{
  "type": "Domain",
  "indicator": "jsperf.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/jsperf.com",
    "alexa": "http://www.alexa.com/siteinfo/jsperf.com",
    "indicator": "jsperf.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [
      {
        "source": "majestic",
        "message": "Whitelisted domain jsperf.com",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3155144963,
      "indicator": "jsperf.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 22,
      "pulses": [
        {
          "id": "69d46ee1379578309fae9a4a",
          "name": "VirusTotal report\n                    for l-Management-System-School-ERP-nulled-by-CodeAlright.Com.zip",
          "description": "A look at the results of a report generated by the University of California, Los Angeles (UCLA) and compiled by codecanyon, a university-instikit and an academy.",
          "modified": "2026-05-07T02:13:20.636000",
          "created": "2026-04-07T02:41:37.877000",
          "tags": [
            "file type",
            "unix",
            "mitre attack",
            "network info",
            "wed jun",
            "overview",
            "dropped info",
            "processes extra",
            "overview zenbox",
            "linux verdict",
            "persistence",
            "malicious",
            "next",
            "newstoday2",
            "ip address",
            "virustotal box",
            "apples sandbox",
            "sandbox sha256",
            "analysis date",
            "screnshots",
            "file",
            "operations",
            "process open",
            "python",
            "javascript",
            "html",
            "sample",
            "test",
            "urls",
            "united",
            "extra info",
            "uncomment",
            "performs dns",
            "layer protocol",
            "attack network",
            "info dropped",
            "info processes",
            "info",
            "may try",
            "ascii text",
            "png image",
            "https",
            "reads cpu",
            "tls version",
            "ascii",
            "usrliblog"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/01f57cc95906a44558c5c1f19ef3191fe6f2f1cc03e1d10d1da421b7c604903f_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529261&Signature=RJNKrp%2FaK0APCyfk557hpXXr%2BMWPGME1nJO1%2BQCUEm9xRuKB0DlxP%2BfDSiZsLcJsAhaI%2FWxbH%2F%2FdbHllDXKgjJl92HzsTFyTAT0eMx%2BzlFLXKn0VyBmCHKLgKoFS4fDODUKy6SKJxdUav7aDP1aVhAXMPp%2BT3yWjDdSos0HQalqAt%2FcsVg1w28zfPjvVVGv%2B%2FvJeCIgzhXeE2pX6Npumx67Yym8jiiqV75WoDu",
            "https://vtbehaviour.commondatastorage.googleapis.com/00913627185b352deaf0ec837f85a7f606b27112956875de5d610fba8151306c_VirusTotal%20Box%20of%20Apples.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529477&Signature=s8ZCWLcVqjdBgBGejTcqippuMvftwgsdUQHUAjBnm45yUvqDsHIMIA29%2BJcb%2BrruXxHPD5tQv1BwAzlV1o7EuhxX4qMqDcFWSLqoc%2FqAnEVxLg0zXohtwMkHxv0z%2Bp5AL0jLyAwNYz7bH56tnmUs3tHPYc48OeM4AanV030U%2FnmXlF8kJ6cjAemipfTNe1QRx3ecbONm9c3B51FK0BbzZEdRX0pTHIM4AK1M",
            "https://vtbehaviour.commondatastorage.googleapis.com/0347ed7ffd09f6728c494128b1d11792893d5cde9e4effdc2bcc8f9ebb12a0e1_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529533&Signature=diQ6r2CuvkDxYGybQtlzxVxtH8iGMt6XlgZBEpk7B5n%2FVtwOuZaPpuNyM%2Fr4VbSp2H67%2FddXTZ3XJG8LdUMwLVXsSDKIq%2BjyQHccTuCS0HXEDbllONqfU6gWICxxtdC%2F4wdaL8fVyCE%2FHHcnWm5PufAa002Tn02MbSx9cFdNZS4R86MEMARaMiXSCiGQuiLR2STQCGqU%2Byg16ky%2FYjPbLtB6WD5skgEs3AgDmDNlDLjtbb",
            "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_Zenbox%20macOS.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529640&Signature=G0ONarqL7o1MkYvMlqktPKmEpNw5A3hwHYnIBwD8r%2F0xQfBDCaCPoL6%2BMxjj5Ftsb47O6KGvZzp2CS1xFcRHfbhEnUGRJR9o2%2FjSPy6NAV226GNwtSGdDXxPJFfETfpFlDEj%2FOCd26qtcBDdT4lX2saiGfx0%2FunV94XcNq3cUTVm%2Fsf0BO74945PnFWtBu3Oq%2FBm9AlaLwnyEZ5TDLfhXyqiTv1Qsx%2FWmBk0PIieA9MtTm",
            "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529701&Signature=BDpq68evTIZGfF61fRMAYEM%2BQtXgDfwPgp7qnaSE1mJStRV1ikHnSjRDxrMwGqkg0kaXqLEpQ%2BLuSCdJ9wJJzfrkQuV1%2Bbcg0cctnCOLgWhiXjekyol4iul%2FPXEGu6%2F1a20JEEoUfg9Dq6%2FosKMN9fmk%2BtqQcFa6PODcE3qJcO23YhWwDpmSYZ7t8JNsALFm98c6r%2BfBLLjnCSpVql2zQJifkl%2BteR57LTZG7W2lbENV",
            "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_VirusTotal%20Box%20of%20Apples.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529758&Signature=zXDmSolL1BXRVntoMjKFPJaZtQ0tI1lf56M%2BqCFh1c0JirSCS7DGBgxMdHuaZG8hsB%2FV1nO0JEfDegHE1Ibm55QO9TriIg9yCH6dZSsofTmiHiBOUZtTMSH1Pg1z%2FnuElFFvVDHQ2Ryhog0fw%2BwfS0Fpe5ZOoTF8KK883iH45dmOAcVEphu7K5A%2FrzfFG93bFibxA7MRKbLLGBbrIVz4yFSuuFHimac0dVn%"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 158,
            "FileHash-SHA1": 158,
            "FileHash-SHA256": 1127,
            "URL": 110,
            "hostname": 45,
            "domain": 179
          },
          "indicator_count": 1777,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d46ee073b843b1b52f59a2",
          "name": "VirusTotal report\n                    for l-Management-System-School-ERP-nulled-by-CodeAlright.Com.zip",
          "description": "A look at the results of a report generated by the University of California, Los Angeles (UCLA) and compiled by codecanyon, a university-instikit and an academy.",
          "modified": "2026-05-07T02:13:20.636000",
          "created": "2026-04-07T02:41:36.582000",
          "tags": [
            "file type",
            "unix",
            "mitre attack",
            "network info",
            "wed jun",
            "overview",
            "dropped info",
            "processes extra",
            "overview zenbox",
            "linux verdict",
            "persistence",
            "malicious",
            "next",
            "newstoday2",
            "ip address",
            "virustotal box",
            "apples sandbox",
            "sandbox sha256",
            "analysis date",
            "screnshots",
            "file",
            "operations",
            "process open",
            "python",
            "javascript",
            "html",
            "sample",
            "test",
            "urls",
            "united",
            "extra info",
            "uncomment",
            "performs dns",
            "layer protocol",
            "attack network",
            "info dropped",
            "info processes",
            "info",
            "may try",
            "ascii text",
            "png image",
            "https",
            "reads cpu",
            "tls version",
            "ascii",
            "usrliblog"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/01f57cc95906a44558c5c1f19ef3191fe6f2f1cc03e1d10d1da421b7c604903f_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529261&Signature=RJNKrp%2FaK0APCyfk557hpXXr%2BMWPGME1nJO1%2BQCUEm9xRuKB0DlxP%2BfDSiZsLcJsAhaI%2FWxbH%2F%2FdbHllDXKgjJl92HzsTFyTAT0eMx%2BzlFLXKn0VyBmCHKLgKoFS4fDODUKy6SKJxdUav7aDP1aVhAXMPp%2BT3yWjDdSos0HQalqAt%2FcsVg1w28zfPjvVVGv%2B%2FvJeCIgzhXeE2pX6Npumx67Yym8jiiqV75WoDu",
            "https://vtbehaviour.commondatastorage.googleapis.com/00913627185b352deaf0ec837f85a7f606b27112956875de5d610fba8151306c_VirusTotal%20Box%20of%20Apples.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529477&Signature=s8ZCWLcVqjdBgBGejTcqippuMvftwgsdUQHUAjBnm45yUvqDsHIMIA29%2BJcb%2BrruXxHPD5tQv1BwAzlV1o7EuhxX4qMqDcFWSLqoc%2FqAnEVxLg0zXohtwMkHxv0z%2Bp5AL0jLyAwNYz7bH56tnmUs3tHPYc48OeM4AanV030U%2FnmXlF8kJ6cjAemipfTNe1QRx3ecbONm9c3B51FK0BbzZEdRX0pTHIM4AK1M",
            "https://vtbehaviour.commondatastorage.googleapis.com/0347ed7ffd09f6728c494128b1d11792893d5cde9e4effdc2bcc8f9ebb12a0e1_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529533&Signature=diQ6r2CuvkDxYGybQtlzxVxtH8iGMt6XlgZBEpk7B5n%2FVtwOuZaPpuNyM%2Fr4VbSp2H67%2FddXTZ3XJG8LdUMwLVXsSDKIq%2BjyQHccTuCS0HXEDbllONqfU6gWICxxtdC%2F4wdaL8fVyCE%2FHHcnWm5PufAa002Tn02MbSx9cFdNZS4R86MEMARaMiXSCiGQuiLR2STQCGqU%2Byg16ky%2FYjPbLtB6WD5skgEs3AgDmDNlDLjtbb",
            "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_Zenbox%20macOS.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529640&Signature=G0ONarqL7o1MkYvMlqktPKmEpNw5A3hwHYnIBwD8r%2F0xQfBDCaCPoL6%2BMxjj5Ftsb47O6KGvZzp2CS1xFcRHfbhEnUGRJR9o2%2FjSPy6NAV226GNwtSGdDXxPJFfETfpFlDEj%2FOCd26qtcBDdT4lX2saiGfx0%2FunV94XcNq3cUTVm%2Fsf0BO74945PnFWtBu3Oq%2FBm9AlaLwnyEZ5TDLfhXyqiTv1Qsx%2FWmBk0PIieA9MtTm",
            "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529701&Signature=BDpq68evTIZGfF61fRMAYEM%2BQtXgDfwPgp7qnaSE1mJStRV1ikHnSjRDxrMwGqkg0kaXqLEpQ%2BLuSCdJ9wJJzfrkQuV1%2Bbcg0cctnCOLgWhiXjekyol4iul%2FPXEGu6%2F1a20JEEoUfg9Dq6%2FosKMN9fmk%2BtqQcFa6PODcE3qJcO23YhWwDpmSYZ7t8JNsALFm98c6r%2BfBLLjnCSpVql2zQJifkl%2BteR57LTZG7W2lbENV",
            "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_VirusTotal%20Box%20of%20Apples.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529758&Signature=zXDmSolL1BXRVntoMjKFPJaZtQ0tI1lf56M%2BqCFh1c0JirSCS7DGBgxMdHuaZG8hsB%2FV1nO0JEfDegHE1Ibm55QO9TriIg9yCH6dZSsofTmiHiBOUZtTMSH1Pg1z%2FnuElFFvVDHQ2Ryhog0fw%2BwfS0Fpe5ZOoTF8KK883iH45dmOAcVEphu7K5A%2FrzfFG93bFibxA7MRKbLLGBbrIVz4yFSuuFHimac0dVn%"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 158,
            "FileHash-SHA1": 158,
            "FileHash-SHA256": 1127,
            "URL": 116,
            "hostname": 49,
            "domain": 182,
            "email": 1
          },
          "indicator_count": 1791,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d4569dc87656b4a255a124",
          "name": "VirusTotal report\n                    for download.rar",
          "description": "0347ed7f6728c494128d5cde9e4effdc2bcc8f944d78bca8d, as well as 1.3m2.",
          "modified": "2026-05-07T00:00:42.275000",
          "created": "2026-04-07T00:58:05.842000",
          "tags": [
            "json text",
            "json"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 281,
            "FileHash-SHA1": 277,
            "FileHash-SHA256": 2208,
            "URL": 113,
            "domain": 169,
            "hostname": 75
          },
          "indicator_count": 3123,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d4569a944adf94a75efcf9",
          "name": "VirusTotal report\n                    for download.rar",
          "description": "0347ed7f6728c494128d5cde9e4effdc2bcc8f944d78bca8d, as well as 1.3m2.",
          "modified": "2026-05-07T00:00:42.275000",
          "created": "2026-04-07T00:58:02.158000",
          "tags": [
            "json text",
            "json"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 287,
            "FileHash-SHA1": 283,
            "FileHash-SHA256": 2301,
            "URL": 113,
            "domain": 169,
            "hostname": 75
          },
          "indicator_count": 3228,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d4510870e9906d58e7a554",
          "name": "CAPE Sandbox -y2k",
          "description": "> full text of the full report on this year's EU Referendum, which will take place on 26 May 2017, has been published by BBC Radio 5 live in the UK and Ireland.>y2k status",
          "modified": "2026-05-07T00:00:42.275000",
          "created": "2026-04-07T00:34:16.928000",
          "tags": [
            "html document",
            "ascii text",
            "language"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 310,
            "FileHash-SHA1": 308,
            "FileHash-SHA256": 1270,
            "domain": 168,
            "hostname": 31,
            "URL": 98
          },
          "indicator_count": 2185,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d45107d82d67453e8ade06",
