{
  "type": "URL",
  "indicator": "https://www.zendesk.com/privacy",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.zendesk.com/privacy",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "alexa",
        "message": "Alexa rank: #292",
        "name": "Listed on Alexa"
      },
      {
        "source": "akamai",
        "message": "Akamai rank: #1325",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "whitelist",
        "message": "Whitelisted domain zendesk.com",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain zendesk.com",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3427864348,
      "indicator": "https://www.zendesk.com/privacy",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "6a10c1936b635b73722e3b80",
          "name": "C2 Widget unsigned, masqueraded Wmiprvse.[exe] * CAPE Sandbox",
          "description": "High-confidence detection of a masqueraded Wmiprvse.exe binary. Despite a 2019 creation timestamp, the file lacks digital signatures and exhibits aggressive (LotL) behaviors including resource hijacking and unauthorized HTTP egress.\nDomain: Wmiprvse.exe (Masqueraded)Hash (SHA-256): 50994d21e...  (Ghost-No Certs / No IP) red flag- lack of digital certificate data. Standard (WMI) binaries are signed by Microsoft. An unsigned version indicates the binary has been modified, hollowed, or replaced. The binary initiates HTTP Comms without resolving to a  domain or static IP in the static analysis phase, suggesting it may use (DGA) or hidden (P2P) instructions that only trigger under specific sandbox conditions. 2019-  It likely exploits legacy WMI vulnerabilities or utilizes the WMI Event Sub. method to maintain persistence across reboots. Utilizing a 2019, the malware attempts to blend in as an \"old, trusted\" system file to bypass scanners that prioritize scanning new/recently modified files.",
          "modified": "2026-05-25T09:43:10.181000",
          "created": "2026-05-22T20:50:27.987000",
          "tags": [
            "please",
            "chat",
            "cancel",
            "email",
            "sorry",
            "zendesk chat",
            "back",
            "name",
            "chat rating",
            "click",
            "close",
            "enterprise",
            "premium",
            "legacy",
            "friday",
            "hello",
            "mitre attack",
            "network info",
            "sigma",
            "program",
            "mid frommemory",
            "overview",
            "processes extra",
            "overview zenbox",
            "verdict",
            "guest system",
            "next",
            "unicode text",
            "utf8 text",
            "javascript",
            "show",
            "standards",
            "technology",
            "detail",
            "wordpress",
            "cves",
            "widget logic",
            "institute",
            "widget context",
            "request forgery",
            "widget",
            "impact",
            "site request",
            "forgery",
            "csrf",
            "cve20267615",
            "slider",
            "elementor",
            "scripting",
            "mount",
            "cve20264341",
            "bundle",
            "cvecve202620858",
            "free",
            "exploit",
            "abusedmost",
            "vbscript",
            "jscript",
            "wmi traffic",
            "remote wmi",
            "port",
            "dcom",
            "powershell"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/50994d21e6e536c08192cb8956f81eacfef9f30a0a7a5e0353331260944c074c_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779482077&Signature=nJUEiJ6dQ9BpsB0iqcay0woOAG%2Fp%2FZrQWO3F9ECQng4g5IghQMR2UtGHtz69%2BXwm5SmZln9qdlb6k8fO3vZ1i8iYCIYD4to7EkIelW2SmdfX%2FvBT9VAo4l%2B74GtPn32h%2BRAZCfkA%2Fa7jIs%2BL5GfGqOjOyCossQG6h%2FHhJlhOk5%2FEmdR0SPESzQzsQaDNt9eRcjgm4HvCXbbia01tcosvJrvko3cIKinj0xKmSzUI7k",
