{
  "type": "URL",
  "indicator": "https://www.zhiqihuo.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.zhiqihuo.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3526890123,
      "indicator": "https://www.zhiqihuo.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 12,
      "pulses": [
        {
          "id": "65a4885e735b9e8ba94805bc",
          "name": "Apple | Worm:Win32/Benjamin | thebrotherssabey.com",
          "description": "",
          "modified": "2024-09-05T06:51:42.608000",
          "created": "2024-01-15T01:20:30.730000",
          "tags": [
            "execution",
            "whois record",
            "contacted",
            "ssl certificate",
            "whois whois",
            "contacted urls",
            "copy",
            "historical ssl",
            "referrer",
            "urls url",
            "icmp",
            "malicious",
            "installer",
            "problems",
            "collections",
            "report",
            "phishing",
            "service tool",
            "greatness",
            "threat network",
            "emotet",
            "magniber",
            "startpage",
            "attack",
            "banker",
            "keylogger",
            "namecheap inc",
            "com laude",
            "ltd dba",
            "cloudflare",
            "porkbun llc",
            "ii llc",
            "csc corporate",
            "domains",
            "computer",
            "company limited",
            "first",
            "cloudflarenet",
            "google",
            "amazon02",
            "akamaias",
            "telecom italia",
            "utc submissions",
            "microsoftcorpas",
            "indonesia",
            "beijing gu",
            "appleaustin",
            "sucurisec",
            "amazonaes",
            "limited",
            "tsara brashears",
            "pornhub",
            "thebrotherssabey",
            "then brothers sabey",
            "brian sabey",
            "apple",
            "icloud",
            "apple engineering",
            "soc",
            "hacker",
            "teams",
            "malvertizing",
            "cyberthreat",
            "cyber crime",
            "data",
            "v3 serial",
            "number",
            "cgb stgreater",
            "ecc domain",
            "server ca",
            "subject public",
            "key info",
            "key algorithm",
            "ec oid",
            "remote",
            "remote attacker",
            "benjamin",
            "worm",
            "trojan",
            "win32",
            "trojanspy",
            "ransomware",
            "command and control",
            "cnc",
            "c2",
            "stealer",
            "password",
            "apple unlocker",
            "pornographers",
            "cyber stalking",
            "revenge rat",
            "masquerading",
            "scanning host",
            "phishing",
            "dns",
            "network",
            "cobalt strike",
            "mitre attack",
            "metro hacker",
            "t-mobile hacker",
            "stalker",
            "social engineering",
            "et",
            "torrent trecker",
            "view",
            "duckdns",
            "blackhat",
            "data center",
            "tracking",
            "illegal",
            "malware scripting",
            "malware spreader",
            "network rat",
            "multiple botnetworks"
          ],
          "references": [
            "https://thebrotherssabey.wordpress.com/",
            "acam-mdn.apple.com",
            "beacons.bcp.gvt.com",
            "cpcontacts.webcamara.online",
            "http://dreamsofspanking.com/scene/item/rosie-backlash-caning?utm_campaign=apr15",
            "http://ti.hicloudcam.com",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://search.app.goo.gl/?ofl",
            "Worm:Win32/Benjamin",
            "FileHash-SHA256\t00000254e6344d34a1e4ef157cb01d8b7efa65c22c996f9dfe85e7482c6c86ab",
            "FileHash-MD5\ted5c771224fbd6f9b2c0cf1e8cce09b5",
            "FileHash-SHA1\tf336b50f5cca2ddc0341e2c4001b419a830d27a5",
            "applemusic-spotlight.myunidays.com",
            "nr-data.net",
            "http://init.ess.apple.com/WebObjects/VCInit.woa/wa/getBag?ix=4",
            "blackhat.store",
            "api.telegram.org",
            "cobaltstrike4.tk | https://cobaltstrike4.tk:8443/include/template/isx.php"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Worm:Win32/Benjamin",
              "display_name": "Worm:Win32/Benjamin",
              "target": "/malware/Worm:Win32/Benjamin"
            },
            {
              "id": "#Lowfi:SIGA:TrojanSpy:MSIL/Keylogger",
              "display_name": "#Lowfi:SIGA:TrojanSpy:MSIL/Keylogger",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Silk",
              "display_name": "Silk",
              "target": null
            },
            {
              "id": "Sabey",
              "display_name": "Sabey",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65a429795adf468b427a3c8b",
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 2469,
            "URL": 6038,
            "FileHash-MD5": 169,
            "FileHash-SHA1": 157,
            "FileHash-SHA256": 3922,
            "CIDR": 2,
            "hostname": 2787,
            "email": 2,
            "CVE": 1
          },
          "indicator_count": 15547,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "633 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65a8720daa2d0263a2b1de88",
          "name": "Linux/Mumblehard introduction via  phone call  Social Engineering",
          "description": "Already deeply compromised individuals more at risk of elaborate phone call interception/redirect/transfer from legitimate services. Many different schemes are used to access and nullify victims identity, involves ssn#, bank account information, email exchange text messaging, PDF exchange, Spam sent to all known accounts, password reset, request for ID upload to verify (steal) identity, extensive holds while trying to 'help' you, unannounced credit check ID theft. Ransomware, Linux attack, Botnetwork behavior.  Active threat. Linux/Mumblehard backdoor/botnet",
          "modified": "2024-02-17T00:01:16.653000",
          "created": "2024-01-18T00:34:21.136000",
          "tags": [
            "ssl certificate",
            "april",
            "resolutions",
            "threat roundup",
            "whois record",
            "historical ssl",
            "vt graph",
            "attack",
            "formbook",
            "subdomains",
            "august",
            "cobalt strike",
            "mumblehard",
            "iframe",
            "djcodychase.com",
            "first",
            "utc submissions",
            "submitters",
            "webico company",
            "limited",
            "summary iocs",
            "graph community",
            "urls",
            "gandi sas",
            "amazonaes",
            "cloudflarenet",
            "computer",
            "company limited",
            "cloud host",
            "pte ltd",
            "singlehopllc",
            "squarespace",
            "amazon02",
            "team internet",
            "google",
            "internapblk4",
            "domains",
            "registrar",
            "dynadot llc",
            "ip detections",
            "country",
            "detections type",
            "name",
            "win32 exe",
            "file size",
            "detections file",
            "kb file",
            "execution",
            "contacted",
            "apple ios",
            "tsara brashears",
            "virus network",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "matches rule",
            "relacionada",
            "hacktool",
            "emotet",
            "critical",
            "copy",
            "installer",
            "banker",
            "keylogger",
            "it's back",
            "name verdict",
            "falcon sandbox",
            "json data",
            "localappdata",
            "temp",
            "getprocaddress",
            "windir",
            "ascii text",
            "file",
            "indicator",
            "mitre att",
            "ck id",
            "win64",
            "path",
            "date",
            "factory",
            "hybrid",
            "cookie",
            "benjamin"
          ],
          "references": [
            "djcodychase.com",
            "https://www.trendmicro.com/vinfo/gb/security/news/cybercrime-and-digital-threats/mumblehard-botnet-that-targeted-linux-systems-has-been-shut-down Source Trend"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Backdoor:Linux/Mumblehard",
              "display_name": "Backdoor:Linux/Mumblehard",
              "target": "/malware/Backdoor:Linux/Mumblehard"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "FormBook",
              "display_name": "FormBook",
              "target": null
            },
            {
              "id": "Win.Dropper.XtremeRAT-7708589-0",
              "display_name": "Win.Dropper.XtremeRAT-7708589-0",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Worm:Win32/Benjamin",
              "display_name": "Worm:Win32/Benjamin",
              "target": "/malware/Worm:Win32/Benjamin"
            }
          ],
          "attack_ids": [
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 114,
            "FileHash-SHA1": 106,
            "FileHash-SHA256": 3407,
            "URL": 6246,
            "domain": 2463,
            "hostname": 1693,
            "CVE": 2
          },
          "indicator_count": 14031,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "834 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65aab9d7a0b4116f622b0aa0",
          "name": "Linux/Mumblehard introduction via phone call Social Engineering",
          "description": "",
          "modified": "2024-02-17T00:01:16.653000",
          "created": "2024-01-19T18:05:11.592000",
          "tags": [
            "ssl certificate",
            "april",
            "resolutions",
            "threat roundup",
            "whois record",
            "historical ssl",
            "vt graph",
            "attack",
            "formbook",
            "subdomains",
            "august",
            "cobalt strike",
            "mumblehard",
            "iframe",
            "djcodychase.com",
            "first",
            "utc submissions",
            "submitters",
            "webico company",
            "limited",
            "summary iocs",
            "graph community",
            "urls",
            "gandi sas",
            "amazonaes",
            "cloudflarenet",
            "computer",
            "company limited",
            "cloud host",
            "pte ltd",
            "singlehopllc",
            "squarespace",
            "amazon02",
            "team internet",
            "google",
            "internapblk4",
            "domains",
            "registrar",
            "dynadot llc",
            "ip detections",
            "country",
            "detections type",