          "name": "CAPE Sandbox -y2k",
          "description": "> full text of the full report on this year's EU Referendum, which will take place on 26 May 2017, has been published by BBC Radio 5 live in the UK and Ireland.>y2k status",
          "modified": "2026-05-07T00:00:42.275000",
          "created": "2026-04-07T00:34:15.789000",
          "tags": [
            "html document",
            "ascii text",
            "language"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 310,
            "FileHash-SHA1": 308,
            "FileHash-SHA256": 1270,
            "domain": 168,
            "hostname": 31,
            "URL": 98
          },
          "indicator_count": 2185,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d4510678007ab57751a513",
          "name": "CAPE Sandbox -y2k",
          "description": "> full text of the full report on this year's EU Referendum, which will take place on 26 May 2017, has been published by BBC Radio 5 live in the UK and Ireland.>y2k status",
          "modified": "2026-05-07T00:00:42.275000",
          "created": "2026-04-07T00:34:14.009000",
          "tags": [
            "html document",
            "ascii text",
            "language"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 310,
            "FileHash-SHA1": 308,
            "FileHash-SHA256": 1270,
            "domain": 168,
            "hostname": 31,
            "URL": 98
          },
          "indicator_count": 2185,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d45104133846ffc6b2a6fe",
          "name": "CAPE Sandbox -y2k",
          "description": "> full text of the full report on this year's EU Referendum, which will take place on 26 May 2017, has been published by BBC Radio 5 live in the UK and Ireland.>y2k status",
          "modified": "2026-05-07T00:00:42.275000",
          "created": "2026-04-07T00:34:12.507000",
          "tags": [
            "html document",
            "ascii text",
            "language"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 310,
            "FileHash-SHA1": 308,
            "FileHash-SHA256": 1270,
            "domain": 168,
            "hostname": 31,
            "URL": 98
          },
          "indicator_count": 2185,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65eea19a23474b8c7dca351f",
          "name": "All Items - find from the UA archive disk",
          "description": "Again have zero idea 'what these are' - just uploading from the 'archives' as I sort through things",
          "modified": "2025-12-24T08:28:47.628000",
          "created": "2024-03-11T06:15:54.351000",
          "tags": [],
          "references": [
            "https://www.virustotal.com/gui/collection/09af9ef0b7b23d2dc73d83858106ae4fc97a352dbb521ac04493a0e79095ac69/iocs",
            "https://www.virustotal.com/gui/collection/79c25168b2f93d9730a56b8d2b834cbfb2752b63b21b9dd51109416fbaa676d8/iocs",
            "https://www.virustotal.com/graph/embed/g8726609a12794ebeb59edd531961a233068149bcdf994b428f20141be6111551?theme=dark",
            "https://www.virustotal.com/graph/embed/g365a82115f934e31a69118715695c91c231f66cda9084c9389e56afb985a243e?theme=dark",
            "",
            "https://www.virustotal.com/gui/collection/6a8d582df4fe5a29885dad4074236bc9e4ed445aaf0cc00702d45963fb0459bb/iocs"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1165,
            "hostname": 866,
            "URL": 657,
            "FileHash-SHA256": 26,
            "email": 337,
            "FileHash-MD5": 12,
            "FileHash-SHA1": 8,
            "CIDR": 1
          },
          "indicator_count": 3072,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 129,
          "modified_text": "160 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "665c44f012d938d1c7dd591e",
          "name": "PIT Projekt.exe (www.pitprojekt.pl , pitprojekt.pl)  oraz  Ceidg.gov.pl - Dane publiczne wpisu",
          "description": "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=f3ee4c4e-e009-4d69-82da-eef3bad1ecc4   NIP:6161230754\nhttps://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=7a025cc6-5167-43cf-947f-387a3b830778               NIP;6112323510\nhttp://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=7a025cc6-5167-43cf-947f-387a3b830778\n2.16.6.145146f05-9aac-4942-a42d-f2550a19c0c4              NIP:6131434311\nipv4: 2.16.6.14, 2.16.6.6, 2.16.6.1,",
          "modified": "2025-10-06T11:12:39.639000",
          "created": "2024-06-02T10:09:52.601000",
          "tags": [
            "ceidg.gov.pl - centralna ewidencja i informacja o dzia\u0142alno\u015bci g",
            "prosz czeka",
            "pobierz plik",
            "wojcieszyce",
            "urls competing",
            "ceidg centralna",
            "gospodarczej",
            "wyszukiwanie",
            "przejd",
            "centrum pomocy",
            "informacja o",
            "mapa",
            "strona gwna",
            "przegldanie",
            "ceidg szybki",
            "uwagi prawne",
            "deklaracja",
            "serwer",
            "returnurl",
            "idf3ee4c4ee00",
            "id7a025cc6516",
            "wctxrm0",
            "idf3ee4c4",
            "id35146f059aa",
            "ideb8f4cf26ef",
            "id7a025cc",
            "id35146f0",
            "publicznywsz3",
            "id97c275c",
            "url wiek",
            "ssdeep",
            "sha1",
            "pehasz",
            "typlibid",
            "pit projekt",
            "chcesz",
            "pity online",
            "program",
            "interesuje ci",
            "pity zapisane",
            "jeli",
            "oddajemy w",
            "twoje rce",
            "dziki jego"
          ],
          "references": [
            "http://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=7a025cc6-5167-43cf-947f-387a3b830778",
            "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=f3ee4c4e-e009-4d69-82da-eef3bad1ecc4",
            "https://aplikacja.ceidg.gov.pl/CEIDG/GroupMenu.aspx?key=_group_search",
            "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=35146f05-9aac-4942-a42d-f2550a19c0c4",
            "http://www.pitprojekt.pl",
            "http://pitprojekt.pl"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Wojcieszyce",
              "display_name": "Wojcieszyce",
              "target": null
            },
            {
              "id": "Serwer",
              "display_name": "Serwer",
              "target": null
            },
            {
              "id": "Serwer A Przed\u0142u\u017cenie sesji #{text}",
              "display_name": "Serwer A Przed\u0142u\u017cenie sesji #{text}",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8271,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1259,
            "URL": 6009,
            "hostname": 3030,
            "FileHash-SHA256": 10233,
            "FileHash-MD5": 2742,
            "FileHash-SHA1": 2348,
            "email": 75,
            "SSLCertFingerprint": 11,
            "YARA": 2,
            "CVE": 13,
            "FileHash-PEHASH": 1,
            "IPv4": 34,
            "IPv6": 6
          },
          "indicator_count": 25763,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 135,
          "modified_text": "238 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68038f7eb6f6810aa6d6439f",
          "name": "\"+g+\"",
          "description": "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.aspx?Id=855bdfc1-7dbc-4a86-9d27-89ebb0ecf166&archival=False",
          "modified": "2025-09-01T08:05:25.121000",
          "created": "2025-04-19T11:56:46.933000",
          "tags": [
            "copyright",
            "customevent",
            "typeof e",
            "boomerang",
            "typeof t",
            "macintosh",
            "os x",
            "post",
            "typeof",
            "iframe",
            "date",
            "poka menu",
            "nie znaleziono",
            "poka start",
            "poka",
            "max dostpnych",
            "pierwsza",
            "ostatnia",
            "nastpna",
            "poprzednia",
            "brak danych",
            "first",
            "ceidg",
            "wystpi bd",
            "error",
            "true",
            "null",
            "linkdownload",
            "show",
            "ctrlmappings",
            "version",
            "versionchange",
            "body",
            "false",
            "span",
            "input",
            "paginate",
            "next",
            "last",
            "selectstart",
            "loop",
            "function",
            "bootstrap",
            "datatables",
            "responsive",
            "2016 sprymedia",
            "amd define",
            "object",
            "commonjs",
            "window",
            "browser",
            "button",
            "datatable",
            "sprymedia ltd",
            "columns",
            "colidx",
            "column",
            "parent",
            "child",
            "param",
            "display",
            "click",
            "middle",
            "class",
            "target",
            "never",
            "find",
            "footer",
            "close",
            "regexp",
            "matches",
            "cookie",
            "inputmask",
            "input mask",
            "robin herbots",
            "mit license",
            "xmlhttprequest",
            "left",
            "month",
            "boolean",
            "maxdate",
            "right",
            "daterangepicker",
            "yyyymmdd",
            "calendar",
            "jquery",
            "webpackrequire",
            "typeof symbol",
            "type",
            "setprototypeof",
            "maskpos",
            "wrapnativesuper",
            "backspace",
            "insert",
            "internal",
            "mask",
            "void",
            "this",
            "nie mona",
            "array",
            "nonmsdombrowser",
            "horizontal",
            "leftarrow",
            "uparrow",
            "rightarrow",
            "downarrow",
            "explorer",
            "form",
            "legend",
            "hmmss",
            "mmmm d",
            "yyyy h",
            "typeof define",
            "number",
            "locale",
            "character",
            "seeknext",
            "masked",
            "input plugin",
            "josh bush",
            "azaz",
            "azaz09",
            "black",
            "kontrast",
            "arrcookies",
            "getcookielang",
            "and information",
            "on business",
            "sign",
            "twoja",
            "opinia",
            "informacja o",
            "notify ui",
            "widget",
            "eric hynds",
            "dual",
            "name",
            "dtopt",
            "example",
            "using",
            "open",
            "adata",
            "hungarian",
            "aria",
            "legacy",
            "trident",
            "format",
            "nuke",
            "apos",
            "bitcoin",
            "outer",
            "mark",
            "info",
            "reload",
            "behaviour",
            "write",
            "buttons",
            "anything",
            "prop",
            "thecookie",
            "create",
            "thevalue",
            "string name",
            "pluginscookie",
            "author",
            "eventkey",
            "datakey",
            "default",
            "dataapikey",
            "defaulttype",
            "config",