            "https://vtbehaviour.commondatastorage.googleapis.com/50994d21e6e536c08192cb8956f81eacfef9f30a0a7a5e0353331260944c074c_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779482097&Signature=sACP7gBBLJngNhl4IUXtgAiK29nO0W90X4yE9f7kzzAPem3FAhuJfM1VaC4SBLuxW%2FHZBwX1ugrpwkF5q3iP6n9XnEoXtrzlFgd2Y6Q%2FEWrXgE3dKrKOfdT4lLqIJ6Z9gNMupmI84vm5KvS2pvUnuhEc5odbK6Iefl%2Bc8dtZeittEaaKcGiFdYPcEhS%2Fb5Okxu9LLjb%2Fm8u%2BzcrWLWM736OdZwQpDnsmGctSIytTKdxEMUZElJdrtTyd8A"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 5,
            "IPv4": 23,
            "URL": 30,
            "hostname": 49,
            "domain": 7,
            "CVE": 9
          },
          "indicator_count": 128,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "6 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a10c193e508eb580d8d5352",
          "name": "C2 Widget unsigned, masqueraded Wmiprvse.[exe] * CAPE Sandbox",
          "description": "High-confidence detection of a masqueraded Wmiprvse.exe binary. Despite a 2019 creation timestamp, the file lacks digital signatures and exhibits aggressive (LotL) behaviors including resource hijacking and unauthorized HTTP egress.\nDomain: Wmiprvse.exe (Masqueraded)Hash (SHA-256): 50994d21e...  (Ghost-No Certs / No IP) red flag- lack of digital certificate data. Standard (WMI) binaries are signed by Microsoft. An unsigned version indicates the binary has been modified, hollowed, or replaced. The binary initiates HTTP Comms without resolving to a  domain or static IP in the static analysis phase, suggesting it may use (DGA) or hidden (P2P) instructions that only trigger under specific sandbox conditions. 2019-  It likely exploits legacy WMI vulnerabilities or utilizes the WMI Event Sub. method to maintain persistence across reboots. Utilizing a 2019, the malware attempts to blend in as an \"old, trusted\" system file to bypass scanners that prioritize scanning new/recently modified files.",
          "modified": "2026-05-25T09:43:09.022000",
          "created": "2026-05-22T20:50:27.547000",
          "tags": [
            "please",
            "chat",
            "cancel",
            "email",
            "sorry",
            "zendesk chat",
            "back",
            "name",
            "chat rating",
            "click",
            "close",
            "enterprise",
            "premium",
            "legacy",
            "friday",
            "hello",
            "mitre attack",
            "network info",
            "sigma",
            "program",
            "mid frommemory",
            "overview",
            "processes extra",
            "overview zenbox",
            "verdict",
            "guest system",
            "next",
            "unicode text",
            "utf8 text",
            "javascript",
            "show",
            "standards",
            "technology",
            "detail",
            "wordpress",
            "cves",
            "widget logic",
            "institute",
            "widget context",
            "request forgery",
            "widget",
            "impact",
            "site request",
            "forgery",
            "csrf",
            "cve20267615",
            "slider",
            "elementor",
            "scripting",
            "mount",
            "cve20264341",
            "bundle",
            "cvecve202620858",
            "free",
            "exploit",
            "abusedmost",
            "vbscript",
            "jscript",
            "wmi traffic",
            "remote wmi",
            "port",
            "dcom",
            "powershell"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/50994d21e6e536c08192cb8956f81eacfef9f30a0a7a5e0353331260944c074c_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779482077&Signature=nJUEiJ6dQ9BpsB0iqcay0woOAG%2Fp%2FZrQWO3F9ECQng4g5IghQMR2UtGHtz69%2BXwm5SmZln9qdlb6k8fO3vZ1i8iYCIYD4to7EkIelW2SmdfX%2FvBT9VAo4l%2B74GtPn32h%2BRAZCfkA%2Fa7jIs%2BL5GfGqOjOyCossQG6h%2FHhJlhOk5%2FEmdR0SPESzQzsQaDNt9eRcjgm4HvCXbbia01tcosvJrvko3cIKinj0xKmSzUI7k",