            "name",
            "win32 exe",
            "file size",
            "detections file",
            "kb file",
            "execution",
            "contacted",
            "apple ios",
            "tsara brashears",
            "virus network",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "matches rule",
            "relacionada",
            "hacktool",
            "emotet",
            "critical",
            "copy",
            "installer",
            "banker",
            "keylogger",
            "it's back",
            "name verdict",
            "falcon sandbox",
            "json data",
            "localappdata",
            "temp",
            "getprocaddress",
            "windir",
            "ascii text",
            "file",
            "indicator",
            "mitre att",
            "ck id",
            "win64",
            "path",
            "date",
            "factory",
            "hybrid",
            "cookie",
            "benjamin"
          ],
          "references": [
            "djcodychase.com",
            "https://www.trendmicro.com/vinfo/gb/security/news/cybercrime-and-digital-threats/mumblehard-botnet-that-targeted-linux-systems-has-been-shut-down Source Trend"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Backdoor:Linux/Mumblehard",
              "display_name": "Backdoor:Linux/Mumblehard",
              "target": "/malware/Backdoor:Linux/Mumblehard"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "FormBook",
              "display_name": "FormBook",
              "target": null
            },
            {
              "id": "Win.Dropper.XtremeRAT-7708589-0",
              "display_name": "Win.Dropper.XtremeRAT-7708589-0",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Worm:Win32/Benjamin",
              "display_name": "Worm:Win32/Benjamin",
              "target": "/malware/Worm:Win32/Benjamin"
            }
          ],
          "attack_ids": [
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65a8720daa2d0263a2b1de88",
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 114,
            "FileHash-SHA1": 106,
            "FileHash-SHA256": 3407,
            "URL": 6246,
            "domain": 2463,
            "hostname": 1693,
            "CVE": 2
          },
          "indicator_count": 14031,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "834 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65a429795adf468b427a3c8b",
          "name": "Apple | Worm:Win32/Benjamin | thebrotherssabey.com",
          "description": "Retaliation. Brian Sabey representing as an attorney and many other occupations contacted and socially engineered target. Uncertain of true name. Contacted 'alleged' SA assault victim. Made claims of representing a Jeffrey Scott Reimer DPT' alleged 'S' Assaulter.  Substantiated claims made with the twist of 'victim consented'. Mark Brian Sbabeys claims dismissed. Continues to hack, harass, intimidate target in every possible way. Hacking, monitoring, service, modification, phone contact, malicious texting, in person monitoring via colleagues, hacks into medical and medical billing centers, sells/leaks targets data on dark web.    Removed targets name from most pulses via  remote device access. Self whitelist. Everything he does is illegal.\n\nTarget not important enough to law enforcement.",
          "modified": "2024-02-13T17:04:19.437000",
          "created": "2024-01-14T18:35:37.757000",
          "tags": [
            "execution",
            "whois record",
            "contacted",
            "ssl certificate",
            "whois whois",
            "contacted urls",
            "copy",
            "historical ssl",
            "referrer",
            "urls url",
            "icmp",
            "malicious",
            "installer",
            "problems",
            "collections",
            "report",
            "phishing",
            "service tool",
            "greatness",
            "threat network",
            "emotet",
            "magniber",
            "startpage",
            "attack",
            "banker",
            "keylogger",
            "namecheap inc",
            "com laude",
            "ltd dba",
            "cloudflare",
            "porkbun llc",
            "ii llc",
            "csc corporate",
            "domains",
            "computer",
            "company limited",
            "first",
            "cloudflarenet",
            "google",
            "amazon02",
            "akamaias",
            "telecom italia",
            "utc submissions",
            "microsoftcorpas",
            "indonesia",
            "beijing gu",
            "appleaustin",
            "sucurisec",
            "amazonaes",
            "limited",
            "tsara brashears",
            "pornhub",
            "thebrotherssabey",
            "then brothers sabey",
            "brian sabey",
            "apple",
            "icloud",
            "apple engineering",
            "soc",
            "hacker",
            "teams",
            "malvertizing",
            "cyberthreat",
            "cyber crime",
            "data",
            "v3 serial",
            "number",
            "cgb stgreater",
            "ecc domain",
            "server ca",
            "subject public",
            "key info",
            "key algorithm",
            "ec oid",
            "remote",
            "remote attacker",
            "benjamin",
            "worm",
            "trojan",
            "win32",
            "trojanspy",
            "ransomware",
            "command and control",
            "cnc",
            "c2",
            "stealer",
            "password",
            "apple unlocker",
            "pornographers",
            "cyber stalking",
            "revenge rat",
            "masquerading",
            "scanning host",
            "phishing",
            "dns",
            "network",
            "cobalt strike",
            "mitre attack",
            "metro hacker",
            "t-mobile hacker",
            "stalker",
            "social engineering",
            "et",
            "torrent trecker",
            "view",
            "duckdns",
            "blackhat",
            "data center",
            "tracking",
            "illegal",
            "malware scripting",
            "malware spreader",
            "network rat",
            "multiple botnetworks"
          ],
          "references": [
            "https://thebrotherssabey.wordpress.com/",
            "acam-mdn.apple.com",
            "beacons.bcp.gvt.com",
            "cpcontacts.webcamara.online",
            "http://dreamsofspanking.com/scene/item/rosie-backlash-caning?utm_campaign=apr15",
            "http://ti.hicloudcam.com",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://search.app.goo.gl/?ofl",
            "Worm:Win32/Benjamin",
            "FileHash-SHA256\t00000254e6344d34a1e4ef157cb01d8b7efa65c22c996f9dfe85e7482c6c86ab",
            "FileHash-MD5\ted5c771224fbd6f9b2c0cf1e8cce09b5",
            "FileHash-SHA1\tf336b50f5cca2ddc0341e2c4001b419a830d27a5",
            "applemusic-spotlight.myunidays.com",
            "nr-data.net",
            "http://init.ess.apple.com/WebObjects/VCInit.woa/wa/getBag?ix=4",
            "blackhat.store",
            "api.telegram.org",
            "cobaltstrike4.tk | https://cobaltstrike4.tk:8443/include/template/isx.php"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Worm:Win32/Benjamin",
              "display_name": "Worm:Win32/Benjamin",
              "target": "/malware/Worm:Win32/Benjamin"
            },
            {
              "id": "#Lowfi:SIGA:TrojanSpy:MSIL/Keylogger",
              "display_name": "#Lowfi:SIGA:TrojanSpy:MSIL/Keylogger",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Silk",
              "display_name": "Silk",
              "target": null
            },
            {
              "id": "Sabey",
              "display_name": "Sabey",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 2462,
            "URL": 5950,
            "FileHash-MD5": 168,
            "FileHash-SHA1": 156,
            "FileHash-SHA256": 3901,
            "CIDR": 2,
            "hostname": 2766,
            "email": 2,
            "CVE": 1
          },
          "indicator_count": 15408,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "838 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65a2f9169d6996c1c928ac0b",
          "name": "Remote attack: Win32/Enosch.A gtalk connectivity check | High Priority",
          "description": "W32/Enosch.A!tr is classified as a Trojan. Trojan has the capabilities to remote access connection handling, perform Denial of Service (DoS) attacks. Worms automatically spread to other PCs. This threat can perform a number of actions of a malicious hacker's choice. This hacker is choosing to delete files, accounts, pulses, by graphs while acting as user.  An authenticated use in browser bar https://www.google.com/?authuser=0.\n\nAttempts to modify,delete graphs, pulses, accounts, passwords. Acting as user.",
          "modified": "2024-02-12T20:02:49.516000",
          "created": "2024-01-13T20:56:54.333000",
          "tags": [
            "default",
            "show",
            "regsetvalueexa",
            "search",
            "regdword",
            "medium",
            "settingswpad",
            "delete",
            "ids detections",
            "yara detections",
            "worm",
            "malware",
            "copy",
            "write",
            "win32",
            "first",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "summary iocs",
            "graph community",
            "productidis",
            "urls",
            "mb iesettings",
            "related file",
            "cybersecurity",
            "agency",
            "csc corporate",
            "domains",
            "tucows domains",
            "nameweb bvba",
            "tucows",
            "google",
            "amazon02",
            "twitter",
            "ovh sas",
            "facebook",
            "incapsula",
            "optimizer",
            "activator",
            "kb program",
            "mb super",
            "kb acrotray",
            "1tzv",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "hostnames",
            "urls https",
            "checks_debugger",
            "network_icmp",
            "network_smtp",
            "persistence_autorun",
            "modifies_proxy_wpad",
            "antivm_queries_computername",
            "dumped_buffer",
            "network_http",
            "antivm_network_adapters",
            "smtp_gmail",
            "attacking",
            "browser",
            "object",
            "deleted",
            "deleting",
            "deleted virustotal graphs",
            "corruption",
            "legal",
            "gvt",
            "adams co",
            "colorado",
            "law",
            "illegal practices",
            "hacking",
            "enter rexxfield",
            "roberts",
            "smith",
            "script urls",
            "as20940",
            "united",
            "a domains",
            "certificate",
            "showing",
            "entries",