            "shown",
            "trigger",
            "delta",
            "guard",
            "arrow",
            "leave",
            "scroll",
            "dataspy",
            "sessiontimeout",
            "return",
            "settimeout",
            "mytimerid",
            "requestcounter",
            "starttimer",
            "stop",
            "typeof n",
            "adminlte",
            "typeof o",
            "main",
            "js application",
            "adminlte v2",
            "colorlib",
            "ui date",
            "written",
            "jacek wysocki",
            "poprzedni",
            "marzec",
            "kwiecie",
            "czerwiec",
            "lipiec",
            "sierpie",
            "wrzesie",
            "openpopup",
            "href",
            "toggle",
            "msviewport",
            "popover",
            "json",
            "json text",
            "string",
            "otherwise",
            "holder",
            "mind",
            "copy",
            "meta",
            "third",
            "text",
            "choice",
            "confirm",
            "nie pytaj",
            "site",
            "title",
            "value",
            "alert",
            "warn",
            "migrate",
            "foundation",
            "see http",
            "forget",
            "newvalue",
            "nones5",
            "fall",
            "wrongvalid",
            "onerror",
            "year",
            "fast",
            "argument",
            "popper",
            "method",
            "data",
            "html",
            "flip",
            "factory",
            "onload",
            "tbody",
            "courier",
            "elem",
            "handle",
            "expando",
            "match",
            "selector",
            "sizzle",
            "android",
            "capture",
            "seed",
            "pass",
            "enough",
            "code",
            "bind",
            "core",
            "local",
            "verify",
            "accept",
            "done",
            "override",
            "inject",
            "possible",
            "hold",
            "45deg",
            "larger",
            "screen styling",
            "90deg",
            "support",
            "sidebar mini",
            "e1f0ff",
            "font awesome",
            "free",
            "autocomplete",
            "folder",
            "expanded folder",
            "tabela",
            "sorting",
            "xform",
            "nadpisane style",
            "menlo",
            "monaco",
            "consolas",
            "mono",
            "courier new",
            "browse",
            "twitter",
            "pt serif",
            "georgia",
            "times new",
            "roman",
            "times",
            "typetime",
            "import",
            "roboto",
            "http",
            "label",
            "demos",
            "effect",
            "inst",
            "super",
            "speed",
            "bounce",
            "hack",
            "logic",
            "shift",
            "double",
            "february",
            "april",
            "june",
            "august",
            "friday",
            "erase",
            "atom",
            "caja",
            "spinner",
            "refresh",
            "alpha",
            "sentinel",
            "back",
            "blind",
            "drop",
            "ceidg.gov.pl - centralna ewidencja i informacja o dzia\u0142alno\u015bci g",
            "prosz czeka",
            "pobierz plik"
          ],
          "references": [
            "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.aspx?Id=855bdfc1-7dbc-4a86-9d27-89ebb0ecf166&archival=False",
            "UE_pl_top.svg",
            "UE_pl_top_sm.svg",
            "XZ4AH-ABKPW-SQPBC-CYWES-BCG6V",
            "dataTables.lang.js.pobrane",
            "EntryChangeHistory.aspx.js.pobrane",
            "dataTables.input.js.pobrane",
            "responsive.bootstrap4.js.pobrane",
            "dataTables.bootstrap4.js.pobrane",
            "dataTables.responsive.js.pobrane",
            "jquery.session.js.pobrane",
            "inputmask.binding.js.pobrane",
            "daterangepicker.js.pobrane",
            "jquery.inputmask.min.js.pobrane",
            "ScriptResource.axd",
            "moment-with-locales.min.js.pobrane",
            "jquery.maskedinput-1.2.2.js.pobrane",
            "feedback.js.pobrane",
            "jquery.notify.min.js.pobrane",
            "jquery.dataTables.js.pobrane",
            "jquery.cookie.js.pobrane",
            "bootstrap.js.pobrane",
            "SessionTimeout.js.pobrane",
            "adminlte.min.js.pobrane",
            "jquery.easing.1.3.js.pobrane",
            "jquery.feedbackBadge.min.js.pobrane",
            "ui.datepicker-pl.js.pobrane",
            "ceidg-master.js.pobrane",
            "CommonResponsive.js.pobrane",
            "json2.js.pobrane",
            "jquery.alerts.js.pobrane",
            "jquery-migrate-1.2.1.js.pobrane",
            "dataTables.bootstrap4.css",
            "CommonScripts.js.pobrane",
            "popper.js.pobrane",
            "responsive.bootstrap4.css",
            "jquery-3.0.0.js.pobrane",
            "daterangepicker.css",
            "AdminLTE.css",
            "ui.notify.css",
            "ceidg.css",
            "bootstrap-gov-pl.css",
            "biznes.css",
            "jquery-ui.js.pobrane",
            "saved_resource.html"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 25,
            "URL": 165,
            "domain": 353,
            "hostname": 215,
            "email": 2
          },
          "indicator_count": 767,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "274 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67a7f06a5d0f22ad92684646",
          "name": "WebForm.com.gov.pl/CEIDG/ScriptResource.axd",
          "description": "The following is the full text of the WebForm.com.gov.pl/CEIDG/ScriptResource.axd, following the following:.au, for the first time.",
          "modified": "2025-05-14T21:27:17.040000",
          "created": "2025-02-09T00:01:46.054000",
          "tags": [
            "null",
            "nie mona",
            "array",
            "input",
            "nonmsdombrowser",
            "object",
            "html",
            "component",
            "body",
            "horizontal",
            "date",
            "calendar",
            "february",
            "april",
            "june",
            "august",
            "iframe",
            "form",
            "friday",
            "explorer",
            "target",
            "error",
            "legend",
            "this",
            "type",
            "regexp",
            "elem",
            "index",
            "function",
            "handle",
            "check",
            "safari",
            "expando",
            "android",
            "false",
            "hooks",
            "copy",
            "prop",
            "class",
            "mark",
            "window",
            "code",
            "capture",
            "accept",
            "seed",
            "override",
            "hook",
            "look",
            "loop",
            "install",
            "pass",
            "enough",
            "bind",
            "core",
            "local",
            "verify",
            "done",
            "find",
            "internal",
            "inject",
            "possible",
            "hold",
            "middle",
            "guard",
            "fall",
            "stop",
            "panic",
            "back",
            "restrict",
            "speed",
            "turn",
            "grab",
            "getclass",
            "jquery",
            "bubble",
            "anchor",
            "shift"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1143,
            "domain": 155,
            "hostname": 523,
            "FileHash-SHA256": 151
          },
          "indicator_count": 1972,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "383 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "663d2869e0f3a42bbddc42ff",
          "name": "UPX executable packer.",
          "description": "A new rule has been introduced  a \"suspicious\" ELF binary that is packed with the UPX executable packer.\nSuggested ATT&CK IDs: rule SUSP_ELF_LNX_UPX_Compressed_File { meta: description = \"Detects a suspicious ELF binary with UPX compression\" author = \"Florian Roth (Nextron Systems)\" reference = \"Internal Research\" date = \"2018-12-12\" score = 40 hash1 = \"038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4\" id = \"078937de-59b3-538e-a5c3-57f4e6050212\" strings: $s1 = \"PROT_EXEC|PROT_WRITE failed.\" fullword ascii $s2 = \"$Id: UPX\" fullword ascii $s3 = \"$Info: This file is packed with the UPX executable packer\" ascii $fp1 = \"check your UCL installation !\"",
          "modified": "2024-10-14T00:01:17.069000",
          "created": "2024-05-09T19:47:53.786000",
          "tags": [
            "cioch adrian",
            "centrum usug",
            "sieciowych",
            "elf binary",
            "upx compression",
            "roth",
            "nextron",
            "info",
            "javascript",
            "html",
            "office open",
            "xml document",
            "network capture",
            "win32 exe",
            "xml pakietu",
            "pdf zestawy",
            "przechwytywanie",
            "office",
            "filehashsha1",
            "url https",
            "cve cve20201070",
            "cve cve20203153",
            "cve cve20201048",
            "cve cve20211732",
            "cve20201048 apr",
            "filehashmd5",
            "cve cve20010901",
            "cve cve20021841",
            "cve20153202 apr",
            "cve cve20160728",
            "cve cve20161807",
            "cve cve20175123",
            "cve20185407 apr",
            "cve cve20054605",
            "cve cve20060745",
            "cve cve20070452",
            "cve cve20070453",
            "cve cve20070454",
            "cve cve20071355",
            "cve cve20071358",
            "cve cve20071871",
            "cve20149614 apr",
            "cve cve20151503",
            "cve cve20152080",
            "cve cve20157377",
            "cve cve20170131",
            "cve20200796 may",
            "cve cve20113403"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6861,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 5771,
            "domain": 3139,
            "URL": 14525,
            "FileHash-SHA1": 2610,
            "IPv4": 108,
            "CIDR": 40,
            "FileHash-SHA256": 10705,
            "FileHash-MD5": 3373,
            "YARA": 2,
            "CVE": 148,
            "Mutex": 7,
            "FilePath": 3,
            "SSLCertFingerprint": 3,
            "email": 23,
            "JA3": 1,
            "IPv6": 2
          },
          "indicator_count": 40460,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "596 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6639853fc403f7be5bd6f27d",
          "name": "Facebook+",
          "description": "",
          "modified": "2024-05-07T01:34:55.365000",
          "created": "2024-05-07T01:34:55.365000",
          "tags": [],
          "references": [
            "https://www.virustotal.com/gui/collection/09af9ef0b7b23d2dc73d83858106ae4fc97a352dbb521ac04493a0e79095ac69/iocs",
            "https://www.virustotal.com/gui/collection/79c25168b2f93d9730a56b8d2b834cbfb2752b63b21b9dd51109416fbaa676d8/iocs",