            "https://vtbehaviour.commondatastorage.googleapis.com/50994d21e6e536c08192cb8956f81eacfef9f30a0a7a5e0353331260944c074c_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779482097&Signature=sACP7gBBLJngNhl4IUXtgAiK29nO0W90X4yE9f7kzzAPem3FAhuJfM1VaC4SBLuxW%2FHZBwX1ugrpwkF5q3iP6n9XnEoXtrzlFgd2Y6Q%2FEWrXgE3dKrKOfdT4lLqIJ6Z9gNMupmI84vm5KvS2pvUnuhEc5odbK6Iefl%2Bc8dtZeittEaaKcGiFdYPcEhS%2Fb5Okxu9LLjb%2Fm8u%2BzcrWLWM736OdZwQpDnsmGctSIytTKdxEMUZElJdrtTyd8A"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 5,
            "IPv4": 23,
            "URL": 30,
            "hostname": 49,
            "domain": 7,
            "CVE": 9
          },
          "indicator_count": 128,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "6 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c13ee010f81d3f9b3af",
          "name": "Malware hosting - hostrocket.com",
          "description": "",
          "modified": "2023-12-06T14:58:27.115000",
          "created": "2023-12-06T14:58:27.115000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 232,
            "hostname": 963,
            "domain": 412,
            "URL": 2337,
            "email": 3,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 3949,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f492a0581b2eb202e47c9",
          "name": "Malware hosting - hostrocket.com",
          "description": "ChunkLoadError, a new type of error, failed to load a chunk of JavaScript, according to the web browser operator, E.noconflict.com, as well as the website itself.",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T23:43:38.539000",
          "tags": [
            "jxuiwidget",
            "null",
            "function",
            "jxuihtmldiv",
            "date",
            "jxuilabel",
            "zendesk chat",
            "regexp",
            "api update",
            "jxuihtmla",
            "window",
            "chat",
            "void",
            "error",
            "loader",
            "back",
            "click",
            "close",
            "agent",
            "hello",
            "form",
            "banned",
            "cookie",
            "small",
            "legacy",
            "direct",
            "colorbox core",
            "style",
            "user style",
            "colorbox",
            "html",
            "6deg",
            "e5e5e5",
            "dbdbdb",
            "d2d2d2",
            "eaedef",
            "michael farrell",
            "home",
            "helvetica",
            "ssd shared",
            "page",
            "formnum",
            "hidden",
            "current",
            "hostrocket",
            "dotblock",
            "fast",
            "href",
            "price slider",
            "tooltip",
            "dotblock popup",
            "callback",
            "rect",
            "cycle plugin",
            "number",
            "auto",
            "shuffle",
            "manual",
            "roll",
            "speed",
            "stop",
            "false",
            "first",
            "look",
            "copyright",
            "gpl version",
            "http",
            "document",
            "ui effects",
            "width",
            "left",
            "bottom",
            "this",
            "atom",
            "html id",
            "price",
            "timer",
            "value",
            "processor",
            "example",
            "storage",
            "string",
            "class",
            "thecookie",
            "create",
            "thevalue",
            "param",
            "type",
            "pluginscookie",
            "author",
            "jquery",
            "u00a0",
            "option",
            "body",
            "optgroup",
            "multiple",
            "selectboxhover",
            "selectbox",
            "label",
            "control",
            "slideshow",
            "jack moore",
            "mit license",
            "overlay",
            "wrapper",
            "content",
            "loadedcontent",
            "loadingoverlay",
            "next",
            "iframe",
            "array",
            "attr",
            "tools",
            "ui library",
            "no copyrights",
            "or licenses",
            "like",
            "media",
            "john resig",
            "dual",