            "entrust",
            "scan endpoints",
            "district",
            "as16625 akamai",
            "aaaa",
            "passive dns",
            "united kingdom",
            "whitelisted",
            "modification",
            "silence",
            "state",
            "hostname",
            "samples",
            "cover up",
            "silencing",
            "Iowa.gov",
            "dga",
            "fcc",
            "unsigned",
            "remote",
            "wiper",
            "nosy pega",
            "trojan",
            "unknown",
            "access denied",
            "servers",
            "creation date",
            "date",
            "next",
            "apple",
            "ssl certificate",
            "threat roundup",
            "march",
            "october",
            "july",
            "april",
            "whois record",
            "june",
            "roundup",
            "september",
            "august",
            "plugx",
            "goldfinder",
            "sibot",
            "hacktool",
            "february",
            "regsz",
            "english",
            "nsisinetc",
            "mozilla",
            "adobe air",
            "java",
            "http",
            "post http",
            "updater",
            "meta",
            "suspicious",
            "persistence",
            "execution",
            "referrer",
            "communicating",
            "skynet",
            "malicious",
            "gen.o",
            "dynamicloader",
            "cape",
            "enosch malware",
            "enosch",
            "music",
            "contacted",
            "pe resource",
            "resolutions",
            "siblings",
            "urls http"
          ],
          "references": [
            "https://otx.alienvault.com/indicator/file/c98108ca8f4e0dd8a3f63d4ac490e115",
            "https://www.google.com/?authuser=0",
            "Wiper to Ransomware: The Evolution of Agrius - Sourced: ArcSight Threat Intelligence",
            "AS15133 MCI Communications Services Inc d b a Verizon Business, Loudon County, Va",
            "207 Iowa.gov domains and hosts acting as cyber security [cyberreason]",
            "iowa.gov, accidentreports.iowa.gov, beready.iowa.gov, affordableconnectivity.gov",
            "appanoosecounty.iowa.gov, bigben.iowa.gov [Ben Smith?]",
            "lacity.gov, auditortest.iowa.gov, broadband.iowa.gov, admin.auditor.iowa.gov,",
            "https://lacity.gov/san/index.htm, https://personnel.lacity.gov, https://lacity.gov/SAN,",
            "Domains Contacted: smtp.gmail.com www.google.com",
            "DGA Domain [affordableconnectivity.gov & GetInternet.gov]  Home ACP Universal Service Administrative Company",
            "www.fcc.gov? DGA Domains : Certificate Subject\tUS 443 Certificate Subject\tDistrict of Columbia 443 Certificate Subject\tWashington 443 Certificate Subject\tFederal Communications Commission 443 Certificate Subject\tGovernment Entity 443 Certificate Subject\t1934-06-19 443 Certificate Subject\taffordableconnectivity.gov 443 Certificate Issuer\tEntrust, Inc. 443 Certificate Issuer\tSee www.entrust.net/legal-terms 443 Certificate Issuer",
            "(c) 2014 Entrust, Inc. - for authorized use only 443 Certificate Issuer\tEntrust Certification Authority - L1M",
            "https://www.clear.com.br/site/DirectTalk/Filter?botopenned=3Dtrue [???]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Belgium",
            "Netherlands",
            "Spain",
            "Australia",
            "Korea, Republic of",
            "Hong Kong"
          ],
          "malware_families": [
            {
              "id": "Nullsoft_NSIS",
              "display_name": "Nullsoft_NSIS",
              "target": null
            },
            {
              "id": "Win32:Agent-ASTI\\ [Trj]",
              "display_name": "Win32:Agent-ASTI\\ [Trj]",
              "target": null
            },
            {
              "id": "Worm:Win32/Enosch!atmn",
              "display_name": "Worm:Win32/Enosch!atmn",
              "target": "/malware/Worm:Win32/Enosch!atmn"
            },
            {
              "id": "Win.Trojan.Agent-357800",
              "display_name": "Win.Trojan.Agent-357800",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 30,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2701,
            "FileHash-SHA1": 1512,
            "FileHash-SHA256": 5351,
            "SSLCertFingerprint": 1,
            "URL": 1774,
            "email": 7,
            "hostname": 1170,
            "domain": 1209
          },
          "indicator_count": 13725,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "838 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65a2f9200337f0d1fa195ada",
          "name": "Remote attack: Win32/Enosch.A gtalk connectivity check | High Priority",
          "description": "W32/Enosch.A!tr is classified as a Trojan. Trojan has the capabilities to remote access connection handling, perform Denial of Service (DoS) attacks. Worms automatically spread to other PCs. This threat can perform a number of actions of a malicious hacker's choice. This hacker is choosing to delete files, accounts, pulses, by graphs while acting as user.  An authenticated use in browser bar https://www.google.com/?authuser=0.\n\nAttempts to modify,delete graphs, pulses, accounts, passwords. Acting as user.",
          "modified": "2024-02-12T20:02:49.516000",
          "created": "2024-01-13T20:57:04.197000",
          "tags": [
            "default",
            "show",
            "regsetvalueexa",
            "search",
            "regdword",
            "medium",
            "settingswpad",
            "delete",
            "ids detections",
            "yara detections",
            "worm",
            "malware",
            "copy",
            "write",
            "win32",
            "first",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "summary iocs",
            "graph community",
            "productidis",
            "urls",
            "mb iesettings",
            "related file",
            "cybersecurity",
            "agency",
            "csc corporate",
            "domains",
            "tucows domains",
            "nameweb bvba",
            "tucows",
            "google",
            "amazon02",
            "twitter",
            "ovh sas",
            "facebook",
            "incapsula",
            "optimizer",
            "activator",
            "kb program",
            "mb super",
            "kb acrotray",
            "1tzv",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "hostnames",
            "urls https",
            "checks_debugger",
            "network_icmp",
            "network_smtp",
            "persistence_autorun",
            "modifies_proxy_wpad",
            "antivm_queries_computername",
            "dumped_buffer",
            "network_http",
            "antivm_network_adapters",
            "smtp_gmail",
            "attacking",
            "browser",
            "object",
            "deleted",
            "deleting",
            "deleted virustotal graphs",
            "corruption",
            "legal",
            "gvt",
            "adams co",
            "colorado",
            "law",
            "illegal practices",
            "hacking",
            "enter rexxfield",
            "roberts",
            "smith",
            "script urls",
            "as20940",
            "united",
            "a domains",
            "certificate",
            "showing",
            "entries",
            "entrust",
            "scan endpoints",
            "district",
            "as16625 akamai",
            "aaaa",
            "passive dns",
            "united kingdom",
            "whitelisted",
            "modification",
            "silence",
            "state",
            "hostname",
            "samples",
            "cover up",
            "silencing",
            "Iowa.gov",
            "dga",
            "fcc",
            "unsigned",
            "remote",
            "wiper",
            "nosy pega",
            "trojan",
            "unknown",
            "access denied",
            "servers",
            "creation date",
            "date",
            "next",
            "apple",
            "ssl certificate",
            "threat roundup",
            "march",
            "october",
            "july",
            "april",
            "whois record",
            "june",
            "roundup",
            "september",
            "august",
            "plugx",
            "goldfinder",
            "sibot",
            "hacktool",
            "february",
            "regsz",
            "english",
            "nsisinetc",
            "mozilla",
            "adobe air",
            "java",
            "http",
            "post http",
            "updater",
            "meta",
            "suspicious",
            "persistence",
            "execution",
            "referrer",
            "communicating",
            "skynet",
            "malicious",
            "gen.o",
            "dynamicloader",
            "cape",
            "enosch malware",
            "enosch",
            "music",
            "contacted",
            "pe resource",
            "resolutions",
            "siblings",
            "urls http"
          ],
          "references": [
            "https://otx.alienvault.com/indicator/file/c98108ca8f4e0dd8a3f63d4ac490e115",
            "https://www.google.com/?authuser=0",
            "Wiper to Ransomware: The Evolution of Agrius - Sourced: ArcSight Threat Intelligence",
            "AS15133 MCI Communications Services Inc d b a Verizon Business, Loudon County, Va",
            "207 Iowa.gov domains and hosts acting as cyber security [cyberreason]",
            "iowa.gov, accidentreports.iowa.gov, beready.iowa.gov, affordableconnectivity.gov",
            "appanoosecounty.iowa.gov, bigben.iowa.gov [Ben Smith?]",
            "lacity.gov, auditortest.iowa.gov, broadband.iowa.gov, admin.auditor.iowa.gov,",
            "https://lacity.gov/san/index.htm, https://personnel.lacity.gov, https://lacity.gov/SAN,",
            "Domains Contacted: smtp.gmail.com www.google.com",
            "DGA Domain [affordableconnectivity.gov & GetInternet.gov]  Home ACP Universal Service Administrative Company",
            "www.fcc.gov? DGA Domains : Certificate Subject\tUS 443 Certificate Subject\tDistrict of Columbia 443 Certificate Subject\tWashington 443 Certificate Subject\tFederal Communications Commission 443 Certificate Subject\tGovernment Entity 443 Certificate Subject\t1934-06-19 443 Certificate Subject\taffordableconnectivity.gov 443 Certificate Issuer\tEntrust, Inc. 443 Certificate Issuer\tSee www.entrust.net/legal-terms 443 Certificate Issuer",
            "(c) 2014 Entrust, Inc. - for authorized use only 443 Certificate Issuer\tEntrust Certification Authority - L1M",
            "https://www.clear.com.br/site/DirectTalk/Filter?botopenned=3Dtrue [???]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Belgium",
            "Netherlands",
            "Spain",
            "Australia",
            "Korea, Republic of",