            "https://www.virustotal.com/graph/embed/g8726609a12794ebeb59edd531961a233068149bcdf994b428f20141be6111551?theme=dark",
            "https://www.virustotal.com/graph/embed/g365a82115f934e31a69118715695c91c231f66cda9084c9389e56afb985a243e?theme=dark",
            "",
            "https://www.virustotal.com/gui/collection/6a8d582df4fe5a29885dad4074236bc9e4ed445aaf0cc00702d45963fb0459bb/iocs"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65eea19a23474b8c7dca351f",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Phone2209",
            "id": "281168",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1165,
            "hostname": 866,
            "URL": 657,
            "FileHash-SHA256": 26,
            "email": 337,
            "FileHash-MD5": 12,
            "FileHash-SHA1": 8,
            "CIDR": 1
          },
          "indicator_count": 3072,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1,
          "modified_text": "756 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c1c5e2cc4dfe8d0ed97",
          "name": "CPANEL-TUCOWS \u2014malware hosting",
          "description": "",
          "modified": "2023-12-06T14:58:36.254000",
          "created": "2023-12-06T14:58:36.254000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 815,
            "hostname": 3487,
            "domain": 1182,
            "URL": 10194,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 1
          },
          "indicator_count": 15682,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708b5e9b8ce0f5fd87fb98",
          "name": "ewqopweowia543.ga",
          "description": "",
          "modified": "2023-12-06T14:55:26.621000",
          "created": "2023-12-06T14:55:26.621000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "hostname": 706,
            "domain": 234,
            "FileHash-SHA256": 238,
            "URL": 1386
          },
          "indicator_count": 2565,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707f8475d8a8785dfc5a2f",
          "name": "Zetalytics API",
          "description": "",
          "modified": "2023-12-06T14:04:52.250000",
          "created": "2023-12-06T14:04:52.250000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 754,
            "hostname": 833,
            "domain": 441,
            "URL": 2375,
            "CIDR": 5,
            "FileHash-MD5": 2,
            "email": 1
          },
          "indicator_count": 4411,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "628e33df0169fe33f79b766b",
          "name": "Seems to be coming from space . Space malware? \u4e91\u9002\u914d(AllMobilize Inc.)  --\u4f01\u4e1a\u6d4f\u89c8\u5668\u53ca\u79fb\u52a8\u5316\u89e3\u51b3\u65b9\u6848\u4f9b\u5e94\u5546 | \u4e91\u9002\u914d",
          "description": "AllMobilize, Amaze, and all its partners - all of them with the same name - are now available to use on Facebook, Twitter, Instagram and other social media platforms, including Facebook.",
          "modified": "2022-05-25T13:49:19.876000",
          "created": "2022-05-25T13:49:19.876000",
          "tags": [
            "ebeef5",
            "dcdfe6",
            "e64552",
            "helvetica",
            "ffffff",
            "pingfang sc",
            "helveticaneue",
            "arial",
            "microsoft yahei",
            "45deg",
            "post",
            "sqdl",
            "sqhz",
            "eptyzj",
            "zjxcys",
            "doform",
            "modernizr",
            "typeradio",
            "tagnames",
            "boolean",
            "date",
            "array",
            "error",
            "typeof t",
            "dtft",
            "amaze ui",
            "function",
            "regexp",
            "d1dd2",
            "mstransitionend",
            "team",
            "android",
            "february",
            "april",
            "june",
            "august",
            "void",
            "null",
            "type",
            "elem",
            "index",
            "handle",
            "sizzle",
            "check",
            "target",
            "hooks",
            "prop",
            "copy",
            "class",
            "mark",
            "internal",
            "stack",
            "false",
            "code",
            "accept",
            "seed",
            "first",
            "body",
            "jquery",
            "pass",
            "bind",
            "core",
            "local",
            "verify",
            "done",
            "find",
            "inject",
            "possible",
            "hold",
            "trigger",
            "camel",
            "bubble",
            "window",
            "middle",
            "capture",
            "iframe",
            "fall",
            "stop",
            "panic",
            "back",
            "speed",
            "grab",
            "install",
            "open",
            "invalid request",
            "button",
            "input",
            "cpu os",
            "span",
            "label",
            "this",
            "trident",
            "pykey",
            "eventparams",
            "object",
            "event",
            "infinity",
            "pykeye",
            "string",
            "typeof",
            "typeof e",
            "typeof r",
            "typeof s",
            "typeof console",
            "contenttype",
            "number",
            "\u4e91\u9002\u914d\uff0c\u4f01\u4e1a\u79fb\u52a8\u5316\uff0c\u4f01\u4e1a\u79fb\u52a8\u5316\u89e3\u51b3\u65b9\u6848\uff0c\u4e91\u9002\u914d\u8de8\u5c4f",
            "\u4e91\u9002\u914d\u7f51\u7ad9\u9002\u914d",
            "\u4e91\u9002\u914d\u8de8\u5c4f\u4e91",
            "\u4e91\u9002\u914d\u8de8\u5c4f\u5e94\u7528",
            "\u4f01\u4e1aoa\u79fb\u52a8\u5316\u3001\u4f01\u4e1a\u79fb\u52a8\u95e8\u6237\u3001\u79fb\u52a8\u5e94\u7528\u7ba1\u7406\u3001\u79fb\u52a8\u5e94\u7528\u5e73\u53f0",
            "xcloud",
            "amaze",
            "sdp enterplorer",
            "siebel domino",
            "siebel",
            "domino",
            "allmobilize",
            "apipc",
            "ui amaze"
          ],
          "references": [
            "https://www.yunshipei.com/",
            "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
            "https://stats.ipinyou.com/adv?a=SR..sxcg_4d0DhagaJWCLj_ZdX&u=https%3A%2F%2Fwww.yunshipei.com%2F&rd=1653485491040&v=2&e=sr%3D390x844%26sc%3D32-bit%26je%3Dfalse%26lg%3Den-us%26vb%3D1%26did%3D%26dt%3D%26ps%3D390x3885%26vp%3D390x664%26ec%3DUTF-8%26vbt%3D1822%26sp%3D0%26ur%3D%26st%3D%26ev%3Dvg",
            "https://goutong.baidu.com/site/270/98c14a71a44014f7aa9d23449a55ae8f/b.js?siteId=3064033",
            "https://stats.ipinyou.com/presadv?a=SR..sxcg_4d0DhagaJWCLj_ZdX&cb=py.cb",
            "https://fm.ipinyou.com/j/a.js",
            "https://www.yunshipei.com/assets/js/jquery.js",
            "https://www.yunshipei.com/assets/js/amazeui.min.js",
            "https://www.yunshipei.com/assets/js/app.min.js",
            "https://sgoutong.baidu.com/embed/1652930761/asset/embed/css/mobile/main.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 652,
            "URL": 1482,
            "domain": 242,
            "FileHash-SHA256": 142,
            "FileHash-MD5": 3
          },
          "indicator_count": 2521,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1468 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f6d2300f3002b1d0f8a68",
          "name": "CPANEL-TUCOWS \u2014malware hosting",
          "description": "FBEvents-PostalCodeType, a new type of phone number type, has been added to the list of \"signals\" that can be controlled by a specialised operator.",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-20T02:17:07.272000",
          "tags": [
            "tucows",
            "vimeo",
            "enter otp",
            "foruserlogin",
            "username",
            "email address",
            "phone number",
            "click",
            "null",
            "otpviamail",
            "otpviasms",
            "error",
            "regexp",
            "edge",
            "elem",
            "function",
            "handle",
            "return",
            "expando",
            "match",
            "selector",
            "android",
            "false",
            "date",
            "target",
            "class",
            "mark",
            "copy",
            "capture",
            "seed",
            "pass",
            "enough",
            "code",
            "never",
            "core",
            "local",
            "verify",
            "fall",
            "accept",
            "done",
            "find",
            "internal",
            "inject",
            "possible",
            "prop",
            "trigger",
            "qe",
            "number",
            "string",
            "copyright",
            "uint8array",
            "xhfunction",
            "yhfunction",
            "gtmwrdf3cb",
            "host",
            "path",
            "gaugescookie",
            "gaugesuniqueday",
            "gaugesgauges",
            "slice",
            "image",
            "gaugestracker",
            "gaugesunique",
            "script",
            "closure library",
            "typeerror",
            "symbol",
            "array int8array",
            "caregexp",
            "legacy",
            "extra",
            "bootstrap",
            "medium",
            "large",
            "segoe ui",
            "roboto",
            "oxygensans",
            "ubuntu",
            "cantarell",
            "helvetica neue",
            "dataalignleft",
            "figcaption",
            "video",
            "ff6c2c",
            "styles",
            "badges",
            "small",
            "woff2",
            "fontface",
            "sans",
            "u1c801c88",
            "u20b4",
            "u2de02dff",
            "ua640a69f",
            "ufe2efe2f",
            "u04b004b1",
            "u2116",
            "arial",
            "helvetica",
            "montserrat",
            "productnav",
            "secondarynav",
            "typecheckbox",
            "menlo",
            "monaco",
            "consolas",
            "twitter",
            "font awesome",
            "license",
            "brands",
            "duotone",
            "msie",
            "russia",
            "paypal",
            "enduser license",
            "agreement",
            "europe",
            "typeof t",
            "typeof e",
            "typeof",
            "version",
            "attr",
            "pseudo",
            "object",
            "array",
            "invalid attempt",
            "typeof symbol",
            "survey",
            "trident",
            "form",
            "fullscreen",
            "property",
            "311218982",
            "textjavascript",
            "piscriptnum",
            "hj",
            "hotjar",
            "email",
            "telefon",
            "meta",
            "cookie",
            "keypress",
            "live",
            "generic",
            "window",
            "widget",
            "ciudad",
            "adore",
            "experiment",
            "mutation",
            "udc66udc67",
            "ud83d",
            "ufe0f",
            "ud83e",
            "udc68udc69",
            "udfcbudfcc",
            "u2640u2642",
            "source",
            "ud83dudc6cud83c",
            "cookiebot",
            "iabv2",
            "jsonversion",
            "cookie script",