            "gtmkw8b5l",
            "classes",
            "host",
            "path",
            "element",
            "trackpageview",
            "typeerror",
            "typeof symbol",
            "typeof e",
            "typeof t",
            "referenceerror",
            "promise",
            "script",
            "boolean",
            "typeof n"
          ],
          "references": [
            "xfe-URL-hostrocket.com-stix2-2.1-export 2.json",
            "https://www.googletagmanager.com/gtm.js?id=GTM-KW8B5L",
            "https://www.hostrocket.com/js/jquery-1.6.1.min.js",
            "https://www.hostrocket.com/js/jquery.tools.min.js",
            "https://www.hostrocket.com/js/jquery.colorbox-min.js",
            "https://www.hostrocket.com/js/jquery.selectBox.min.js",
            "https://www.hostrocket.com/js/jquery.cookie.js",
            "https://www.hostrocket.com/js/jquery.price_slider.js",
            "https://www.hostrocket.com/js/jquery-ui-1.8.13.custom.min.js",
            "https://www.hostrocket.com/js/jquery.cycle.all.js",
            "https://www.hostrocket.com/js/jquery.behavior.js",
            "https://www.hostrocket.com/contact-files/contact-form.js",
            "https://www.hostrocket.com/css/style.css",
            "https://www.hostrocket.com/css/colorbox.css",
            "https://www.hostrocket.com/css/style-nophone.css",
            "https://v2.zopim.com/bin/v/widget_v2.329.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 963,
            "email": 3,
            "domain": 412,
            "URL": 2338,
            "FileHash-SHA256": 232,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 3950,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1473 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.hostrocket.com/js/jquery.selectBox.min.js",
        "https://vtbehaviour.commondatastorage.googleapis.com/50994d21e6e536c08192cb8956f81eacfef9f30a0a7a5e0353331260944c074c_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779482097&Signature=sACP7gBBLJngNhl4IUXtgAiK29nO0W90X4yE9f7kzzAPem3FAhuJfM1VaC4SBLuxW%2FHZBwX1ugrpwkF5q3iP6n9XnEoXtrzlFgd2Y6Q%2FEWrXgE3dKrKOfdT4lLqIJ6Z9gNMupmI84vm5KvS2pvUnuhEc5odbK6Iefl%2Bc8dtZeittEaaKcGiFdYPcEhS%2Fb5Okxu9LLjb%2Fm8u%2BzcrWLWM736OdZwQpDnsmGctSIytTKdxEMUZElJdrtTyd8A",
        "https://www.hostrocket.com/css/colorbox.css",
        "https://www.hostrocket.com/js/jquery.behavior.js",
        "https://www.hostrocket.com/css/style-nophone.css",
        "https://www.hostrocket.com/js/jquery.colorbox-min.js",
        "https://v2.zopim.com/bin/v/widget_v2.329.js",
        "https://vtbehaviour.commondatastorage.googleapis.com/50994d21e6e536c08192cb8956f81eacfef9f30a0a7a5e0353331260944c074c_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779482077&Signature=nJUEiJ6dQ9BpsB0iqcay0woOAG%2Fp%2FZrQWO3F9ECQng4g5IghQMR2UtGHtz69%2BXwm5SmZln9qdlb6k8fO3vZ1i8iYCIYD4to7EkIelW2SmdfX%2FvBT9VAo4l%2B74GtPn32h%2BRAZCfkA%2Fa7jIs%2BL5GfGqOjOyCossQG6h%2FHhJlhOk5%2FEmdR0SPESzQzsQaDNt9eRcjgm4HvCXbbia01tcosvJrvko3cIKinj0xKmSzUI7k",
        "https://www.hostrocket.com/js/jquery-ui-1.8.13.custom.min.js",
        "xfe-URL-hostrocket.com-stix2-2.1-export 2.json",
        "https://www.hostrocket.com/js/jquery.cycle.all.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-KW8B5L",
        "https://www.hostrocket.com/js/jquery-1.6.1.min.js",
        "https://www.hostrocket.com/js/jquery.tools.min.js",
        "https://www.hostrocket.com/js/jquery.cookie.js",
        "https://www.hostrocket.com/contact-files/contact-form.js",
        "https://www.hostrocket.com/css/style.css",
        "https://www.hostrocket.com/js/jquery.price_slider.js"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 4078
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/zendesk.com",
    "whois": "http://whois.domaintools.com/zendesk.com",
    "domain": "zendesk.com",
    "hostname": "www.zendesk.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "6a10c1936b635b73722e3b80",
      "name": "C2 Widget unsigned, masqueraded Wmiprvse.[exe] * CAPE Sandbox",