            "Hong Kong"
          ],
          "malware_families": [
            {
              "id": "Nullsoft_NSIS",
              "display_name": "Nullsoft_NSIS",
              "target": null
            },
            {
              "id": "Win32:Agent-ASTI\\ [Trj]",
              "display_name": "Win32:Agent-ASTI\\ [Trj]",
              "target": null
            },
            {
              "id": "Worm:Win32/Enosch!atmn",
              "display_name": "Worm:Win32/Enosch!atmn",
              "target": "/malware/Worm:Win32/Enosch!atmn"
            },
            {
              "id": "Win.Trojan.Agent-357800",
              "display_name": "Win.Trojan.Agent-357800",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 33,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2701,
            "FileHash-SHA1": 1512,
            "FileHash-SHA256": 5351,
            "SSLCertFingerprint": 1,
            "URL": 1774,
            "email": 7,
            "hostname": 1170,
            "domain": 1209
          },
          "indicator_count": 13725,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "838 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655e5c72277117d3b0e00fbd",
          "name": "Command and Scripting Interpreter",
          "description": "https:/www.usaopps.com/government_contractors/contractor-5388777-SIERRA-PIPELINE-INC-.htm",
          "modified": "2023-12-22T19:00:52.050000",
          "created": "2023-11-22T19:54:26.925000",
          "tags": [
            "whois record",
            "contacted",
            "execution",
            "ssl certificate",
            "historical ssl",
            "resolutions",
            "problems",
            "red team",
            "whois whois",
            "referrer",
            "startpage",
            "generic malware",
            "cobaltstrike",
            "malware generic",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "blacklist https",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "malware",
            "malicious site",
            "malware site",
            "malicious url",
            "phishing site",
            "alexa",
            "phishing",
            "redline stealer",
            "bank",
            "team",
            "iframe",
            "downldr",
            "presenoker",
            "artemis",
            "live",
            "zbot",
            "united",
            "cyber threat",
            "covid19",
            "mail spammer",
            "malicious host",
            "anonymizer",
            "engineering",
            "purplewave",
            "malicious",
            "keybase",
            "union",
            "asyncrat",
            "cobalt strike",
            "dnspionage",
            "ransomware",
            "maltiverse",
            "malicious link",
            "detection list",
            "blacklist",
            "pattern match",
            "file",
            "ascii text",
            "windows nt",
            "appdata",
            "mitre att",
            "null",
            "date",
            "ck id",
            "show technique",
            "unknown",
            "accept",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "fast",
            "blacklist http",
            "heur",
            "adware",
            "unsafe",
            "riskware",
            "agent",
            "swrort",
            "exploit",
            "crack",
            "opencandy",
            "tiggre",
            "cleaner",
            "conduit",
            "wacatac",
            "nircmd",
            "filetour",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "installcore",
            "webshell",
            "acint",
            "systweak",
            "behav",
            "genkryptik",
            "xtrat",
            "softcnapp",
            "fusioncore",
            "installpack",
            "xrat",
            "jquery",
            "content scraper",
            "malware hosting",
            "bid site",
            "https:/www.usaopps.com/government_contractors/contractor-5388777",
            "CVE-2017-11882",
            "CVE-2017-0147",
            "CVE-2017-8570",
            "CVE-2005-1790",
            "CVE-2009-3672",
            "CVE-2010-3962",
            "CVE-2012-3993",
            "CVE-2014-3153",
            "CVE-2014-6332",
            "CVE-2016-0189",
            "CVE-2017-0199",
            "CVE-2018-4893",
            "CVE-2020-0601",
            "CVE-2020-0674",
            "CVE-2021-27065",
            "CVE-2021-40444"
          ],
          "references": [
            "https://www.hybrid-analysis.com/sample/bc437a855075805df699bd915cd27814a799969bb38db45f09f5f16a54ccc5b6/655e548bc2555fc8280ba976",
            "https:/www.usaopps.com/government_contractors/contractor-5388777-SIERRA-PIPELINE-INC-.htm"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            }
          ],
          "industries": [
            "Business",
            "Economy",
            "Government",
            "Legal"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 608,
            "FileHash-SHA1": 312,
            "FileHash-SHA256": 1086,
            "URL": 2843,
            "domain": 341,
            "hostname": 1091,
            "CVE": 16
          },
          "indicator_count": 6297,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "891 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65709943cc506763d721edec",
          "name": ":v3 - and the rest.... - www.tiuli.com/image/a057f08d1d773ab75e116ba4fffc595f.jpg?width=1080&#039;",
          "description": "",
          "modified": "2023-12-06T15:54:43.175000",
          "created": "2023-12-06T15:54:43.175000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 781,
            "domain": 712,
            "URL": 4962,
            "hostname": 1795,
            "email": 4,
            "FileHash-MD5": 164,
            "FileHash-SHA1": 159
          },
          "indicator_count": 8577,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65709120ed2b0db3696f67ac",
          "name": "http://www.protys.fr - Frightening relations really as this is a hybrid clean scan",
          "description": "",
          "modified": "2023-12-06T15:20:00.123000",
          "created": "2023-12-06T15:20:00.123000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 4,
            "FileHash-SHA256": 1579,
            "hostname": 625,
            "domain": 298,
            "URL": 1124,
            "email": 5,
            "FileHash-MD5": 54,
            "FileHash-SHA1": 51
          },
          "indicator_count": 3740,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6430dfed2b3b3f93d5a7cc19",
          "name": ":v3 - and the rest.... - www.tiuli.com/image/a057f08d1d773ab75e116ba4fffc595f.jpg?width=1080&#039;",
          "description": "",
          "modified": "2023-05-08T02:00:47.680000",
          "created": "2023-04-08T03:30:53.195000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "chromeua",
            "optout",
            "runtime data",
            "ansi",
            "pcap processing",
            "drmedgeua",
            "pcap",
            "pcap frame",
            "optin",
            "edgeua",
            "date",
            "suspicious",
            "hybrid",
            "close",
            "click",
            "hosts",
            "april",
            "general",
            "strings",
            "qakbot",
            "united",
            "https://www.tiuli.com/tracks/21/%D7%9E%D7%92-%D7%A8%D7%A1%D7%94-"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/9a478e33d2a8fa58780b09519e3f9bbbc9a32595e67b7fead10a9ad4ec17a614/6430cb9896a0a8d5f1092b9d",
            "https://hybrid-analysis.com/sample/e7d74be84c0b7bd09a96d5932c79d9579a9b2426f8ab43896a77a4b8b11d289a/6430d038f2ba281e660c5ef6",
            "http://cdn.lineate-33x.net/static/vpaid/vpaid.98dc0711.js?viewable_impression_url=https://lbs-event.gcp.lineate-33x.net/view?event=AAAAAB7wpEhwdgACAq1WS2xcVxmee8cej0dJIVkgVmjkBWrRnPF5P9pFcCPURiZpEocGsbHO0771vLgzdppUlSpL3VggFbOBLFAViU1WyCuwWHkFkUAoy7AiG5C7qbxC3oT_zkxQG7Hkyrpzzq_v_o_v_85_3Prt5dajy60bRDIplMAacyUNI0KoTSq55jKZEFnaZEQKxjVBIeGAeMQOmYAVwoxEil1yIsZNxqwvh-Px5dtFf7T5__X57X_99Xc_a7T__Y9__v1vq9-7UAXYK-I963rx9kUiTJdS0mW0S_BPyuvDB0WvZ1dFF7dfv1sMwvDeuH3jTpvgLn6rDQbJ32p_KPkb7bXRqBfvRrdeTFYFU10m26-vv3vn-g877",
            "https://www.tiuli.com/tracks/21/%D7%9E%D7%92-%D7%A8%D7%A1%D7%94-%D7%91%D7%A7%D7%A2%D7%AA-%D7%91%D7%99%D7%AA-%D7%A6%D7%99%D7%93%D7%94"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4962,
            "hostname": 1795,
            "FileHash-SHA256": 781,
            "domain": 712,
            "email": 4,
            "FileHash-MD5": 164,
            "FileHash-SHA1": 159
          },
          "indicator_count": 8577,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 94,
          "modified_text": "1119 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62efae65aff064cd7700bd70",
          "name": "http://www.protys.fr - Frightening relations really as this is a hybrid clean scan",
          "description": "",
          "modified": "2022-09-06T00:02:32.372000",
          "created": "2022-08-07T12:21:57.669000",
          "tags": [
            "apt",
            "data",
            "decrypted ssl",
            "windows nt",
            "okdate",
            "gmtetag",
            "iframe",
            "null",
            "cookie",
            "next",
            "twitter",
            "push",
            "code",
            "logic",
            "format",
            "apache",
            "jquery",
            "loader",
            "target",
            "canvas",
            "footer",
            "mark",
            "ruby",
            "facebook",
            "alexa",
            "screen",
            "infinity",
            "prop",
            "freeze",
            "dummy",
            "august",
            "local",
            "mozilla",
            "CVE-2017-11882",
            "CVE-2020-11022",
            "CVE-2020-11023",
            "CVE-2021-22941"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/c8c06a88f18d72420ac017c4b67d1e55170138a9d0f6d6046e7efc7b72ca8de0/62ef762fa396e628fa6ec076",
            "CVE-2021-22941",
            "CVE-2020-11023",
            "CVE-2020-11022",
            "CVE-2017-11882"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 625,
            "URL": 1124,
            "domain": 298,
            "FileHash-SHA256": 1579,
            "CVE": 4,
            "email": 5,
            "FileHash-MD5": 54,
            "FileHash-SHA1": 51
          },
          "indicator_count": 3740,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 394,
          "modified_text": "1363 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62e4b20de57e2dd981be7d6c",
          "name": "bootstrap.libp2p.io and frirnds",
          "description": "",
          "modified": "2022-08-29T00:01:52.177000",
          "created": "2022-07-30T04:22:37.460000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "runtime data",
            "ansi",
            "data",
            "decrypted ssl",
            "windows nt",
            "threat level",
            "date",
            "sha256",
            "size",
            "sha1",