            "methodstrict",
            "ticket",
            "id attribute",
            "cookiebot setup",
            "cookieconsent",
            "project",
            "reduceright",
            "trackevent",
            "pageview",
            "gtmwb4lhq4",
            "void",
            "pfunction",
            "contenttype",
            "zfunction",
            "bfunction",
            "mvoid",
            "ofunction",
            "thank",
            "f39c11",
            "quick question",
            "difficult",
            "easy",
            "poll",
            "typeof window",
            "invalid uuid",
            "functional",
            "member",
            "hnew regexp",
            "qfunction",
            "adview",
            "addbillinginfo",
            "addtocart",
            "addtolist",
            "contact",
            "download",
            "install",
            "signup",
            "addtowishlist",
            "lead",
            "custom",
            "typeof require",
            "sha256",
            "viewcontent",
            "search",
            "iterator",
            "boolean",
            "service",
            "phonenumber",
            "facebook",
            "javascript",
            "1cend"
          ],
          "references": [
            "xfe-URL-Cpanel.com-stix2-2.1-export.json",
            "https://pi.pardot.com/pd.js",
            "https://connect.facebook.net/signals/config/285857426541675?v=2.9.57&r=stable",
            "https://www.redditstatic.com/ads/pixel.js",
            "https://snap.licdn.com/li.lms-analytics/insight.min.js",
            "https://static.ads-twitter.com/uwt.js",
            "https://www.googleadservices.com/pagead/conversion_async.js",
            "https://static.hotjar.com/c/hotjar-1683409.js?sv=7",
            "https://www.google-analytics.com/analytics.js",
            "https://consent.cookiebot.com/da52fc49-8e48-42b7-9ad3-c219404f6f92/cc.js?renew=false&referer=cpanel.net&dnt=false",
            "https://consentcdn.cookiebot.com/consentconfig/da52fc49-8e48-42b7-9ad3-c219404f6f92/cpanel.net/configuration.js",
            "https://www.googletagmanager.com/gtm.js?id=GTM-WB4LHQ4",
            "https://www.bugherd.com/sidebarv2.js?apikey=kmu00qbvuigehexs5chefq",
            "https://consent.cookiebot.com/uc.js",
            "https://cpanel.net/wp-includes/js/wp-emoji-release.min.js?ver=5.6",
            "https://script.hotjar.com/modules.0076bf93c385ddf0ff58.js",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/728582492/?random=1650418372747&cv=9&fst=1650418372747&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fcpanel.net%2F&tiba=Hosting%20Platform%20of%20Choice&hn=www.googleadservices.com&us_privacy=1---&async=1&rfmt=3&fmt=4",
            "https://www.googleadservices.com/pagead/conversion/854235671/?random=1650418372749&cv=9&fst=1650418372749&num=1&value=0&label=PRNxCIWemu8BEJe0qpcD&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&data=ads_data_redaction%3Dfalse&frm=0&url=https%3A%2F%2Fcpanel.net%2F&tiba=Hosting%20Platform%20of%20Choice&gcs=G111&did=dMWZhNz&edid=dMWZhNz&auid=2050955691.1650418373&capi=2&hn=www.googleadservices.com&btty",
            "https://pi.pardot.com/analytics?ver=3&visitor_id=&visitor_id_sign=&pi_opt_in=&campaign_id=33566&account_id=872471&title=Hosting%20Platform%20of%20Choice&url=https%3A%2F%2Fcpanel.net%2F&referrer=",
            "https://www.1.cpanel.net/analytics?conly=true&visitor_id=311218274&visitor_id_sign=3e1116a56bfd91923fe15cac565b502779c6ec3fe7449557f3940ba04e77079951b9efb044c2275f4211d26742585a9d14544eae&pi_opt_in=&campaign_id=33566&account_id=872471&title=Hosting%20Platform%20of%20Choice&url=https://cpanel.net/&referrer=",
            "https://script.hotjar.com/survey-v2.3716506838f2208ab9e2.js",
            "https://cpanel.net/wp-content/themes/cPbase/assets/js/dist/script.js?ver=5.6",
            "https://cpanel.net/wp-content/themes/cPbase/assets/js/dist/cpbase.js?ver=5.6",
            "https://cpanel.net/wp-includes/js/wp-embed.min.js?ver=5.6",
            "https://pro.fontawesome.com/releases/v5.13.1/css/all.css",
            "https://vars.hotjar.com/box-4924254a9ce4dc9b959b6e4a9b662d60.html",
            "https://consentcdn.cookiebot.com/sdk/bc-v4.min.html",
            "https://cpanel.net/wp-content/themes/cPbase/style.css?ver=5.6",
            "https://cpanel.net/wp-includes/css/dist/block-library/style.min.css?ver=5.6",
            "https://fonts.googleapis.com/css?family=Open+Sans:100,200,300,400,500,600,700%7CMontserrat:100,200,300,400,500,600,700",
            "https://cpanel.net/wp-content/themes/cPbase/assets/css/version96.css",
            "https://cpanel.net/wp-content/themes/cPbase/assets/css/roadmap.css",
            "xfe-URL-pi.pardot.com-stix2-2.1-export.json",
            "xfe-URL-Cpanel.net-stix2-2.1-export.json",
            "https://secure.gaug.es/track.js",
            "https://www.googletagmanager.com/gtm.js?id=GTM-WRDF3CB",
            "https://149371662.v2.pressablecdn.com/wp-includes/js/jquery/jquery.js",
            "https://149371662.v2.pressablecdn.com/wp-content/plugins/user-verification/assets/front/js/scripts-otp.js",
            "https://player.vimeo.com/video/571271613",
            "https://bid.g.doubleclick.net/xbbe/pixel?d=KAE"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Tunisia"
          ],
          "malware_families": [
            {
              "id": "Qe",
              "display_name": "Qe",
              "target": null
            },
            {
              "id": "hj",
              "display_name": "hj",
              "target": null
            },
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3487,
            "URL": 10195,
            "domain": 1182,
            "FileHash-SHA256": 815,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 1
          },
          "indicator_count": 15683,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 74,
          "modified_text": "1475 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6253871aa38954c4426d475e",
          "name": "http://prima-abnehmen-shop.com/uk/order-now.html?affiliate=24&source=418&subid2=ddukc&subid3=35908921",
          "description": "In e, a new RegExp, has been added to the list of properties that can be used to store information in a single place, as well as a \"sizzle\" on the side of the page.",
          "modified": "2022-05-10T00:02:48.350000",
          "created": "2022-04-11T01:40:42.011000",
          "tags": [
            "strong",
            "imprint",
            "price",
            "address",
            "prima abnehmen",
            "usage return",
            "contact",
            "packs",
            "card",
            "digit code",
            "date",
            "back",
            "later",
            "function",
            "regexp",
            "edge",
            "elem",
            "webpackrequire",
            "return",
            "null",
            "handle",
            "expando",
            "match",
            "android",
            "target",
            "error",
            "false",
            "class",
            "mark",
            "harmony",
            "copy",
            "capture",
            "seed",
            "pass",
            "enough",
            "code",
            "never",
            "core",
            "local",
            "verify",
            "fall",
            "accept",
            "done",
            "find",
            "internal",
            "inject",
            "possible",
            "prop",
            "trigger",
            "typeof t",
            "typeof symbol",
            "typeerror",
            "object",
            "typeof e",
            "pseudo",
            "child",
            "this",
            "void",
            "array",
            "typeof n",
            "boolean",
            "messagechannel",
            "string",
            "symbol",
            "seventracker",
            "post",
            "nonce",
            "script",
            "please do",
            "not copy",
            "and paste",
            "this code",
            "cgrecaptchacfg",
            "ngrecaptcha",
            "recaptchaapi",
            "render",
            "typedarraytag",
            "blink",
            "gecko",
            "webkit",
            "trident",
            "the author",
            "this software",
            "copyright",
            "software is",
            "provided",
            "as is",
            "disclaims all",
            "warranties with",
            "regard to",
            "including all",
            "direct",
            "generator",
            "backspace",
            "select",
            "uint8array",
            "math",
            "number",
            "iframe",
            "span",
            "form",
            "click",
            "enterprise",
            "infinity",
            "template",
            "next",
            "body",
            "typeof r",
            "64e3",
            "urlsearchparams",
            "ofunction",
            "pfunction",
            "bfunction",
            "ffunction",
            "ifunction",
            "load",
            "sans",
            "woff2",
            "semibold",
            "bold",
            "italic",
            "semibold italic",
            "bold italic",
            "u20b4",
            "u2de02dff",
            "ua640a69f",
            "sufeffxa0",
            "attr"
          ],
          "references": [
            "xfe-URL-dk9ctyhidjrvgn.xyz-stix2-2.1-export.json",
            "http://dk9ctyhidjrvgn.xyz/index_files/jquery.js",
            "http://dk9ctyhidjrvgn.xyz/index_files/sss.css",
            "https://tracking.premiumhealtheurope.com/code.js",
            "https://static.cloudflareinsights.com/beacon.min.js",
            "https://www.gstatic.com/recaptcha/releases/Y-cOIEkAqcfDdup_qnnmkxIC/recaptcha__en.js",
            "https://cdn.getaddress.io/scripts/getaddress-autocomplete-1.1.2.min.js",
            "https://js.mollie.com/v1/mollie.js",
            "https://www.google.com/recaptcha/api.js?render=6LerjKkcAAAAAHIvlsndboXTiYDGt_xACa77alyA",
            "https://tracking.premiumhealth.eu/code.js",
            "https://eu-library.klarnaservices.com/lib.js",
            "https://prima-abnehmen-shop.com/_Resources/Static/Packages/Seven.Prima/Scripts/Main.js?bust=2a0b1c62",
            "https://prima-abnehmen-shop.com/_Resources/Static/Packages/Seven.Offerpage.Checkout/Scripts/main.min.js?bust=ef22ff16",
            "https://prima-abnehmen-shop.com/uk/order-now.html?affiliate=24&source=418&subid2=ddukc&subid3=35908921"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 640,
            "URL": 1862,
            "FileHash-SHA256": 149,
            "domain": 341
          },
          "indicator_count": 2992,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1484 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625045b8e764847c54ed286e",
          "name": "ewqopweowia543.ga",
          "description": "If you want to know what type of Touches you will get when you get stuck in the middle of a page, then ask for a random number of letters or numbers, or, if you can't find one.",
          "modified": "2022-05-08T00:03:14.586000",
          "created": "2022-04-08T14:24:56.301000",
          "tags": [
            "90deg",
            "250px",
            "helvetica neue",
            "helvetica",
            "roboto",
            "georgia",
            "typesearch",
            "typecheckbox",
            "label",
            "liberation mono",
            "function",
            "constructor",
            "param",