      "description": "High-confidence detection of a masqueraded Wmiprvse.exe binary. Despite a 2019 creation timestamp, the file lacks digital signatures and exhibits aggressive (LotL) behaviors including resource hijacking and unauthorized HTTP egress.\nDomain: Wmiprvse.exe (Masqueraded)Hash (SHA-256): 50994d21e...  (Ghost-No Certs / No IP) red flag- lack of digital certificate data. Standard (WMI) binaries are signed by Microsoft. An unsigned version indicates the binary has been modified, hollowed, or replaced. The binary initiates HTTP Comms without resolving to a  domain or static IP in the static analysis phase, suggesting it may use (DGA) or hidden (P2P) instructions that only trigger under specific sandbox conditions. 2019-  It likely exploits legacy WMI vulnerabilities or utilizes the WMI Event Sub. method to maintain persistence across reboots. Utilizing a 2019, the malware attempts to blend in as an \"old, trusted\" system file to bypass scanners that prioritize scanning new/recently modified files.",
      "modified": "2026-05-25T09:43:10.181000",
      "created": "2026-05-22T20:50:27.987000",
      "tags": [
        "please",
        "chat",
        "cancel",
        "email",
        "sorry",
        "zendesk chat",
        "back",
        "name",
        "chat rating",
        "click",
        "close",
        "enterprise",
        "premium",
        "legacy",
        "friday",
        "hello",
        "mitre attack",
        "network info",
        "sigma",
        "program",
        "mid frommemory",
        "overview",
        "processes extra",
        "overview zenbox",
        "verdict",
        "guest system",
        "next",
        "unicode text",
        "utf8 text",
        "javascript",
        "show",
        "standards",
        "technology",
        "detail",
        "wordpress",
        "cves",
        "widget logic",
        "institute",
        "widget context",
        "request forgery",
        "widget",
        "impact",
        "site request",
        "forgery",
        "csrf",
        "cve20267615",
        "slider",
        "elementor",
        "scripting",
        "mount",
        "cve20264341",
        "bundle",
        "cvecve202620858",
        "free",
        "exploit",
        "abusedmost",
        "vbscript",
        "jscript",
        "wmi traffic",
        "remote wmi",
        "port",
        "dcom",
        "powershell"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/50994d21e6e536c08192cb8956f81eacfef9f30a0a7a5e0353331260944c074c_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779482077&Signature=nJUEiJ6dQ9BpsB0iqcay0woOAG%2Fp%2FZrQWO3F9ECQng4g5IghQMR2UtGHtz69%2BXwm5SmZln9qdlb6k8fO3vZ1i8iYCIYD4to7EkIelW2SmdfX%2FvBT9VAo4l%2B74GtPn32h%2BRAZCfkA%2Fa7jIs%2BL5GfGqOjOyCossQG6h%2FHhJlhOk5%2FEmdR0SPESzQzsQaDNt9eRcjgm4HvCXbbia01tcosvJrvko3cIKinj0xKmSzUI7k",
        "https://vtbehaviour.commondatastorage.googleapis.com/50994d21e6e536c08192cb8956f81eacfef9f30a0a7a5e0353331260944c074c_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779482097&Signature=sACP7gBBLJngNhl4IUXtgAiK29nO0W90X4yE9f7kzzAPem3FAhuJfM1VaC4SBLuxW%2FHZBwX1ugrpwkF5q3iP6n9XnEoXtrzlFgd2Y6Q%2FEWrXgE3dKrKOfdT4lLqIJ6Z9gNMupmI84vm5KvS2pvUnuhEc5odbK6Iefl%2Bc8dtZeittEaaKcGiFdYPcEhS%2Fb5Okxu9LLjb%2Fm8u%2BzcrWLWM736OdZwQpDnsmGctSIytTKdxEMUZElJdrtTyd8A"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 3,
        "FileHash-SHA1": 2,
        "FileHash-SHA256": 5,
        "IPv4": 23,
        "URL": 30,
        "hostname": 49,
        "domain": 7,
        "CVE": 9
      },
      "indicator_count": 128,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "6 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a10c193e508eb580d8d5352",
      "name": "C2 Widget unsigned, masqueraded Wmiprvse.[exe] * CAPE Sandbox",