            "light",
            "accept",
            "malicious",
            "tmos",
            "5555",
            "format",
            "hybrid",
            "suspicious",
            "close",
            "click",
            "hosts",
            "general",
            "local",
            "path",
            "mozilla",
            "strings",
            "bootstrap.libp2p.io"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/666ec602c8ca673678f8784fb81248ccbcd4c40f9028768c9bc7426f48435c5c/62e49db77776f20b8c127df6"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 188,
            "URL": 403,
            "domain": 102,
            "FileHash-SHA256": 294,
            "FileHash-MD5": 59,
            "FileHash-SHA1": 50
          },
          "indicator_count": 1096,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 392,
          "modified_text": "1371 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "cobaltstrike4.tk | https://cobaltstrike4.tk:8443/include/template/isx.php",
        "207 Iowa.gov domains and hosts acting as cyber security [cyberreason]",
        "www.fcc.gov? DGA Domains : Certificate Subject\tUS 443 Certificate Subject\tDistrict of Columbia 443 Certificate Subject\tWashington 443 Certificate Subject\tFederal Communications Commission 443 Certificate Subject\tGovernment Entity 443 Certificate Subject\t1934-06-19 443 Certificate Subject\taffordableconnectivity.gov 443 Certificate Issuer\tEntrust, Inc. 443 Certificate Issuer\tSee www.entrust.net/legal-terms 443 Certificate Issuer",
        "acam-mdn.apple.com",
        "djcodychase.com",
        "https://www.tiuli.com/tracks/21/%D7%9E%D7%92-%D7%A8%D7%A1%D7%94-%D7%91%D7%A7%D7%A2%D7%AA-%D7%91%D7%99%D7%AA-%D7%A6%D7%99%D7%93%D7%94",
        "https://hybrid-analysis.com/sample/e7d74be84c0b7bd09a96d5932c79d9579a9b2426f8ab43896a77a4b8b11d289a/6430d038f2ba281e660c5ef6",
        "https://www.google.com/?authuser=0",
        "AS15133 MCI Communications Services Inc d b a Verizon Business, Loudon County, Va",
        "http://dreamsofspanking.com/scene/item/rosie-backlash-caning?utm_campaign=apr15",
        "https://thebrotherssabey.wordpress.com/",
        "Wiper to Ransomware: The Evolution of Agrius - Sourced: ArcSight Threat Intelligence",
        "nr-data.net",
        "http://init.ess.apple.com/WebObjects/VCInit.woa/wa/getBag?ix=4",
        "https://www.clear.com.br/site/DirectTalk/Filter?botopenned=3Dtrue [???]",
        "CVE-2020-11023",
        "https://hybrid-analysis.com/sample/9a478e33d2a8fa58780b09519e3f9bbbc9a32595e67b7fead10a9ad4ec17a614/6430cb9896a0a8d5f1092b9d",
        "https://search.app.goo.gl/?ofl",
        "FileHash-MD5\ted5c771224fbd6f9b2c0cf1e8cce09b5",
        "beacons.bcp.gvt.com",
        "https://www.trendmicro.com/vinfo/gb/security/news/cybercrime-and-digital-threats/mumblehard-botnet-that-targeted-linux-systems-has-been-shut-down Source Trend",
        "https://hybrid-analysis.com/sample/666ec602c8ca673678f8784fb81248ccbcd4c40f9028768c9bc7426f48435c5c/62e49db77776f20b8c127df6",
        "appanoosecounty.iowa.gov, bigben.iowa.gov [Ben Smith?]",
        "https://www.hybrid-analysis.com/sample/bc437a855075805df699bd915cd27814a799969bb38db45f09f5f16a54ccc5b6/655e548bc2555fc8280ba976",
        "lacity.gov, auditortest.iowa.gov, broadband.iowa.gov, admin.auditor.iowa.gov,",
        "Worm:Win32/Benjamin",
        "api.telegram.org",
        "http://cdn.lineate-33x.net/static/vpaid/vpaid.98dc0711.js?viewable_impression_url=https://lbs-event.gcp.lineate-33x.net/view?event=AAAAAB7wpEhwdgACAq1WS2xcVxmee8cej0dJIVkgVmjkBWrRnPF5P9pFcCPURiZpEocGsbHO0771vLgzdppUlSpL3VggFbOBLFAViU1WyCuwWHkFkUAoy7AiG5C7qbxC3oT_zkxQG7Hkyrpzzq_v_o_v_85_3Prt5dajy60bRDIplMAacyUNI0KoTSq55jKZEFnaZEQKxjVBIeGAeMQOmYAVwoxEil1yIsZNxqwvh-Px5dtFf7T5__X57X_99Xc_a7T__Y9__v1vq9-7UAXYK-I963rx9kUiTJdS0mW0S_BPyuvDB0WvZ1dFF7dfv1sMwvDeuH3jTpvgLn6rDQbJ32p_KPkb7bXRqBfvRrdeTFYFU10m26-vv3vn-g877",
        "CVE-2017-11882",
        "FileHash-SHA1\tf336b50f5cca2ddc0341e2c4001b419a830d27a5",
        "DGA Domain [affordableconnectivity.gov & GetInternet.gov]  Home ACP Universal Service Administrative Company",
        "http://alohatube.xyz/search/tsara-brashears",
        "(c) 2014 Entrust, Inc. - for authorized use only 443 Certificate Issuer\tEntrust Certification Authority - L1M",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "https://hybrid-analysis.com/sample/c8c06a88f18d72420ac017c4b67d1e55170138a9d0f6d6046e7efc7b72ca8de0/62ef762fa396e628fa6ec076",
        "blackhat.store",
        "http://ti.hicloudcam.com",
        "FileHash-SHA256\t00000254e6344d34a1e4ef157cb01d8b7efa65c22c996f9dfe85e7482c6c86ab",
        "https://lacity.gov/san/index.htm, https://personnel.lacity.gov, https://lacity.gov/SAN,",
        "https:/www.usaopps.com/government_contractors/contractor-5388777-SIERRA-PIPELINE-INC-.htm",
        "CVE-2021-22941",
        "https://otx.alienvault.com/indicator/file/c98108ca8f4e0dd8a3f63d4ac490e115",
        "CVE-2020-11022",
        "iowa.gov, accidentreports.iowa.gov, beready.iowa.gov, affordableconnectivity.gov",
        "Domains Contacted: smtp.gmail.com www.google.com",
        "cpcontacts.webcamara.online",
        "applemusic-spotlight.myunidays.com"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Tulach",
            "Cobalt strike",
            "Win.trojan.agent-357800",
            "Win.dropper.xtremerat-7708589-0",
            "Hacktool",
            "Worm:win32/enosch!atmn",
            "Silk",
            "Formbook",
            "Win32:agent-asti\\ [trj]",
            "Worm:win32/benjamin",
            "Sabey",
            "Nullsoft_nsis",
            "Ransomware",
            "Backdoor:linux/mumblehard",
            "Emotet",
            "#lowfi:siga:trojanspy:msil/keylogger"
          ],
          "industries": [
            "Economy",
            "Government",
            "Business",
            "Legal"
          ],
          "unique_indicators": 62154
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/zhiqihuo.com",
    "whois": "http://whois.domaintools.com/zhiqihuo.com",
    "domain": "zhiqihuo.com",
    "hostname": "www.zhiqihuo.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 12,
  "pulses": [
    {
      "id": "65a4885e735b9e8ba94805bc",
      "name": "Apple | Worm:Win32/Benjamin | thebrotherssabey.com",
      "description": "",
      "modified": "2024-09-05T06:51:42.608000",
      "created": "2024-01-15T01:20:30.730000",
      "tags": [
        "execution",
        "whois record",
        "contacted",
        "ssl certificate",
        "whois whois",
        "contacted urls",
        "copy",
        "historical ssl",
        "referrer",
        "urls url",
        "icmp",
        "malicious",
        "installer",
        "problems",
        "collections",
        "report",
        "phishing",
        "service tool",
        "greatness",
        "threat network",
        "emotet",
        "magniber",
        "startpage",
        "attack",
        "banker",
        "keylogger",
        "namecheap inc",
        "com laude",
        "ltd dba",
        "cloudflare",
        "porkbun llc",
        "ii llc",
        "csc corporate",
        "domains",
        "computer",
        "company limited",
        "first",
        "cloudflarenet",
        "google",
        "amazon02",
        "akamaias",
        "telecom italia",
        "utc submissions",
        "microsoftcorpas",
        "indonesia",
        "beijing gu",
        "appleaustin",
        "sucurisec",
        "amazonaes",
        "limited",
        "tsara brashears",
        "pornhub",
        "thebrotherssabey",
        "then brothers sabey",
        "brian sabey",
        "apple",
        "icloud",
        "apple engineering",
        "soc",
        "hacker",
        "teams",
        "malvertizing",
        "cyberthreat",
        "cyber crime",
        "data",
        "v3 serial",
        "number",
        "cgb stgreater",
        "ecc domain",
        "server ca",
        "subject public",
        "key info",
        "key algorithm",
        "ec oid",
        "remote",
        "remote attacker",
        "benjamin",
        "worm",
        "trojan",
        "win32",
        "trojanspy",
        "ransomware",
        "command and control",
        "cnc",
        "c2",
        "stealer",
        "password",
        "apple unlocker",
        "pornographers",
        "cyber stalking",
        "revenge rat",
        "masquerading",
        "scanning host",
        "phishing",
        "dns",
        "network",
        "cobalt strike",
        "mitre attack",
        "metro hacker",
        "t-mobile hacker",
        "stalker",
        "social engineering",
        "et",
        "torrent trecker",
        "view",
        "duckdns",
        "blackhat",
        "data center",
        "tracking",
        "illegal",
        "malware scripting",
        "malware spreader",
        "network rat",
        "multiple botnetworks"
      ],
      "references": [
        "https://thebrotherssabey.wordpress.com/",
        "acam-mdn.apple.com",
        "beacons.bcp.gvt.com",
        "cpcontacts.webcamara.online",
        "http://dreamsofspanking.com/scene/item/rosie-backlash-caning?utm_campaign=apr15",
        "http://ti.hicloudcam.com",
        "http://alohatube.xyz/search/tsara-brashears",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "https://search.app.goo.gl/?ofl",
        "Worm:Win32/Benjamin",
        "FileHash-SHA256\t00000254e6344d34a1e4ef157cb01d8b7efa65c22c996f9dfe85e7482c6c86ab",
        "FileHash-MD5\ted5c771224fbd6f9b2c0cf1e8cce09b5",
        "FileHash-SHA1\tf336b50f5cca2ddc0341e2c4001b419a830d27a5",
        "applemusic-spotlight.myunidays.com",
        "nr-data.net",
        "http://init.ess.apple.com/WebObjects/VCInit.woa/wa/getBag?ix=4",
        "blackhat.store",
        "api.telegram.org",
        "cobaltstrike4.tk | https://cobaltstrike4.tk:8443/include/template/isx.php"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Worm:Win32/Benjamin",
          "display_name": "Worm:Win32/Benjamin",
          "target": "/malware/Worm:Win32/Benjamin"
        },
        {
          "id": "#Lowfi:SIGA:TrojanSpy:MSIL/Keylogger",
          "display_name": "#Lowfi:SIGA:TrojanSpy:MSIL/Keylogger",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "Silk",
          "display_name": "Silk",
          "target": null
        },
        {
          "id": "Sabey",
          "display_name": "Sabey",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65a429795adf468b427a3c8b",
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 2469,
        "URL": 6038,
        "FileHash-MD5": 169,
        "FileHash-SHA1": 157,
        "FileHash-SHA256": 3922,
        "CIDR": 2,
        "hostname": 2787,
        "email": 2,
        "CVE": 1
      },
      "indicator_count": 15547,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 230,
      "modified_text": "633 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65a8720daa2d0263a2b1de88",
      "name": "Linux/Mumblehard introduction via  phone call  Social Engineering",