            "object",
            "class",
            "event",
            "abide",
            "number",
            "initializes",
            "drilldown",
            "window",
            "sticky",
            "false",
            "null",
            "body",
            "this",
            "date",
            "path",
            "anchor",
            "open",
            "trigger",
            "small",
            "close",
            "void",
            "form",
            "fast",
            "prop",
            "error",
            "shift",
            "test",
            "burn",
            "android",
            "back",
            "killswitch",
            "find",
            "desktop",
            "fall",
            "linear",
            "value",
            "webpackrequire",
            "return",
            "mouse",
            "factory",
            "moduleid",
            "apple cmd",
            "regexp",
            "elem",
            "handle",
            "expando",
            "match",
            "selector",
            "type",
            "sizzle",
            "target",
            "mark",
            "copy",
            "capture",
            "seed",
            "pass",
            "code",
            "bind",
            "core",
            "local",
            "verify",
            "accept",
            "done",
            "internal",
            "inject",
            "possible",
            "hold",
            "camel",
            "first",
            "middle",
            "gc",
            "eq",
            "post",
            "xava",
            "gbva",
            "hbva",
            "ibva",
            "lcva",
            "cdva",
            "oeva",
            "peva",
            "65535",
            "boolean",
            "counter",
            "segoe ui",
            "typeerror",
            "lucida",
            "ecommerce",
            "ext link",
            "comic",
            "impact",
            "light"
          ],
          "references": [
            "xfe-URL-ewqopweowia543.ga-stix2-2.0-export.json",
            "https://mc.yandex.ru/metrika/watch.js",
            "https://ssl.google-analytics.com/ga.js",
            "https://vestacp.com/bower_components/jquery/dist/jquery.js",
            "https://vestacp.com/bower_components/what-input/dist/what-input.js",
            "https://vestacp.com/bower_components/foundation-sites/dist/js/foundation.js",
            "https://vestacp.com/js/app.js",
            "https://vestacp.com/css/app.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Eq",
              "display_name": "Eq",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 706,
            "URL": 1386,
            "CVE": 1,
            "FileHash-SHA256": 238,
            "domain": 234
          },
          "indicator_count": 2565,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1486 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "621bc3aa050a6c5693595f25",
          "name": "Zetalytics API",
          "description": "",
          "modified": "2022-03-29T00:03:34.773000",
          "created": "2022-02-27T18:32:10.542000",
          "tags": [
            "google",
            "google llc",
            "detected",
            "expand overall",
            "http",
            "amazonaes",
            "openssl",
            "lookup go",
            "rescan add",
            "verdict report",
            "behaviour",
            "june",
            "apache",
            "search url",
            "search domain",
            "scan url",
            "url search",
            "domain scan",
            "url url",
            "us summary",
            "line",
            "google maps",
            "api warning",
            "redirects links",
            "similar dom",
            "content api",
            "domains",
            "Ransomware"
          ],
          "references": [
            "zetalytics .pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Win.Virus.PolyRansom-5704625-0",
              "display_name": "Win.Virus.PolyRansom-5704625-0",
              "target": null
            },
            {
              "id": "Win32:Cryptor",
              "display_name": "Win32:Cryptor",
              "target": null
            },
            {
              "id": "TELPER:CERT:SoftwareBundler:Win32/Bunpredelt",
              "display_name": "TELPER:CERT:SoftwareBundler:Win32/Bunpredelt",
              "target": null
            },
            {
              "id": "Trojan:Win32/Danabot.G",
              "display_name": "Trojan:Win32/Danabot.G",
              "target": "/malware/Trojan:Win32/Danabot.G"
            },
            {
              "id": "Backdoor:Win32/Poison.E",
              "display_name": "Backdoor:Win32/Poison.E",
              "target": "/malware/Backdoor:Win32/Poison.E"
            },
            {
              "id": "ALF:PUA:Block:IObit.R!MTB",
              "display_name": "ALF:PUA:Block:IObit.R!MTB",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 754,
            "URL": 2375,
            "domain": 441,
            "hostname": 833,
            "CIDR": 5,
            "FileHash-MD5": 2,
            "email": 1
          },
          "indicator_count": 4411,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 405,
          "modified_text": "1526 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "https://ssl.google-analytics.com/ga.js",
        "https://prima-abnehmen-shop.com/uk/order-now.html?affiliate=24&source=418&subid2=ddukc&subid3=35908921",
        "https://www.virustotal.com/gui/collection/6a8d582df4fe5a29885dad4074236bc9e4ed445aaf0cc00702d45963fb0459bb/iocs",
        "https://www.google.com/recaptcha/api.js?render=6LerjKkcAAAAAHIvlsndboXTiYDGt_xACa77alyA",
        "XZ4AH-ABKPW-SQPBC-CYWES-BCG6V",
        "https://fm.ipinyou.com/j/a.js",
        "popper.js.pobrane",
        "jquery.feedbackBadge.min.js.pobrane",
        "https://tracking.premiumhealth.eu/code.js",
        "jquery.cookie.js.pobrane",
        "xfe-URL-Cpanel.com-stix2-2.1-export.json",
        "https://149371662.v2.pressablecdn.com/wp-content/plugins/user-verification/assets/front/js/scripts-otp.js",
        "dataTables.bootstrap4.css",
        "https://www.virustotal.com/gui/collection/79c25168b2f93d9730a56b8d2b834cbfb2752b63b21b9dd51109416fbaa676d8/iocs",
        "xfe-URL-ewqopweowia543.ga-stix2-2.0-export.json",
        "https://secure.gaug.es/track.js",
        "jquery.inputmask.min.js.pobrane",
        "daterangepicker.js.pobrane",
        "https://connect.facebook.net/signals/config/285857426541675?v=2.9.57&r=stable",
        "https://www.gstatic.com/recaptcha/releases/Y-cOIEkAqcfDdup_qnnmkxIC/recaptcha__en.js",
        "AdminLTE.css",
        "https://149371662.v2.pressablecdn.com/wp-includes/js/jquery/jquery.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-WRDF3CB",
        "ScriptResource.axd",
        "ui.notify.css",
        "UE_pl_top.svg",
        "dataTables.responsive.js.pobrane",
        "xfe-URL-pi.pardot.com-stix2-2.1-export.json",
        "UE_pl_top_sm.svg",
        "https://fonts.googleapis.com/css?family=Open+Sans:100,200,300,400,500,600,700%7CMontserrat:100,200,300,400,500,600,700",
        "jquery.notify.min.js.pobrane",
        "feedback.js.pobrane",
        "https://static.ads-twitter.com/uwt.js",
        "https://script.hotjar.com/modules.0076bf93c385ddf0ff58.js",
        "https://www.virustotal.com/graph/embed/g365a82115f934e31a69118715695c91c231f66cda9084c9389e56afb985a243e?theme=dark",
        "jquery-migrate-1.2.1.js.pobrane",
        "https://cpanel.net/wp-content/themes/cPbase/assets/js/dist/cpbase.js?ver=5.6",
        "https://tracking.premiumhealtheurope.com/code.js",
        "jquery.maskedinput-1.2.2.js.pobrane",
        "https://cdn.getaddress.io/scripts/getaddress-autocomplete-1.1.2.min.js",
        "bootstrap.js.pobrane",
        "responsive.bootstrap4.js.pobrane",
        "https://www.googletagmanager.com/gtm.js?id=GTM-WB4LHQ4",
        "https://www.bugherd.com/sidebarv2.js?apikey=kmu00qbvuigehexs5chefq",
        "https://cpanel.net/wp-content/themes/cPbase/assets/css/version96.css",
        "jquery-3.0.0.js.pobrane",
        "https://vestacp.com/bower_components/jquery/dist/jquery.js",
        "https://www.1.cpanel.net/analytics?conly=true&visitor_id=311218274&visitor_id_sign=3e1116a56bfd91923fe15cac565b502779c6ec3fe7449557f3940ba04e77079951b9efb044c2275f4211d26742585a9d14544eae&pi_opt_in=&campaign_id=33566&account_id=872471&title=Hosting%20Platform%20of%20Choice&url=https://cpanel.net/&referrer=",
        "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=35146f05-9aac-4942-a42d-f2550a19c0c4",
        "https://consentcdn.cookiebot.com/sdk/bc-v4.min.html",
        "http://pitprojekt.pl",
        "https://www.yunshipei.com/assets/js/jquery.js",
        "https://www.virustotal.com/graph/embed/g8726609a12794ebeb59edd531961a233068149bcdf994b428f20141be6111551?theme=dark",
        "https://consent.cookiebot.com/uc.js",
        "biznes.css",
        "moment-with-locales.min.js.pobrane",
        "http://dk9ctyhidjrvgn.xyz/index_files/jquery.js",
        "CommonResponsive.js.pobrane",
        "https://vtbehaviour.commondatastorage.googleapis.com/00913627185b352deaf0ec837f85a7f606b27112956875de5d610fba8151306c_VirusTotal%20Box%20of%20Apples.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529477&Signature=s8ZCWLcVqjdBgBGejTcqippuMvftwgsdUQHUAjBnm45yUvqDsHIMIA29%2BJcb%2BrruXxHPD5tQv1BwAzlV1o7EuhxX4qMqDcFWSLqoc%2FqAnEVxLg0zXohtwMkHxv0z%2Bp5AL0jLyAwNYz7bH56tnmUs3tHPYc48OeM4AanV030U%2FnmXlF8kJ6cjAemipfTNe1QRx3ecbONm9c3B51FK0BbzZEdRX0pTHIM4AK1M",
        "ui.datepicker-pl.js.pobrane",
        "responsive.bootstrap4.css",
        "xfe-URL-Cpanel.net-stix2-2.1-export.json",
        "https://pi.pardot.com/analytics?ver=3&visitor_id=&visitor_id_sign=&pi_opt_in=&campaign_id=33566&account_id=872471&title=Hosting%20Platform%20of%20Choice&url=https%3A%2F%2Fcpanel.net%2F&referrer=",
        "http://dk9ctyhidjrvgn.xyz/index_files/sss.css",
        "https://www.redditstatic.com/ads/pixel.js",
        "inputmask.binding.js.pobrane",
        "http://www.pitprojekt.pl",
        "https://consent.cookiebot.com/da52fc49-8e48-42b7-9ad3-c219404f6f92/cc.js?renew=false&referer=cpanel.net&dnt=false",
        "https://script.hotjar.com/survey-v2.3716506838f2208ab9e2.js",
        "dataTables.lang.js.pobrane",
        "https://vtbehaviour.commondatastorage.googleapis.com/01f57cc95906a44558c5c1f19ef3191fe6f2f1cc03e1d10d1da421b7c604903f_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529261&Signature=RJNKrp%2FaK0APCyfk557hpXXr%2BMWPGME1nJO1%2BQCUEm9xRuKB0DlxP%2BfDSiZsLcJsAhaI%2FWxbH%2F%2FdbHllDXKgjJl92HzsTFyTAT0eMx%2BzlFLXKn0VyBmCHKLgKoFS4fDODUKy6SKJxdUav7aDP1aVhAXMPp%2BT3yWjDdSos0HQalqAt%2FcsVg1w28zfPjvVVGv%2B%2FvJeCIgzhXeE2pX6Npumx67Yym8jiiqV75WoDu",
        "https://www.googleadservices.com/pagead/conversion_async.js",
        "https://consentcdn.cookiebot.com/consentconfig/da52fc49-8e48-42b7-9ad3-c219404f6f92/cpanel.net/configuration.js",
        "https://www.yunshipei.com/",
        "https://stats.ipinyou.com/adv?a=SR..sxcg_4d0DhagaJWCLj_ZdX&u=https%3A%2F%2Fwww.yunshipei.com%2F&rd=1653485491040&v=2&e=sr%3D390x844%26sc%3D32-bit%26je%3Dfalse%26lg%3Den-us%26vb%3D1%26did%3D%26dt%3D%26ps%3D390x3885%26vp%3D390x664%26ec%3DUTF-8%26vbt%3D1822%26sp%3D0%26ur%3D%26st%3D%26ev%3Dvg",
        "https://prima-abnehmen-shop.com/_Resources/Static/Packages/Seven.Prima/Scripts/Main.js?bust=2a0b1c62",
        "https://sgoutong.baidu.com/embed/1652930761/asset/embed/css/mobile/main.css",
        "xfe-URL-dk9ctyhidjrvgn.xyz-stix2-2.1-export.json",
        "dataTables.input.js.pobrane",