      "description": "High-confidence detection of a masqueraded Wmiprvse.exe binary. Despite a 2019 creation timestamp, the file lacks digital signatures and exhibits aggressive (LotL) behaviors including resource hijacking and unauthorized HTTP egress.\nDomain: Wmiprvse.exe (Masqueraded)Hash (SHA-256): 50994d21e...  (Ghost-No Certs / No IP) red flag- lack of digital certificate data. Standard (WMI) binaries are signed by Microsoft. An unsigned version indicates the binary has been modified, hollowed, or replaced. The binary initiates HTTP Comms without resolving to a  domain or static IP in the static analysis phase, suggesting it may use (DGA) or hidden (P2P) instructions that only trigger under specific sandbox conditions. 2019-  It likely exploits legacy WMI vulnerabilities or utilizes the WMI Event Sub. method to maintain persistence across reboots. Utilizing a 2019, the malware attempts to blend in as an \"old, trusted\" system file to bypass scanners that prioritize scanning new/recently modified files.",
      "modified": "2026-05-25T09:43:09.022000",
      "created": "2026-05-22T20:50:27.547000",
      "tags": [
        "please",
        "chat",
        "cancel",
        "email",
        "sorry",
        "zendesk chat",
        "back",
        "name",
        "chat rating",
        "click",
        "close",
        "enterprise",
        "premium",
        "legacy",
        "friday",
        "hello",
        "mitre attack",
        "network info",
        "sigma",
        "program",
        "mid frommemory",
        "overview",
        "processes extra",
        "overview zenbox",
        "verdict",
        "guest system",
        "next",
        "unicode text",
        "utf8 text",
        "javascript",
        "show",
        "standards",
        "technology",
        "detail",
        "wordpress",
        "cves",
        "widget logic",
        "institute",
        "widget context",
        "request forgery",
        "widget",
        "impact",
        "site request",
        "forgery",
        "csrf",
        "cve20267615",
        "slider",
        "elementor",
        "scripting",
        "mount",
        "cve20264341",
        "bundle",
        "cvecve202620858",
        "free",
        "exploit",
        "abusedmost",
        "vbscript",
        "jscript",
        "wmi traffic",
        "remote wmi",
        "port",
        "dcom",
        "powershell"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/50994d21e6e536c08192cb8956f81eacfef9f30a0a7a5e0353331260944c074c_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779482077&Signature=nJUEiJ6dQ9BpsB0iqcay0woOAG%2Fp%2FZrQWO3F9ECQng4g5IghQMR2UtGHtz69%2BXwm5SmZln9qdlb6k8fO3vZ1i8iYCIYD4to7EkIelW2SmdfX%2FvBT9VAo4l%2B74GtPn32h%2BRAZCfkA%2Fa7jIs%2BL5GfGqOjOyCossQG6h%2FHhJlhOk5%2FEmdR0SPESzQzsQaDNt9eRcjgm4HvCXbbia01tcosvJrvko3cIKinj0xKmSzUI7k",
        "https://vtbehaviour.commondatastorage.googleapis.com/50994d21e6e536c08192cb8956f81eacfef9f30a0a7a5e0353331260944c074c_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779482097&Signature=sACP7gBBLJngNhl4IUXtgAiK29nO0W90X4yE9f7kzzAPem3FAhuJfM1VaC4SBLuxW%2FHZBwX1ugrpwkF5q3iP6n9XnEoXtrzlFgd2Y6Q%2FEWrXgE3dKrKOfdT4lLqIJ6Z9gNMupmI84vm5KvS2pvUnuhEc5odbK6Iefl%2Bc8dtZeittEaaKcGiFdYPcEhS%2Fb5Okxu9LLjb%2Fm8u%2BzcrWLWM736OdZwQpDnsmGctSIytTKdxEMUZElJdrtTyd8A"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 3,
        "FileHash-SHA1": 2,
        "FileHash-SHA256": 5,
        "IPv4": 23,
        "URL": 30,
        "hostname": 49,
        "domain": 7,
        "CVE": 9
      },
      "indicator_count": 128,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "6 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708c13ee010f81d3f9b3af",
      "name": "Malware hosting - hostrocket.com",
      "description": "",
      "modified": "2023-12-06T14:58:27.115000",
      "created": "2023-12-06T14:58:27.115000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 232,
        "hostname": 963,
        "domain": 412,
        "URL": 2337,
        "email": 3,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1
      },
      "indicator_count": 3949,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "625f492a0581b2eb202e47c9",
      "name": "Malware hosting - hostrocket.com",
      "description": "ChunkLoadError, a new type of error, failed to load a chunk of JavaScript, according to the web browser operator, E.noconflict.com, as well as the website itself.",
      "modified": "2022-05-19T00:00:49.028000",
      "created": "2022-04-19T23:43:38.539000",