      "description": "Already deeply compromised individuals more at risk of elaborate phone call interception/redirect/transfer from legitimate services. Many different schemes are used to access and nullify victims identity, involves ssn#, bank account information, email exchange text messaging, PDF exchange, Spam sent to all known accounts, password reset, request for ID upload to verify (steal) identity, extensive holds while trying to 'help' you, unannounced credit check ID theft. Ransomware, Linux attack, Botnetwork behavior.  Active threat. Linux/Mumblehard backdoor/botnet",
      "modified": "2024-02-17T00:01:16.653000",
      "created": "2024-01-18T00:34:21.136000",
      "tags": [
        "ssl certificate",
        "april",
        "resolutions",
        "threat roundup",
        "whois record",
        "historical ssl",
        "vt graph",
        "attack",
        "formbook",
        "subdomains",
        "august",
        "cobalt strike",
        "mumblehard",
        "iframe",
        "djcodychase.com",
        "first",
        "utc submissions",
        "submitters",
        "webico company",
        "limited",
        "summary iocs",
        "graph community",
        "urls",
        "gandi sas",
        "amazonaes",
        "cloudflarenet",
        "computer",
        "company limited",
        "cloud host",
        "pte ltd",
        "singlehopllc",
        "squarespace",
        "amazon02",
        "team internet",
        "google",
        "internapblk4",
        "domains",
        "registrar",
        "dynadot llc",
        "ip detections",
        "country",
        "detections type",
        "name",
        "win32 exe",
        "file size",
        "detections file",
        "kb file",
        "execution",
        "contacted",
        "apple ios",
        "tsara brashears",
        "virus network",
        "critical risk",
        "cyberstalking",
        "elf collection",
        "matches rule",
        "relacionada",
        "hacktool",
        "emotet",
        "critical",
        "copy",
        "installer",
        "banker",
        "keylogger",
        "it's back",
        "name verdict",
        "falcon sandbox",
        "json data",
        "localappdata",
        "temp",
        "getprocaddress",
        "windir",
        "ascii text",
        "file",
        "indicator",
        "mitre att",
        "ck id",
        "win64",
        "path",
        "date",
        "factory",
        "hybrid",
        "cookie",
        "benjamin"
      ],
      "references": [
        "djcodychase.com",
        "https://www.trendmicro.com/vinfo/gb/security/news/cybercrime-and-digital-threats/mumblehard-botnet-that-targeted-linux-systems-has-been-shut-down Source Trend"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Backdoor:Linux/Mumblehard",
          "display_name": "Backdoor:Linux/Mumblehard",
          "target": "/malware/Backdoor:Linux/Mumblehard"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "FormBook",
          "display_name": "FormBook",
          "target": null
        },
        {
          "id": "Win.Dropper.XtremeRAT-7708589-0",
          "display_name": "Win.Dropper.XtremeRAT-7708589-0",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "Worm:Win32/Benjamin",
          "display_name": "Worm:Win32/Benjamin",
          "target": "/malware/Worm:Win32/Benjamin"
        }
      ],
      "attack_ids": [
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1122",
          "name": "Component Object Model Hijacking",
          "display_name": "T1122 - Component Object Model Hijacking"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 114,
        "FileHash-SHA1": 106,
        "FileHash-SHA256": 3407,
        "URL": 6246,
        "domain": 2463,
        "hostname": 1693,
        "CVE": 2
      },
      "indicator_count": 14031,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "834 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65aab9d7a0b4116f622b0aa0",
      "name": "Linux/Mumblehard introduction via phone call Social Engineering",
      "description": "",
      "modified": "2024-02-17T00:01:16.653000",
      "created": "2024-01-19T18:05:11.592000",
      "tags": [
        "ssl certificate",
        "april",
        "resolutions",
        "threat roundup",
        "whois record",
        "historical ssl",
        "vt graph",
        "attack",
        "formbook",
        "subdomains",
        "august",
        "cobalt strike",
        "mumblehard",
        "iframe",
        "djcodychase.com",
        "first",
        "utc submissions",
        "submitters",
        "webico company",
        "limited",
        "summary iocs",
        "graph community",
        "urls",
        "gandi sas",
        "amazonaes",
        "cloudflarenet",
        "computer",
        "company limited",
        "cloud host",
        "pte ltd",
        "singlehopllc",
        "squarespace",
        "amazon02",
        "team internet",
        "google",
        "internapblk4",
        "domains",
        "registrar",
        "dynadot llc",
        "ip detections",
        "country",
        "detections type",
        "name",
        "win32 exe",
        "file size",
        "detections file",
        "kb file",
        "execution",
        "contacted",
        "apple ios",
        "tsara brashears",
        "virus network",
        "critical risk",
        "cyberstalking",
        "elf collection",
        "matches rule",
        "relacionada",
        "hacktool",
        "emotet",
        "critical",
        "copy",
        "installer",
        "banker",
        "keylogger",
        "it's back",
        "name verdict",
        "falcon sandbox",
        "json data",
        "localappdata",
        "temp",
        "getprocaddress",
        "windir",
        "ascii text",
        "file",
        "indicator",
        "mitre att",
        "ck id",
        "win64",
        "path",
        "date",
        "factory",
        "hybrid",
        "cookie",
        "benjamin"
      ],
      "references": [
        "djcodychase.com",
        "https://www.trendmicro.com/vinfo/gb/security/news/cybercrime-and-digital-threats/mumblehard-botnet-that-targeted-linux-systems-has-been-shut-down Source Trend"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Backdoor:Linux/Mumblehard",
          "display_name": "Backdoor:Linux/Mumblehard",
          "target": "/malware/Backdoor:Linux/Mumblehard"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "FormBook",
          "display_name": "FormBook",
          "target": null
        },
        {
          "id": "Win.Dropper.XtremeRAT-7708589-0",
          "display_name": "Win.Dropper.XtremeRAT-7708589-0",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "Worm:Win32/Benjamin",
          "display_name": "Worm:Win32/Benjamin",
          "target": "/malware/Worm:Win32/Benjamin"
        }
      ],
      "attack_ids": [
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1122",
          "name": "Component Object Model Hijacking",
          "display_name": "T1122 - Component Object Model Hijacking"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65a8720daa2d0263a2b1de88",
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 114,
        "FileHash-SHA1": 106,
        "FileHash-SHA256": 3407,
        "URL": 6246,
        "domain": 2463,
        "hostname": 1693,
        "CVE": 2
      },
      "indicator_count": 14031,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 230,
      "modified_text": "834 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65a429795adf468b427a3c8b",
      "name": "Apple | Worm:Win32/Benjamin | thebrotherssabey.com",
      "description": "Retaliation. Brian Sabey representing as an attorney and many other occupations contacted and socially engineered target. Uncertain of true name. Contacted 'alleged' SA assault victim. Made claims of representing a Jeffrey Scott Reimer DPT' alleged 'S' Assaulter.  Substantiated claims made with the twist of 'victim consented'. Mark Brian Sbabeys claims dismissed. Continues to hack, harass, intimidate target in every possible way. Hacking, monitoring, service, modification, phone contact, malicious texting, in person monitoring via colleagues, hacks into medical and medical billing centers, sells/leaks targets data on dark web.    Removed targets name from most pulses via  remote device access. Self whitelist. Everything he does is illegal.\n\nTarget not important enough to law enforcement.",
      "modified": "2024-02-13T17:04:19.437000",
      "created": "2024-01-14T18:35:37.757000",
      "tags": [
        "execution",
        "whois record",
        "contacted",
        "ssl certificate",
        "whois whois",
        "contacted urls",
        "copy",
        "historical ssl",
        "referrer",
        "urls url",
        "icmp",
        "malicious",
        "installer",
        "problems",
        "collections",
        "report",
        "phishing",
        "service tool",
        "greatness",
        "threat network",
        "emotet",
        "magniber",
        "startpage",
        "attack",
        "banker",
        "keylogger",
        "namecheap inc",
        "com laude",
        "ltd dba",
        "cloudflare",
        "porkbun llc",
        "ii llc",
        "csc corporate",
        "domains",
        "computer",
        "company limited",
        "first",
        "cloudflarenet",
        "google",
        "amazon02",
        "akamaias",
        "telecom italia",
        "utc submissions",
        "microsoftcorpas",
        "indonesia",
        "beijing gu",
        "appleaustin",
        "sucurisec",
        "amazonaes",
        "limited",
        "tsara brashears",
        "pornhub",
        "thebrotherssabey",
        "then brothers sabey",
        "brian sabey",
        "apple",
        "icloud",
        "apple engineering",
        "soc",
        "hacker",
        "teams",
        "malvertizing",
        "cyberthreat",
        "cyber crime",
        "data",
        "v3 serial",
        "number",
        "cgb stgreater",
        "ecc domain",
        "server ca",
        "subject public",
        "key info",
        "key algorithm",
        "ec oid",
        "remote",
        "remote attacker",
        "benjamin",
        "worm",
        "trojan",
        "win32",
        "trojanspy",
        "ransomware",
        "command and control",
        "cnc",
        "c2",
        "stealer",
        "password",
        "apple unlocker",
        "pornographers",
        "cyber stalking",
        "revenge rat",
        "masquerading",
        "scanning host",
        "phishing",
        "dns",
        "network",
        "cobalt strike",
        "mitre attack",
        "metro hacker",
        "t-mobile hacker",
        "stalker",
        "social engineering",
        "et",
        "torrent trecker",
        "view",
        "duckdns",
        "blackhat",
        "data center",
        "tracking",
        "illegal",
        "malware scripting",
        "malware spreader",
        "network rat",
        "multiple botnetworks"
      ],
      "references": [
        "https://thebrotherssabey.wordpress.com/",
        "acam-mdn.apple.com",
        "beacons.bcp.gvt.com",
        "cpcontacts.webcamara.online",
        "http://dreamsofspanking.com/scene/item/rosie-backlash-caning?utm_campaign=apr15",
        "http://ti.hicloudcam.com",
        "http://alohatube.xyz/search/tsara-brashears",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "https://search.app.goo.gl/?ofl",