        "https://bid.g.doubleclick.net/xbbe/pixel?d=KAE",
        "adminlte.min.js.pobrane",
        "CommonScripts.js.pobrane",
        "https://mc.yandex.ru/metrika/watch.js",
        "https://www.google-analytics.com/analytics.js",
        "jquery.easing.1.3.js.pobrane",
        "https://cpanel.net/wp-includes/js/wp-emoji-release.min.js?ver=5.6",
        "http://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=7a025cc6-5167-43cf-947f-387a3b830778",
        "https://vestacp.com/bower_components/what-input/dist/what-input.js",
        "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
        "bootstrap-gov-pl.css",
        "jquery-ui.js.pobrane",
        "https://stats.ipinyou.com/presadv?a=SR..sxcg_4d0DhagaJWCLj_ZdX&cb=py.cb",
        "https://vestacp.com/css/app.css",
        "https://cpanel.net/wp-includes/js/wp-embed.min.js?ver=5.6",
        "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.aspx?Id=855bdfc1-7dbc-4a86-9d27-89ebb0ecf166&archival=False",
        "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_VirusTotal%20Box%20of%20Apples.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529758&Signature=zXDmSolL1BXRVntoMjKFPJaZtQ0tI1lf56M%2BqCFh1c0JirSCS7DGBgxMdHuaZG8hsB%2FV1nO0JEfDegHE1Ibm55QO9TriIg9yCH6dZSsofTmiHiBOUZtTMSH1Pg1z%2FnuElFFvVDHQ2Ryhog0fw%2BwfS0Fpe5ZOoTF8KK883iH45dmOAcVEphu7K5A%2FrzfFG93bFibxA7MRKbLLGBbrIVz4yFSuuFHimac0dVn%",
        "EntryChangeHistory.aspx.js.pobrane",
        "https://cpanel.net/wp-content/themes/cPbase/style.css?ver=5.6",
        "https://static.hotjar.com/c/hotjar-1683409.js?sv=7",
        "jquery.dataTables.js.pobrane",
        "https://pi.pardot.com/pd.js",
        "ceidg-master.js.pobrane",
        "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_Zenbox%20macOS.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529640&Signature=G0ONarqL7o1MkYvMlqktPKmEpNw5A3hwHYnIBwD8r%2F0xQfBDCaCPoL6%2BMxjj5Ftsb47O6KGvZzp2CS1xFcRHfbhEnUGRJR9o2%2FjSPy6NAV226GNwtSGdDXxPJFfETfpFlDEj%2FOCd26qtcBDdT4lX2saiGfx0%2FunV94XcNq3cUTVm%2Fsf0BO74945PnFWtBu3Oq%2FBm9AlaLwnyEZ5TDLfhXyqiTv1Qsx%2FWmBk0PIieA9MtTm",
        "https://snap.licdn.com/li.lms-analytics/insight.min.js",
        "https://eu-library.klarnaservices.com/lib.js",
        "jquery.session.js.pobrane",
        "SessionTimeout.js.pobrane",
        "https://player.vimeo.com/video/571271613",
        "https://www.yunshipei.com/assets/js/amazeui.min.js",
        "jquery.alerts.js.pobrane",
        "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=f3ee4c4e-e009-4d69-82da-eef3bad1ecc4",
        "https://aplikacja.ceidg.gov.pl/CEIDG/GroupMenu.aspx?key=_group_search",
        "https://vtbehaviour.commondatastorage.googleapis.com/0347ed7ffd09f6728c494128b1d11792893d5cde9e4effdc2bcc8f9ebb12a0e1_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529533&Signature=diQ6r2CuvkDxYGybQtlzxVxtH8iGMt6XlgZBEpk7B5n%2FVtwOuZaPpuNyM%2Fr4VbSp2H67%2FddXTZ3XJG8LdUMwLVXsSDKIq%2BjyQHccTuCS0HXEDbllONqfU6gWICxxtdC%2F4wdaL8fVyCE%2FHHcnWm5PufAa002Tn02MbSx9cFdNZS4R86MEMARaMiXSCiGQuiLR2STQCGqU%2Byg16ky%2FYjPbLtB6WD5skgEs3AgDmDNlDLjtbb",
        "https://pro.fontawesome.com/releases/v5.13.1/css/all.css",
        "https://www.googleadservices.com/pagead/conversion/854235671/?random=1650418372749&cv=9&fst=1650418372749&num=1&value=0&label=PRNxCIWemu8BEJe0qpcD&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&data=ads_data_redaction%3Dfalse&frm=0&url=https%3A%2F%2Fcpanel.net%2F&tiba=Hosting%20Platform%20of%20Choice&gcs=G111&did=dMWZhNz&edid=dMWZhNz&auid=2050955691.1650418373&capi=2&hn=www.googleadservices.com&btty",
        "json2.js.pobrane",
        "https://vars.hotjar.com/box-4924254a9ce4dc9b959b6e4a9b662d60.html",
        "https://vestacp.com/js/app.js",
        "zetalytics .pdf",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/728582492/?random=1650418372747&cv=9&fst=1650418372747&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fcpanel.net%2F&tiba=Hosting%20Platform%20of%20Choice&hn=www.googleadservices.com&us_privacy=1---&async=1&rfmt=3&fmt=4",
        "https://prima-abnehmen-shop.com/_Resources/Static/Packages/Seven.Offerpage.Checkout/Scripts/main.min.js?bust=ef22ff16",
        "https://vestacp.com/bower_components/foundation-sites/dist/js/foundation.js",
        "https://goutong.baidu.com/site/270/98c14a71a44014f7aa9d23449a55ae8f/b.js?siteId=3064033",
        "https://cpanel.net/wp-content/themes/cPbase/assets/js/dist/script.js?ver=5.6",
        "ceidg.css",
        "https://cpanel.net/wp-content/themes/cPbase/assets/css/roadmap.css",
        "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529701&Signature=BDpq68evTIZGfF61fRMAYEM%2BQtXgDfwPgp7qnaSE1mJStRV1ikHnSjRDxrMwGqkg0kaXqLEpQ%2BLuSCdJ9wJJzfrkQuV1%2Bbcg0cctnCOLgWhiXjekyol4iul%2FPXEGu6%2F1a20JEEoUfg9Dq6%2FosKMN9fmk%2BtqQcFa6PODcE3qJcO23YhWwDpmSYZ7t8JNsALFm98c6r%2BfBLLjnCSpVql2zQJifkl%2BteR57LTZG7W2lbENV",
        "daterangepicker.css",
        "saved_resource.html",
        "https://www.yunshipei.com/assets/js/app.min.js",
        "dataTables.bootstrap4.js.pobrane",
        "https://cpanel.net/wp-includes/css/dist/block-library/style.min.css?ver=5.6",
        "https://static.cloudflareinsights.com/beacon.min.js",
        "https://www.virustotal.com/gui/collection/09af9ef0b7b23d2dc73d83858106ae4fc97a352dbb521ac04493a0e79095ac69/iocs",
        "https://js.mollie.com/v1/mollie.js"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Gc",
            "Hj",
            "Win32:cryptor",
            "Win.virus.polyransom-5704625-0",
            "Trojan:win32/danabot.g",
            "Wojcieszyce",
            "Qe",
            "Telper:cert:softwarebundler:win32/bunpredelt",
            "Alf:pua:block:iobit.r!mtb",
            "Eq",
            "Reduceright",
            "Backdoor:win32/poison.e",
            "Serwer",
            "Serwer a przed\u0142u\u017cenie sesji #{text}"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 22,
  "pulses": [
    {
      "id": "69d46ee1379578309fae9a4a",
      "name": "VirusTotal report\n                    for l-Management-System-School-ERP-nulled-by-CodeAlright.Com.zip",
      "description": "A look at the results of a report generated by the University of California, Los Angeles (UCLA) and compiled by codecanyon, a university-instikit and an academy.",
      "modified": "2026-05-07T02:13:20.636000",
      "created": "2026-04-07T02:41:37.877000",
      "tags": [
        "file type",
        "unix",
        "mitre attack",
        "network info",
        "wed jun",
        "overview",
        "dropped info",
        "processes extra",
        "overview zenbox",
        "linux verdict",
        "persistence",
        "malicious",
        "next",
        "newstoday2",
        "ip address",
        "virustotal box",
        "apples sandbox",
        "sandbox sha256",
        "analysis date",
        "screnshots",
        "file",
        "operations",
        "process open",
        "python",
        "javascript",
        "html",
        "sample",
        "test",
        "urls",
        "united",
        "extra info",
        "uncomment",
        "performs dns",
        "layer protocol",
        "attack network",
        "info dropped",
        "info processes",
        "info",
        "may try",
        "ascii text",
        "png image",
        "https",
        "reads cpu",
        "tls version",
        "ascii",
        "usrliblog"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/01f57cc95906a44558c5c1f19ef3191fe6f2f1cc03e1d10d1da421b7c604903f_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529261&Signature=RJNKrp%2FaK0APCyfk557hpXXr%2BMWPGME1nJO1%2BQCUEm9xRuKB0DlxP%2BfDSiZsLcJsAhaI%2FWxbH%2F%2FdbHllDXKgjJl92HzsTFyTAT0eMx%2BzlFLXKn0VyBmCHKLgKoFS4fDODUKy6SKJxdUav7aDP1aVhAXMPp%2BT3yWjDdSos0HQalqAt%2FcsVg1w28zfPjvVVGv%2B%2FvJeCIgzhXeE2pX6Npumx67Yym8jiiqV75WoDu",
        "https://vtbehaviour.commondatastorage.googleapis.com/00913627185b352deaf0ec837f85a7f606b27112956875de5d610fba8151306c_VirusTotal%20Box%20of%20Apples.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529477&Signature=s8ZCWLcVqjdBgBGejTcqippuMvftwgsdUQHUAjBnm45yUvqDsHIMIA29%2BJcb%2BrruXxHPD5tQv1BwAzlV1o7EuhxX4qMqDcFWSLqoc%2FqAnEVxLg0zXohtwMkHxv0z%2Bp5AL0jLyAwNYz7bH56tnmUs3tHPYc48OeM4AanV030U%2FnmXlF8kJ6cjAemipfTNe1QRx3ecbONm9c3B51FK0BbzZEdRX0pTHIM4AK1M",
        "https://vtbehaviour.commondatastorage.googleapis.com/0347ed7ffd09f6728c494128b1d11792893d5cde9e4effdc2bcc8f9ebb12a0e1_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529533&Signature=diQ6r2CuvkDxYGybQtlzxVxtH8iGMt6XlgZBEpk7B5n%2FVtwOuZaPpuNyM%2Fr4VbSp2H67%2FddXTZ3XJG8LdUMwLVXsSDKIq%2BjyQHccTuCS0HXEDbllONqfU6gWICxxtdC%2F4wdaL8fVyCE%2FHHcnWm5PufAa002Tn02MbSx9cFdNZS4R86MEMARaMiXSCiGQuiLR2STQCGqU%2Byg16ky%2FYjPbLtB6WD5skgEs3AgDmDNlDLjtbb",
        "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_Zenbox%20macOS.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529640&Signature=G0ONarqL7o1MkYvMlqktPKmEpNw5A3hwHYnIBwD8r%2F0xQfBDCaCPoL6%2BMxjj5Ftsb47O6KGvZzp2CS1xFcRHfbhEnUGRJR9o2%2FjSPy6NAV226GNwtSGdDXxPJFfETfpFlDEj%2FOCd26qtcBDdT4lX2saiGfx0%2FunV94XcNq3cUTVm%2Fsf0BO74945PnFWtBu3Oq%2FBm9AlaLwnyEZ5TDLfhXyqiTv1Qsx%2FWmBk0PIieA9MtTm",
        "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529701&Signature=BDpq68evTIZGfF61fRMAYEM%2BQtXgDfwPgp7qnaSE1mJStRV1ikHnSjRDxrMwGqkg0kaXqLEpQ%2BLuSCdJ9wJJzfrkQuV1%2Bbcg0cctnCOLgWhiXjekyol4iul%2FPXEGu6%2F1a20JEEoUfg9Dq6%2FosKMN9fmk%2BtqQcFa6PODcE3qJcO23YhWwDpmSYZ7t8JNsALFm98c6r%2BfBLLjnCSpVql2zQJifkl%2BteR57LTZG7W2lbENV",
        "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_VirusTotal%20Box%20of%20Apples.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529758&Signature=zXDmSolL1BXRVntoMjKFPJaZtQ0tI1lf56M%2BqCFh1c0JirSCS7DGBgxMdHuaZG8hsB%2FV1nO0JEfDegHE1Ibm55QO9TriIg9yCH6dZSsofTmiHiBOUZtTMSH1Pg1z%2FnuElFFvVDHQ2Ryhog0fw%2BwfS0Fpe5ZOoTF8KK883iH45dmOAcVEphu7K5A%2FrzfFG93bFibxA7MRKbLLGBbrIVz4yFSuuFHimac0dVn%"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 158,
        "FileHash-SHA1": 158,
        "FileHash-SHA256": 1127,
        "URL": 110,
        "hostname": 45,
        "domain": 179
      },
      "indicator_count": 1777,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d46ee073b843b1b52f59a2",
      "name": "VirusTotal report\n                    for l-Management-System-School-ERP-nulled-by-CodeAlright.Com.zip",
      "description": "A look at the results of a report generated by the University of California, Los Angeles (UCLA) and compiled by codecanyon, a university-instikit and an academy.",
      "modified": "2026-05-07T02:13:20.636000",
      "created": "2026-04-07T02:41:36.582000",
      "tags": [
        "file type",
        "unix",
        "mitre attack",
        "network info",
        "wed jun",
        "overview",
        "dropped info",
        "processes extra",
        "overview zenbox",
        "linux verdict",
        "persistence",
        "malicious",
        "next",
        "newstoday2",
        "ip address",
        "virustotal box",
        "apples sandbox",
        "sandbox sha256",
        "analysis date",
        "screnshots",
        "file",
        "operations",
        "process open",
        "python",
        "javascript",
        "html",
        "sample",
        "test",
        "urls",
        "united",
        "extra info",
        "uncomment",
        "performs dns",
        "layer protocol",
        "attack network",
        "info dropped",
        "info processes",
        "info",
        "may try",
        "ascii text",
        "png image",
        "https",
        "reads cpu",
        "tls version",
        "ascii",