      "tags": [
        "jxuiwidget",
        "null",
        "function",
        "jxuihtmldiv",
        "date",
        "jxuilabel",
        "zendesk chat",
        "regexp",
        "api update",
        "jxuihtmla",
        "window",
        "chat",
        "void",
        "error",
        "loader",
        "back",
        "click",
        "close",
        "agent",
        "hello",
        "form",
        "banned",
        "cookie",
        "small",
        "legacy",
        "direct",
        "colorbox core",
        "style",
        "user style",
        "colorbox",
        "html",
        "6deg",
        "e5e5e5",
        "dbdbdb",
        "d2d2d2",
        "eaedef",
        "michael farrell",
        "home",
        "helvetica",
        "ssd shared",
        "page",
        "formnum",
        "hidden",
        "current",
        "hostrocket",
        "dotblock",
        "fast",
        "href",
        "price slider",
        "tooltip",
        "dotblock popup",
        "callback",
        "rect",
        "cycle plugin",
        "number",
        "auto",
        "shuffle",
        "manual",
        "roll",
        "speed",
        "stop",
        "false",
        "first",
        "look",
        "copyright",
        "gpl version",
        "http",
        "document",
        "ui effects",
        "width",
        "left",
        "bottom",
        "this",
        "atom",
        "html id",
        "price",
        "timer",
        "value",
        "processor",
        "example",
        "storage",
        "string",
        "class",
        "thecookie",
        "create",
        "thevalue",
        "param",
        "type",
        "pluginscookie",
        "author",
        "jquery",
        "u00a0",
        "option",
        "body",
        "optgroup",
        "multiple",
        "selectboxhover",
        "selectbox",
        "label",
        "control",
        "slideshow",
        "jack moore",
        "mit license",
        "overlay",
        "wrapper",
        "content",
        "loadedcontent",
        "loadingoverlay",
        "next",
        "iframe",
        "array",
        "attr",
        "tools",
        "ui library",
        "no copyrights",
        "or licenses",
        "like",
        "media",
        "john resig",
        "dual",
        "gtmkw8b5l",
        "classes",
        "host",
        "path",
        "element",
        "trackpageview",
        "typeerror",
        "typeof symbol",
        "typeof e",
        "typeof t",
        "referenceerror",
        "promise",
        "script",
        "boolean",
        "typeof n"
      ],
      "references": [
        "xfe-URL-hostrocket.com-stix2-2.1-export 2.json",
        "https://www.googletagmanager.com/gtm.js?id=GTM-KW8B5L",
        "https://www.hostrocket.com/js/jquery-1.6.1.min.js",
        "https://www.hostrocket.com/js/jquery.tools.min.js",
        "https://www.hostrocket.com/js/jquery.colorbox-min.js",
        "https://www.hostrocket.com/js/jquery.selectBox.min.js",
        "https://www.hostrocket.com/js/jquery.cookie.js",
        "https://www.hostrocket.com/js/jquery.price_slider.js",
        "https://www.hostrocket.com/js/jquery-ui-1.8.13.custom.min.js",
        "https://www.hostrocket.com/js/jquery.cycle.all.js",
        "https://www.hostrocket.com/js/jquery.behavior.js",
        "https://www.hostrocket.com/contact-files/contact-form.js",
        "https://www.hostrocket.com/css/style.css",
        "https://www.hostrocket.com/css/colorbox.css",
        "https://www.hostrocket.com/css/style-nophone.css",
        "https://v2.zopim.com/bin/v/widget_v2.329.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 963,
        "email": 3,
        "domain": 412,
        "URL": 2338,
        "FileHash-SHA256": 232,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1
      },
      "indicator_count": 3950,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1473 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.zendesk.com/privacy",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.zendesk.com/privacy",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780242372.407975
}