        "Worm:Win32/Benjamin",
        "FileHash-SHA256\t00000254e6344d34a1e4ef157cb01d8b7efa65c22c996f9dfe85e7482c6c86ab",
        "FileHash-MD5\ted5c771224fbd6f9b2c0cf1e8cce09b5",
        "FileHash-SHA1\tf336b50f5cca2ddc0341e2c4001b419a830d27a5",
        "applemusic-spotlight.myunidays.com",
        "nr-data.net",
        "http://init.ess.apple.com/WebObjects/VCInit.woa/wa/getBag?ix=4",
        "blackhat.store",
        "api.telegram.org",
        "cobaltstrike4.tk | https://cobaltstrike4.tk:8443/include/template/isx.php"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Worm:Win32/Benjamin",
          "display_name": "Worm:Win32/Benjamin",
          "target": "/malware/Worm:Win32/Benjamin"
        },
        {
          "id": "#Lowfi:SIGA:TrojanSpy:MSIL/Keylogger",
          "display_name": "#Lowfi:SIGA:TrojanSpy:MSIL/Keylogger",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "Silk",
          "display_name": "Silk",
          "target": null
        },
        {
          "id": "Sabey",
          "display_name": "Sabey",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 2462,
        "URL": 5950,
        "FileHash-MD5": 168,
        "FileHash-SHA1": 156,
        "FileHash-SHA256": 3901,
        "CIDR": 2,
        "hostname": 2766,
        "email": 2,
        "CVE": 1
      },
      "indicator_count": 15408,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "838 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65a2f9169d6996c1c928ac0b",
      "name": "Remote attack: Win32/Enosch.A gtalk connectivity check | High Priority",
      "description": "W32/Enosch.A!tr is classified as a Trojan. Trojan has the capabilities to remote access connection handling, perform Denial of Service (DoS) attacks. Worms automatically spread to other PCs. This threat can perform a number of actions of a malicious hacker's choice. This hacker is choosing to delete files, accounts, pulses, by graphs while acting as user.  An authenticated use in browser bar https://www.google.com/?authuser=0.\n\nAttempts to modify,delete graphs, pulses, accounts, passwords. Acting as user.",
      "modified": "2024-02-12T20:02:49.516000",
      "created": "2024-01-13T20:56:54.333000",
      "tags": [
        "default",
        "show",
        "regsetvalueexa",
        "search",
        "regdword",
        "medium",
        "settingswpad",
        "delete",
        "ids detections",
        "yara detections",
        "worm",
        "malware",
        "copy",
        "write",
        "win32",
        "first",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "summary iocs",
        "graph community",
        "productidis",
        "urls",
        "mb iesettings",
        "related file",
        "cybersecurity",
        "agency",
        "csc corporate",
        "domains",
        "tucows domains",
        "nameweb bvba",
        "tucows",
        "google",
        "amazon02",
        "twitter",
        "ovh sas",
        "facebook",
        "incapsula",
        "optimizer",
        "activator",
        "kb program",
        "mb super",
        "kb acrotray",
        "1tzv",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "hostnames",
        "urls https",
        "checks_debugger",
        "network_icmp",
        "network_smtp",
        "persistence_autorun",
        "modifies_proxy_wpad",
        "antivm_queries_computername",
        "dumped_buffer",
        "network_http",
        "antivm_network_adapters",
        "smtp_gmail",
        "attacking",
        "browser",
        "object",
        "deleted",
        "deleting",
        "deleted virustotal graphs",
        "corruption",
        "legal",
        "gvt",
        "adams co",
        "colorado",
        "law",
        "illegal practices",
        "hacking",
        "enter rexxfield",
        "roberts",
        "smith",
        "script urls",
        "as20940",
        "united",
        "a domains",
        "certificate",
        "showing",
        "entries",
        "entrust",
        "scan endpoints",
        "district",
        "as16625 akamai",
        "aaaa",
        "passive dns",
        "united kingdom",
        "whitelisted",
        "modification",
        "silence",
        "state",
        "hostname",
        "samples",
        "cover up",
        "silencing",
        "Iowa.gov",
        "dga",
        "fcc",
        "unsigned",
        "remote",
        "wiper",
        "nosy pega",
        "trojan",
        "unknown",
        "access denied",
        "servers",
        "creation date",
        "date",
        "next",
        "apple",
        "ssl certificate",
        "threat roundup",
        "march",
        "october",
        "july",
        "april",
        "whois record",
        "june",
        "roundup",
        "september",
        "august",
        "plugx",
        "goldfinder",
        "sibot",
        "hacktool",
        "february",
        "regsz",
        "english",
        "nsisinetc",
        "mozilla",
        "adobe air",
        "java",
        "http",
        "post http",
        "updater",
        "meta",
        "suspicious",
        "persistence",
        "execution",
        "referrer",
        "communicating",
        "skynet",
        "malicious",
        "gen.o",
        "dynamicloader",
        "cape",
        "enosch malware",
        "enosch",
        "music",
        "contacted",
        "pe resource",
        "resolutions",
        "siblings",
        "urls http"
      ],
      "references": [
        "https://otx.alienvault.com/indicator/file/c98108ca8f4e0dd8a3f63d4ac490e115",
        "https://www.google.com/?authuser=0",
        "Wiper to Ransomware: The Evolution of Agrius - Sourced: ArcSight Threat Intelligence",
        "AS15133 MCI Communications Services Inc d b a Verizon Business, Loudon County, Va",
        "207 Iowa.gov domains and hosts acting as cyber security [cyberreason]",
        "iowa.gov, accidentreports.iowa.gov, beready.iowa.gov, affordableconnectivity.gov",
        "appanoosecounty.iowa.gov, bigben.iowa.gov [Ben Smith?]",
        "lacity.gov, auditortest.iowa.gov, broadband.iowa.gov, admin.auditor.iowa.gov,",
        "https://lacity.gov/san/index.htm, https://personnel.lacity.gov, https://lacity.gov/SAN,",
        "Domains Contacted: smtp.gmail.com www.google.com",
        "DGA Domain [affordableconnectivity.gov & GetInternet.gov]  Home ACP Universal Service Administrative Company",
        "www.fcc.gov? DGA Domains : Certificate Subject\tUS 443 Certificate Subject\tDistrict of Columbia 443 Certificate Subject\tWashington 443 Certificate Subject\tFederal Communications Commission 443 Certificate Subject\tGovernment Entity 443 Certificate Subject\t1934-06-19 443 Certificate Subject\taffordableconnectivity.gov 443 Certificate Issuer\tEntrust, Inc. 443 Certificate Issuer\tSee www.entrust.net/legal-terms 443 Certificate Issuer",
        "(c) 2014 Entrust, Inc. - for authorized use only 443 Certificate Issuer\tEntrust Certification Authority - L1M",
        "https://www.clear.com.br/site/DirectTalk/Filter?botopenned=3Dtrue [???]"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Belgium",
        "Netherlands",
        "Spain",
        "Australia",
        "Korea, Republic of",
        "Hong Kong"
      ],
      "malware_families": [
        {
          "id": "Nullsoft_NSIS",
          "display_name": "Nullsoft_NSIS",
          "target": null
        },
        {
          "id": "Win32:Agent-ASTI\\ [Trj]",
          "display_name": "Win32:Agent-ASTI\\ [Trj]",
          "target": null
        },
        {
          "id": "Worm:Win32/Enosch!atmn",
          "display_name": "Worm:Win32/Enosch!atmn",
          "target": "/malware/Worm:Win32/Enosch!atmn"
        },
        {
          "id": "Win.Trojan.Agent-357800",
          "display_name": "Win.Trojan.Agent-357800",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 30,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2701,
        "FileHash-SHA1": 1512,
        "FileHash-SHA256": 5351,
        "SSLCertFingerprint": 1,
        "URL": 1774,
        "email": 7,
        "hostname": 1170,
        "domain": 1209
      },
      "indicator_count": 13725,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 225,
      "modified_text": "838 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65a2f9200337f0d1fa195ada",
      "name": "Remote attack: Win32/Enosch.A gtalk connectivity check | High Priority",
      "description": "W32/Enosch.A!tr is classified as a Trojan. Trojan has the capabilities to remote access connection handling, perform Denial of Service (DoS) attacks. Worms automatically spread to other PCs. This threat can perform a number of actions of a malicious hacker's choice. This hacker is choosing to delete files, accounts, pulses, by graphs while acting as user.  An authenticated use in browser bar https://www.google.com/?authuser=0.\n\nAttempts to modify,delete graphs, pulses, accounts, passwords. Acting as user.",
      "modified": "2024-02-12T20:02:49.516000",
      "created": "2024-01-13T20:57:04.197000",
      "tags": [
        "default",
        "show",
        "regsetvalueexa",
        "search",
        "regdword",
        "medium",
        "settingswpad",
        "delete",
        "ids detections",
        "yara detections",
        "worm",
        "malware",
        "copy",
        "write",
        "win32",
        "first",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "summary iocs",
        "graph community",
        "productidis",
        "urls",
        "mb iesettings",
        "related file",
        "cybersecurity",
        "agency",
        "csc corporate",
        "domains",
        "tucows domains",
        "nameweb bvba",
        "tucows",
        "google",
        "amazon02",
        "twitter",
        "ovh sas",
        "facebook",
        "incapsula",
        "optimizer",
        "activator",
        "kb program",
        "mb super",
        "kb acrotray",
        "1tzv",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "hostnames",
        "urls https",
        "checks_debugger",
        "network_icmp",
        "network_smtp",
        "persistence_autorun",
        "modifies_proxy_wpad",
        "antivm_queries_computername",
        "dumped_buffer",
        "network_http",
        "antivm_network_adapters",
        "smtp_gmail",
        "attacking",
        "browser",
        "object",
        "deleted",
        "deleting",
        "deleted virustotal graphs",
        "corruption",
        "legal",
        "gvt",
        "adams co",
        "colorado",
        "law",
        "illegal practices",
        "hacking",
        "enter rexxfield",
        "roberts",
        "smith",
        "script urls",
        "as20940",
        "united",
        "a domains",
        "certificate",
        "showing",
        "entries",
        "entrust",
        "scan endpoints",
        "district",
        "as16625 akamai",
        "aaaa",
        "passive dns",
        "united kingdom",
        "whitelisted",
        "modification",
        "silence",
        "state",
        "hostname",
        "samples",
        "cover up",
        "silencing",
        "Iowa.gov",
        "dga",
        "fcc",