        "usrliblog"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/01f57cc95906a44558c5c1f19ef3191fe6f2f1cc03e1d10d1da421b7c604903f_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529261&Signature=RJNKrp%2FaK0APCyfk557hpXXr%2BMWPGME1nJO1%2BQCUEm9xRuKB0DlxP%2BfDSiZsLcJsAhaI%2FWxbH%2F%2FdbHllDXKgjJl92HzsTFyTAT0eMx%2BzlFLXKn0VyBmCHKLgKoFS4fDODUKy6SKJxdUav7aDP1aVhAXMPp%2BT3yWjDdSos0HQalqAt%2FcsVg1w28zfPjvVVGv%2B%2FvJeCIgzhXeE2pX6Npumx67Yym8jiiqV75WoDu",
        "https://vtbehaviour.commondatastorage.googleapis.com/00913627185b352deaf0ec837f85a7f606b27112956875de5d610fba8151306c_VirusTotal%20Box%20of%20Apples.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529477&Signature=s8ZCWLcVqjdBgBGejTcqippuMvftwgsdUQHUAjBnm45yUvqDsHIMIA29%2BJcb%2BrruXxHPD5tQv1BwAzlV1o7EuhxX4qMqDcFWSLqoc%2FqAnEVxLg0zXohtwMkHxv0z%2Bp5AL0jLyAwNYz7bH56tnmUs3tHPYc48OeM4AanV030U%2FnmXlF8kJ6cjAemipfTNe1QRx3ecbONm9c3B51FK0BbzZEdRX0pTHIM4AK1M",
        "https://vtbehaviour.commondatastorage.googleapis.com/0347ed7ffd09f6728c494128b1d11792893d5cde9e4effdc2bcc8f9ebb12a0e1_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529533&Signature=diQ6r2CuvkDxYGybQtlzxVxtH8iGMt6XlgZBEpk7B5n%2FVtwOuZaPpuNyM%2Fr4VbSp2H67%2FddXTZ3XJG8LdUMwLVXsSDKIq%2BjyQHccTuCS0HXEDbllONqfU6gWICxxtdC%2F4wdaL8fVyCE%2FHHcnWm5PufAa002Tn02MbSx9cFdNZS4R86MEMARaMiXSCiGQuiLR2STQCGqU%2Byg16ky%2FYjPbLtB6WD5skgEs3AgDmDNlDLjtbb",
        "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_Zenbox%20macOS.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529640&Signature=G0ONarqL7o1MkYvMlqktPKmEpNw5A3hwHYnIBwD8r%2F0xQfBDCaCPoL6%2BMxjj5Ftsb47O6KGvZzp2CS1xFcRHfbhEnUGRJR9o2%2FjSPy6NAV226GNwtSGdDXxPJFfETfpFlDEj%2FOCd26qtcBDdT4lX2saiGfx0%2FunV94XcNq3cUTVm%2Fsf0BO74945PnFWtBu3Oq%2FBm9AlaLwnyEZ5TDLfhXyqiTv1Qsx%2FWmBk0PIieA9MtTm",
        "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529701&Signature=BDpq68evTIZGfF61fRMAYEM%2BQtXgDfwPgp7qnaSE1mJStRV1ikHnSjRDxrMwGqkg0kaXqLEpQ%2BLuSCdJ9wJJzfrkQuV1%2Bbcg0cctnCOLgWhiXjekyol4iul%2FPXEGu6%2F1a20JEEoUfg9Dq6%2FosKMN9fmk%2BtqQcFa6PODcE3qJcO23YhWwDpmSYZ7t8JNsALFm98c6r%2BfBLLjnCSpVql2zQJifkl%2BteR57LTZG7W2lbENV",
        "https://vtbehaviour.commondatastorage.googleapis.com/00695c0012a8ebc08469eb0d32d3974ae70e93d129015dbfe6da128556ab3726_VirusTotal%20Box%20of%20Apples.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775529758&Signature=zXDmSolL1BXRVntoMjKFPJaZtQ0tI1lf56M%2BqCFh1c0JirSCS7DGBgxMdHuaZG8hsB%2FV1nO0JEfDegHE1Ibm55QO9TriIg9yCH6dZSsofTmiHiBOUZtTMSH1Pg1z%2FnuElFFvVDHQ2Ryhog0fw%2BwfS0Fpe5ZOoTF8KK883iH45dmOAcVEphu7K5A%2FrzfFG93bFibxA7MRKbLLGBbrIVz4yFSuuFHimac0dVn%"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 158,
        "FileHash-SHA1": 158,
        "FileHash-SHA256": 1127,
        "URL": 116,
        "hostname": 49,
        "domain": 182,
        "email": 1
      },
      "indicator_count": 1791,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d4569dc87656b4a255a124",
      "name": "VirusTotal report\n                    for download.rar",
      "description": "0347ed7f6728c494128d5cde9e4effdc2bcc8f944d78bca8d, as well as 1.3m2.",
      "modified": "2026-05-07T00:00:42.275000",
      "created": "2026-04-07T00:58:05.842000",
      "tags": [
        "json text",
        "json"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 281,
        "FileHash-SHA1": 277,
        "FileHash-SHA256": 2208,
        "URL": 113,
        "domain": 169,
        "hostname": 75
      },
      "indicator_count": 3123,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d4569a944adf94a75efcf9",
      "name": "VirusTotal report\n                    for download.rar",
      "description": "0347ed7f6728c494128d5cde9e4effdc2bcc8f944d78bca8d, as well as 1.3m2.",
      "modified": "2026-05-07T00:00:42.275000",
      "created": "2026-04-07T00:58:02.158000",
      "tags": [
        "json text",
        "json"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 287,
        "FileHash-SHA1": 283,
        "FileHash-SHA256": 2301,
        "URL": 113,
        "domain": 169,
        "hostname": 75
      },
      "indicator_count": 3228,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d4510870e9906d58e7a554",
      "name": "CAPE Sandbox -y2k",
      "description": "> full text of the full report on this year's EU Referendum, which will take place on 26 May 2017, has been published by BBC Radio 5 live in the UK and Ireland.>y2k status",
      "modified": "2026-05-07T00:00:42.275000",
      "created": "2026-04-07T00:34:16.928000",
      "tags": [
        "html document",
        "ascii text",
        "language"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 310,
        "FileHash-SHA1": 308,
        "FileHash-SHA256": 1270,
        "domain": 168,
        "hostname": 31,
        "URL": 98
      },
      "indicator_count": 2185,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d45107d82d67453e8ade06",
      "name": "CAPE Sandbox -y2k",
      "description": "> full text of the full report on this year's EU Referendum, which will take place on 26 May 2017, has been published by BBC Radio 5 live in the UK and Ireland.>y2k status",
      "modified": "2026-05-07T00:00:42.275000",
      "created": "2026-04-07T00:34:15.789000",
      "tags": [
        "html document",
        "ascii text",
        "language"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 310,
        "FileHash-SHA1": 308,
        "FileHash-SHA256": 1270,
        "domain": 168,
        "hostname": 31,
        "URL": 98
      },
      "indicator_count": 2185,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d4510678007ab57751a513",
      "name": "CAPE Sandbox -y2k",
      "description": "> full text of the full report on this year's EU Referendum, which will take place on 26 May 2017, has been published by BBC Radio 5 live in the UK and Ireland.>y2k status",
      "modified": "2026-05-07T00:00:42.275000",
      "created": "2026-04-07T00:34:14.009000",
      "tags": [
        "html document",
        "ascii text",
        "language"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 310,
        "FileHash-SHA1": 308,
        "FileHash-SHA256": 1270,
        "domain": 168,
        "hostname": 31,
        "URL": 98
      },
      "indicator_count": 2185,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d45104133846ffc6b2a6fe",
      "name": "CAPE Sandbox -y2k",
      "description": "> full text of the full report on this year's EU Referendum, which will take place on 26 May 2017, has been published by BBC Radio 5 live in the UK and Ireland.>y2k status",
      "modified": "2026-05-07T00:00:42.275000",
      "created": "2026-04-07T00:34:12.507000",
      "tags": [
        "html document",
        "ascii text",
        "language"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 310,
        "FileHash-SHA1": 308,
        "FileHash-SHA256": 1270,
        "domain": 168,
        "hostname": 31,
        "URL": 98
      },
      "indicator_count": 2185,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65eea19a23474b8c7dca351f",
      "name": "All Items - find from the UA archive disk",
      "description": "Again have zero idea 'what these are' - just uploading from the 'archives' as I sort through things",
      "modified": "2025-12-24T08:28:47.628000",
      "created": "2024-03-11T06:15:54.351000",
      "tags": [],
      "references": [
        "https://www.virustotal.com/gui/collection/09af9ef0b7b23d2dc73d83858106ae4fc97a352dbb521ac04493a0e79095ac69/iocs",
        "https://www.virustotal.com/gui/collection/79c25168b2f93d9730a56b8d2b834cbfb2752b63b21b9dd51109416fbaa676d8/iocs",
        "https://www.virustotal.com/graph/embed/g8726609a12794ebeb59edd531961a233068149bcdf994b428f20141be6111551?theme=dark",
        "https://www.virustotal.com/graph/embed/g365a82115f934e31a69118715695c91c231f66cda9084c9389e56afb985a243e?theme=dark",
        "",
        "https://www.virustotal.com/gui/collection/6a8d582df4fe5a29885dad4074236bc9e4ed445aaf0cc00702d45963fb0459bb/iocs"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1165,
        "hostname": 866,
        "URL": 657,
        "FileHash-SHA256": 26,
        "email": 337,
        "FileHash-MD5": 12,
        "FileHash-SHA1": 8,
        "CIDR": 1
      },
      "indicator_count": 3072,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 129,
      "modified_text": "160 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "665c44f012d938d1c7dd591e",
      "name": "PIT Projekt.exe (www.pitprojekt.pl , pitprojekt.pl)  oraz  Ceidg.gov.pl - Dane publiczne wpisu",
      "description": "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=f3ee4c4e-e009-4d69-82da-eef3bad1ecc4   NIP:6161230754\nhttps://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=7a025cc6-5167-43cf-947f-387a3b830778               NIP;6112323510\nhttp://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=7a025cc6-5167-43cf-947f-387a3b830778\n2.16.6.145146f05-9aac-4942-a42d-f2550a19c0c4              NIP:6131434311\nipv4: 2.16.6.14, 2.16.6.6, 2.16.6.1,",
      "modified": "2025-10-06T11:12:39.639000",
      "created": "2024-06-02T10:09:52.601000",
      "tags": [
        "ceidg.gov.pl - centralna ewidencja i informacja o dzia\u0142alno\u015bci g",
        "prosz czeka",
        "pobierz plik",
        "wojcieszyce",
        "urls competing",
        "ceidg centralna",
        "gospodarczej",
        "wyszukiwanie",
        "przejd",
        "centrum pomocy",
        "informacja o",
        "mapa",
        "strona gwna",
        "przegldanie",
        "ceidg szybki",
        "uwagi prawne",
        "deklaracja",
        "serwer",
        "returnurl",
        "idf3ee4c4ee00",
        "id7a025cc6516",
        "wctxrm0",
        "idf3ee4c4",
        "id35146f059aa",
        "ideb8f4cf26ef",
        "id7a025cc",
        "id35146f0",
        "publicznywsz3",
        "id97c275c",
        "url wiek",
        "ssdeep",
        "sha1",
        "pehasz",
        "typlibid",
        "pit projekt",
        "chcesz",
        "pity online",
        "program",
        "interesuje ci",
        "pity zapisane",
        "jeli",
        "oddajemy w",
        "twoje rce",
        "dziki jego"
      ],
      "references": [
        "http://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=7a025cc6-5167-43cf-947f-387a3b830778",
        "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=f3ee4c4e-e009-4d69-82da-eef3bad1ecc4",
        "https://aplikacja.ceidg.gov.pl/CEIDG/GroupMenu.aspx?key=_group_search",
        "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/SearchDetails.aspx?Id=35146f05-9aac-4942-a42d-f2550a19c0c4",
        "http://www.pitprojekt.pl",
        "http://pitprojekt.pl"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Wojcieszyce",
          "display_name": "Wojcieszyce",
          "target": null
        },
        {
          "id": "Serwer",
          "display_name": "Serwer",
          "target": null
        },
        {
          "id": "Serwer A Przed\u0142u\u017cenie sesji #{text}",
          "display_name": "Serwer A Przed\u0142u\u017cenie sesji #{text}",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8271,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1259,
        "URL": 6009,
        "hostname": 3030,
        "FileHash-SHA256": 10233,
        "FileHash-MD5": 2742,
        "FileHash-SHA1": 2348,
        "email": 75,
        "SSLCertFingerprint": 11,
        "YARA": 2,
        "CVE": 13,
        "FileHash-PEHASH": 1,
        "IPv4": 34,
        "IPv6": 6
      },
      "indicator_count": 25763,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 135,
      "modified_text": "238 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "jsperf.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "jsperf.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780397786.591125
}