code",
        "emails",
        "ireland",
        "poland",
        "high",
        "yara detections",
        "virus",
        "msvisualcpp2003",
        "high process",
        "injection t1055",
        "t1055",
        "icmp traffic",
        "pe file",
        "service",
        "win32",
        "copy",
        "tools",
        "cryptsoft",
        "nxdomain",
        "a br",
        "key management",
        "meta",
        "open",
        "twitter",
        "a domains",
        "cryptsoft src",
        "meet cryptsoft",
        "products a",
        "authority",
        "record value",
        "contact",
        "metro",
        "log id",
        "gmtn",
        "go daddy",
        "tls web",
        "arizona",
        "scottsdale",
        "ca issuers",
        "false",
        "windows nt",
        "msie",
        "read c",
        "ms windows",
        "intel",
        "et trojan",
        "pe32",
        "zip archive",
        "write",
        "possible",
        "malware",
        "beethoven",
        "et",
        "body",
        "scan endpoints",
        "category",
        "file samples",
        "files matching",
        "date hash",
        "phishing",
        "show",
        "t1045",
        "nrv2x",
        "lzma",
        "laszlo molnar",
        "john reiser",
        "antivirus",
        "xp sp2",
        "sp2 working",
        "alerts",
        "contacted",
        "0pgtwhu",
        "filehash",
        "february",
        "crack.zip",
        "as396982 google",
        "urls",
        "domain",
        "hostname",
        "next",
        "belgium unknown",
        "status",
        "name servers",
        "creation date",
        "date",
        "servers",
        "entries",
        "trojan",
        "ipv4",
        "pulse pulses",
        "ransom",
        "gandcrab",
        "active",
        "parking crews"
      ],
      "references": [
        "Researched: http://www.forensickb.com/2013/03/file-entropy-explained.html",
        "https://otx.alienvault.com/otxapi/indicators/url/screenshot/http://www.forensickb.com/2013/03/file-entropy-explained.html",
        "www.crackedmindstechnologies.com",
        "IDS Detections: Tempedreve Checkin Hiloti Style GET to PHP with invalid terse MSIE headers W32/Bayrob Attempted Checkin 2",
        "Observed GandCrab Ransomware Domain (carder .bit in DNS Lookup) Worm.Mydoom Checkin",
        "IDS Detections:  User-Agent (explwer) Hiloti/Mufanom Downloader Checkin Win32/Unruy.R Checkin Ransom.Win32.Birele.gsg Checkin Observed GandCrab Ransomware Domain (ransomware .bit in DNS Lookup)",
        "IDS Detections: Worm.Mydoom Checkin User-Agent (explwer) Hiloti/Mufanom Downloader Checkin Win32/Unruy.R Checkin",
        "IDS Detections: Ransom.Win32.Birele.gsg Checkin Observed GandCrab Ransomware Domain (ransomware .bit in DNS Lookup)",
        "relay.cryptsoft.com | smtp.cryptsoft.com\t| ghs.google.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Romania",
        "Netherlands",
        "Poland",
        "Belgium",
        "Germany",
        "Spain",
        "Italy",
        "Czechia",
        "Austria",
        "Bulgaria",
        "Canada",
        "United Arab Emirates"
      ],
      "malware_families": [
        {
          "id": "Virus:Win32/Sality.AT",
          "display_name": "Virus:Win32/Sality.AT",
          "target": "/malware/Virus:Win32/Sality.AT"
        },
        {
          "id": "Win32:Kukacka",
          "display_name": "Win32:Kukacka",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        },
        {
          "id": "Worm:Win32/Mydoom.O!backdoor",
          "display_name": "Worm:Win32/Mydoom.O!backdoor",
          "target": "/malware/Worm:Win32/Mydoom.O!backdoor"
        },
        {
          "id": "Worm:Win32/Bloored.E",
          "display_name": "Worm:Win32/Bloored.E",
          "target": "/malware/Worm:Win32/Bloored.E"
        },
        {
          "id": "GandCrab",
          "display_name": "GandCrab",
          "target": null
        },
        {
          "id": "TrojanSpy:Win32/Nivdort.AJ",
          "display_name": "TrojanSpy:Win32/Nivdort.AJ",
          "target": "/malware/TrojanSpy:Win32/Nivdort.AJ"
        },
        {
          "id": "TrojanSpy:Win32/Invader.S!MSR",
          "display_name": "TrojanSpy:Win32/Invader.S!MSR",
          "target": "/malware/TrojanSpy:Win32/Invader.S!MSR"
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1089",
          "name": "Disabling Security Tools",
          "display_name": "T1089 - Disabling Security Tools"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        }
      ],
      "industries": [
        "Telecommunications"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 220,
        "FileHash-MD5": 626,
        "FileHash-SHA1": 539,
        "FileHash-SHA256": 1335,
        "domain": 501,
        "hostname": 617,
        "email": 4,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 3844,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 230,
      "modified_text": "600 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "657099cf5e89b0e746c45d1a",
      "name": "bad header p3p csv from 2020 - basically some shady youtube shit and torrents \ud83d\udc81",
      "description": "",
      "modified": "2023-12-06T15:57:03.643000",
      "created": "2023-12-06T15:57:03.643000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 123,
        "hostname": 72,
        "domain": 56,
        "URL": 2513,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1
      },
      "indicator_count": 2766,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "909 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "64482a3f2b107b380abdc5f7",
      "name": "bad header p3p csv from 2020 - basically some shady youtube shit and torrents \ud83d\udc81",
      "description": "File upload: https://otx.alienvault.com/indicator/file/6b383976427a4a9e932ac6516af5a6198d4f6828f63beac882107596203903b8",
      "modified": "2023-04-25T20:09:10.655000",
      "created": "2023-04-25T19:30:07.973000",
      "tags": [
        "united",
        "america",
        "privacy",
        "netherlands",
        "meppel",
        "viet nam",
        "vnpt corp",
        "array",
        "tuyen quang",
        "hanoi",
        "https://otx.alienvault.com/indicator/file/6b383976427a4a9e932ac6"
      ],
      "references": [
        "p3p-policy-commonto.1000klist.pulsedive_1605829585.csv",
        "https://otx.alienvault.com/indicator/file/6b383976427a4a9e932ac6516af5a6198d4f6828f63beac882107596203903b8",
        "youtube torrents"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3788,
        "hostname": 125,
        "domain": 66,
        "FileHash-SHA256": 306,
        "IPv4": 13,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1
      },
      "indicator_count": 4300,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "1133 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.youtube.com/watch",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.youtube.com/watch",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780421539.4577785
}