        "unsigned",
        "remote",
        "wiper",
        "nosy pega",
        "trojan",
        "unknown",
        "access denied",
        "servers",
        "creation date",
        "date",
        "next",
        "apple",
        "ssl certificate",
        "threat roundup",
        "march",
        "october",
        "july",
        "april",
        "whois record",
        "june",
        "roundup",
        "september",
        "august",
        "plugx",
        "goldfinder",
        "sibot",
        "hacktool",
        "february",
        "regsz",
        "english",
        "nsisinetc",
        "mozilla",
        "adobe air",
        "java",
        "http",
        "post http",
        "updater",
        "meta",
        "suspicious",
        "persistence",
        "execution",
        "referrer",
        "communicating",
        "skynet",
        "malicious",
        "gen.o",
        "dynamicloader",
        "cape",
        "enosch malware",
        "enosch",
        "music",
        "contacted",
        "pe resource",
        "resolutions",
        "siblings",
        "urls http"
      ],
      "references": [
        "https://otx.alienvault.com/indicator/file/c98108ca8f4e0dd8a3f63d4ac490e115",
        "https://www.google.com/?authuser=0",
        "Wiper to Ransomware: The Evolution of Agrius - Sourced: ArcSight Threat Intelligence",
        "AS15133 MCI Communications Services Inc d b a Verizon Business, Loudon County, Va",
        "207 Iowa.gov domains and hosts acting as cyber security [cyberreason]",
        "iowa.gov, accidentreports.iowa.gov, beready.iowa.gov, affordableconnectivity.gov",
        "appanoosecounty.iowa.gov, bigben.iowa.gov [Ben Smith?]",
        "lacity.gov, auditortest.iowa.gov, broadband.iowa.gov, admin.auditor.iowa.gov,",
        "https://lacity.gov/san/index.htm, https://personnel.lacity.gov, https://lacity.gov/SAN,",
        "Domains Contacted: smtp.gmail.com www.google.com",
        "DGA Domain [affordableconnectivity.gov & GetInternet.gov]  Home ACP Universal Service Administrative Company",
        "www.fcc.gov? DGA Domains : Certificate Subject\tUS 443 Certificate Subject\tDistrict of Columbia 443 Certificate Subject\tWashington 443 Certificate Subject\tFederal Communications Commission 443 Certificate Subject\tGovernment Entity 443 Certificate Subject\t1934-06-19 443 Certificate Subject\taffordableconnectivity.gov 443 Certificate Issuer\tEntrust, Inc. 443 Certificate Issuer\tSee www.entrust.net/legal-terms 443 Certificate Issuer",
        "(c) 2014 Entrust, Inc. - for authorized use only 443 Certificate Issuer\tEntrust Certification Authority - L1M",
        "https://www.clear.com.br/site/DirectTalk/Filter?botopenned=3Dtrue [???]"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Belgium",
        "Netherlands",
        "Spain",
        "Australia",
        "Korea, Republic of",
        "Hong Kong"
      ],
      "malware_families": [
        {
          "id": "Nullsoft_NSIS",
          "display_name": "Nullsoft_NSIS",
          "target": null
        },
        {
          "id": "Win32:Agent-ASTI\\ [Trj]",
          "display_name": "Win32:Agent-ASTI\\ [Trj]",
          "target": null
        },
        {
          "id": "Worm:Win32/Enosch!atmn",
          "display_name": "Worm:Win32/Enosch!atmn",
          "target": "/malware/Worm:Win32/Enosch!atmn"
        },
        {
          "id": "Win.Trojan.Agent-357800",
          "display_name": "Win.Trojan.Agent-357800",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 33,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2701,
        "FileHash-SHA1": 1512,
        "FileHash-SHA256": 5351,
        "SSLCertFingerprint": 1,
        "URL": 1774,
        "email": 7,
        "hostname": 1170,
        "domain": 1209
      },
      "indicator_count": 13725,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "838 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655e5c72277117d3b0e00fbd",
      "name": "Command and Scripting Interpreter",
      "description": "https:/www.usaopps.com/government_contractors/contractor-5388777-SIERRA-PIPELINE-INC-.htm",
      "modified": "2023-12-22T19:00:52.050000",
      "created": "2023-11-22T19:54:26.925000",
      "tags": [
        "whois record",
        "contacted",
        "execution",
        "ssl certificate",
        "historical ssl",
        "resolutions",
        "problems",
        "red team",
        "whois whois",
        "referrer",
        "startpage",
        "generic malware",
        "cobaltstrike",
        "malware generic",
        "tag count",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "blacklist https",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "malware",
        "malicious site",
        "malware site",
        "malicious url",
        "phishing site",
        "alexa",
        "phishing",
        "redline stealer",
        "bank",
        "team",
        "iframe",
        "downldr",
        "presenoker",
        "artemis",
        "live",
        "zbot",
        "united",
        "cyber threat",
        "covid19",
        "mail spammer",
        "malicious host",
        "anonymizer",
        "engineering",
        "purplewave",
        "malicious",
        "keybase",
        "union",
        "asyncrat",
        "cobalt strike",
        "dnspionage",
        "ransomware",
        "maltiverse",
        "malicious link",
        "detection list",
        "blacklist",
        "pattern match",
        "file",
        "ascii text",
        "windows nt",
        "appdata",
        "mitre att",
        "null",
        "date",
        "ck id",
        "show technique",
        "unknown",
        "accept",
        "hybrid",
        "local",
        "click",
        "strings",
        "class",
        "generator",
        "critical",
        "error",
        "fast",
        "blacklist http",
        "heur",
        "adware",
        "unsafe",
        "riskware",
        "agent",
        "swrort",
        "exploit",
        "crack",
        "opencandy",
        "tiggre",
        "cleaner",
        "conduit",
        "wacatac",
        "nircmd",
        "filetour",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "installcore",
        "webshell",
        "acint",
        "systweak",
        "behav",
        "genkryptik",
        "xtrat",
        "softcnapp",
        "fusioncore",
        "installpack",
        "xrat",
        "jquery",
        "content scraper",
        "malware hosting",
        "bid site",
        "https:/www.usaopps.com/government_contractors/contractor-5388777",
        "CVE-2017-11882",
        "CVE-2017-0147",
        "CVE-2017-8570",
        "CVE-2005-1790",
        "CVE-2009-3672",
        "CVE-2010-3962",
        "CVE-2012-3993",
        "CVE-2014-3153",
        "CVE-2014-6332",
        "CVE-2016-0189",
        "CVE-2017-0199",
        "CVE-2018-4893",
        "CVE-2020-0601",
        "CVE-2020-0674",
        "CVE-2021-27065",
        "CVE-2021-40444"
      ],
      "references": [
        "https://www.hybrid-analysis.com/sample/bc437a855075805df699bd915cd27814a799969bb38db45f09f5f16a54ccc5b6/655e548bc2555fc8280ba976",
        "https:/www.usaopps.com/government_contractors/contractor-5388777-SIERRA-PIPELINE-INC-.htm"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        }
      ],
      "industries": [
        "Business",
        "Economy",
        "Government",
        "Legal"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 28,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 608,
        "FileHash-SHA1": 312,
        "FileHash-SHA256": 1086,
        "URL": 2843,
        "domain": 341,
        "hostname": 1091,
        "CVE": 16
      },
      "indicator_count": 6297,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "891 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65709943cc506763d721edec",
      "name": ":v3 - and the rest.... - www.tiuli.com/image/a057f08d1d773ab75e116ba4fffc595f.jpg?width=1080&#039;",
      "description": "",
      "modified": "2023-12-06T15:54:43.175000",
      "created": "2023-12-06T15:54:43.175000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 781,
        "domain": 712,
        "URL": 4962,
        "hostname": 1795,
        "email": 4,
        "FileHash-MD5": 164,
        "FileHash-SHA1": 159
      },
      "indicator_count": 8577,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65709120ed2b0db3696f67ac",
      "name": "http://www.protys.fr - Frightening relations really as this is a hybrid clean scan",
      "description": "",
      "modified": "2023-12-06T15:20:00.123000",
      "created": "2023-12-06T15:20:00.123000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 4,
        "FileHash-SHA256": 1579,
        "hostname": 625,
        "domain": 298,
        "URL": 1124,
        "email": 5,
        "FileHash-MD5": 54,
        "FileHash-SHA1": 51
      },
      "indicator_count": 3740,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6430dfed2b3b3f93d5a7cc19",
      "name": ":v3 - and the rest.... - www.tiuli.com/image/a057f08d1d773ab75e116ba4fffc595f.jpg?width=1080&#039;",
      "description": "",
      "modified": "2023-05-08T02:00:47.680000",
      "created": "2023-04-08T03:30:53.195000",
      "tags": [
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "chromeua",
        "optout",
        "runtime data",
        "ansi",
        "pcap processing",
        "drmedgeua",
        "pcap",
        "pcap frame",
        "optin",
        "edgeua",
        "date",
        "suspicious",
        "hybrid",
        "close",
        "click",
        "hosts",
        "april",
        "general",
        "strings",
        "qakbot",
        "united",
        "https://www.tiuli.com/tracks/21/%D7%9E%D7%92-%D7%A8%D7%A1%D7%94-"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/9a478e33d2a8fa58780b09519e3f9bbbc9a32595e67b7fead10a9ad4ec17a614/6430cb9896a0a8d5f1092b9d",
        "https://hybrid-analysis.com/sample/e7d74be84c0b7bd09a96d5932c79d9579a9b2426f8ab43896a77a4b8b11d289a/6430d038f2ba281e660c5ef6",
        "http://cdn.lineate-33x.net/static/vpaid/vpaid.98dc0711.js?viewable_impression_url=https://lbs-event.gcp.lineate-33x.net/view?event=AAAAAB7wpEhwdgACAq1WS2xcVxmee8cej0dJIVkgVmjkBWrRnPF5P9pFcCPURiZpEocGsbHO0771vLgzdppUlSpL3VggFbOBLFAViU1WyCuwWHkFkUAoy7AiG5C7qbxC3oT_zkxQG7Hkyrpzzq_v_o_v_85_3Prt5dajy60bRDIplMAacyUNI0KoTSq55jKZEFnaZEQKxjVBIeGAeMQOmYAVwoxEil1yIsZNxqwvh-Px5dtFf7T5__X57X_99Xc_a7T__Y9__v1vq9-7UAXYK-I963rx9kUiTJdS0mW0S_BPyuvDB0WvZ1dFF7dfv1sMwvDeuH3jTpvgLn6rDQbJ32p_KPkb7bXRqBfvRrdeTFYFU10m26-vv3vn-g877",
        "https://www.tiuli.com/tracks/21/%D7%9E%D7%92-%D7%A8%D7%A1%D7%94-%D7%91%D7%A7%D7%A2%D7%AA-%D7%91%D7%99%D7%AA-%D7%A6%D7%99%D7%93%D7%94"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4962,
        "hostname": 1795,
        "FileHash-SHA256": 781,
        "domain": 712,
        "email": 4,
        "FileHash-MD5": 164,
        "FileHash-SHA1": 159
      },
      "indicator_count": 8577,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 94,
      "modified_text": "1119 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.zhiqihuo.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.zhiqihuo.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780254820.9703252
}