{
  "type": "Domain",
  "indicator": "kill.call",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/kill.call",
    "alexa": "http://www.alexa.com/siteinfo/kill.call",
    "indicator": "kill.call",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3193310704,
      "indicator": "kill.call",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "65336ac2b48ca82aeb55aeed",
          "name": "Woodynet.net,Id3.net and me.",
          "description": "The saga continues - But without invoking the jinx I'll focus on the data: Woodynet.net and Id3.net have been my (notso)friendly unoptoutable-dns-resolvers i'm assuming since all of this kicked off now nearing over 1.5+ years ago. I was finally able to dump my iPhone12 in which I had had since this all started and with that really gain some leg and breathing room. But, I'm still being pumped malicious software in the form of ISO's, linux packages, Windows Updates, and so on. And these are the nexus right here. I was able to net a solid bounty from Hybrid-Analysis including 15+ trojans, about 10 different backdoors, and a slew of other collateral that honestly surprised me as Criminalip and OTX weren't wanting to speak the same language in terms of IOC translations from them to the pulse. I'm trying in vain to find the beacon(s) or whatever they're using to keep persistence.",
          "modified": "2024-02-14T21:43:43.324000",
          "created": "2023-10-21T06:08:02.798000",
          "tags": [
            "ip lookup",
            "port check",
            "vulnerability scanner",
            "attack surface",
            "cyber threat intelligence",
            "cti",
            "asm",
            "domain",
            "exploit",
            "phishing",
            "ip address",
            "united",
            "criminal",
            "historical",
            "information",
            "ai spera",
            "search engine",
            "ip search",
            "english english",
            "franais",
            "contact",
            "china",
            "ip location",
            "ip owner",
            "internet",
            "ip locator",
            "remember",
            "dp ip",
            "ip checker",
            "lookup",
            "strong",
            "summary",
            "ip information",
            "pricing login",
            "score",
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "ansi",
            "data",
            "decrypted ssl",
            "windows nt",
            "threat level",
            "runtime data",
            "okserver",
            "date",
            "ffffff",
            "plugin",
            "path",
            "stop",
            "mask",
            "accept",
            "click",
            "prop",
            "error",
            "template",
            "class",
            "core",
            "span",
            "body",
            "suspicious",
            "back",
            "cluster",
            "null",
            "form",
            "zbot",
            "bounce",
            "this",
            "linear",
            "window",
            "ticker",
            "tick",
            "import",
            "orbit",
            "config",
            "main",
            "android",
            "cookie",
            "trident",
            "vidc",
            "hybrid",
            "close",
            "hosts",
            "general",
            "local",
            "mozilla",
            "strings",
            "podcast",
            "team",
            "june",
            "criminal ip",
            "engine",
            "resource",
            "dropped file",
            "pattern match",
            "script",
            "noscript",
            "connectivity",
            "bare metal",
            "iframe",
            "enterprise",
            "discord",
            "twitter",
            "facebook",
            "meta",
            "media",
            "story",
            "tools",
            "tokyo",
            "rocket",
            "fullscreen",
            "next",
            "small",
            "bare",
            "font",
            "helvetica",
            "arial",
            "tbody",
            "dnssec",
            "woodynet",
            "paris",
            "hong",
            "hybrid analysis",
            "api key",
            "vetting process",
            "please note",
            "please"
          ],
          "references": [
            "https://www.criminalip.io/asset/report/69.166.14.38",
            "https://www.criminalip.io/asset/report/114.215.222.125",
            "https://dnschecker.org/ip-location.php?ip=31.204.146.148",
            "https://www.criminalip.io/domain/report?scan_id=8544746",
            "https://hybrid-analysis.com/sample/ab4672795b872e01bc7411fec294eab22d54e97b133769a3de306d9633fa24d6/5efec3f6b03bcb74f200310b",
            "https://www.criminalip.io/images/search/domain/category/icon_page_redirections.svg",
            "https://www.criminalip.io/domain/report?scan_id=8544687",
            "https://hybrid-analysis.com/sample/ab4672795b872e01bc7411fec294eab22d54e97b133769a3de306d9633fa24d6/653366aac5f632cbbf0f0000",
            "https://hybrid-analysis.com/sample/020fe56e2d49ead60b67a1e20b43ee0846c493c7edb3118b34c5c964fc131794/6533667318fa4c29320ec174",
            "https://hybrid-analysis.com/sample/2acab1228e8935d5dfdd1756b8a19698b6c8b786c90f87993ce9799a67a96e4e"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Unknown",
              "display_name": "Unknown",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1035",
              "name": "Service Execution",
              "display_name": "T1035 - Service Execution"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            }
          ],
          "industries": [
            "individuals"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 42,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Merkd1904",
            "id": "196517",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 268,
            "hostname": 50,
            "domain": 61,
            "FileHash-MD5": 112,
            "FileHash-SHA1": 110,
            "FileHash-SHA256": 110,
            "email": 9
          },
          "indicator_count": 720,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 74,
          "modified_text": "838 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6266c416c4598fa139868c64",
          "name": "\u05de\u05e9\u05e8\u05d3 \u05e4\u05e8\u05e1\u05d5\u05dd \u05d5\u05d1\u05e0\u05d9\u05d9\u05ea \u05d0\u05ea\u05e8\u05d9\u05dd | TOPWEB - \u05d8\u05d5\u05e4 \u05d5\u05d5\u05d1- \u05d4\u05d5\u05e4\u05db\u05d9\u05dd \u05e2\u05e1\u05e7\u05d9\u05dd \u05dc\u05de\u05d5\u05ea\u05d2\u05d9\u05dd \u05d1\u05d3\u05d9\u05d2\u05d9\u05d8\u05dc",
          "description": "New RegExp(M) is a new type, and it will change any of the elements to the same type if you want to add them to your HTML page or add a third element.",
          "modified": "2022-05-25T00:04:03.622000",
          "created": "2022-04-25T15:53:58.206000",
          "tags": [
            "init",
            "803911410135716",
            "pageview",
            "date",
            "datalayer",
            "gtmnqnvc6k",
            "copyright",
            "closure library",
            "facebook",
            "google",
            "linkedin",
            "reddit",
            "tumblr",
            "digg",
            "stumbleupon",
            "telegram",
            "whatsapp",
            "email",
            "kfunction",
            "u05deu05dcu05d0",
            "aw363516812",
            "error",
            "promise",
            "inull",
            "webfontconfig",
            "webfont",
            "gc",
            "number",
            "string",
            "uint8array",
            "regexp",
            "xhfunction",
            "yhfunction",
            "host",
            "path",
            "code",
            "topweb",
            "top web",
            "beyond",
            "forex",
            "hackeru",
            "one stop",
            "shop",
            "bgroup",
            "typesubmit",
            "datasecret",
            "shape",
            "html",
            "span",
            "false",
            "scrl",
            "haschildren",
            "zoomindown",
            "show hide",
            "dark",
            "checkbox",
            "back",
            "light",
            "typeof e",
            "formdata",
            "typeof symbol",
            "customevent",
            "post",
            "refill",
            "wpcf7",
            "wpcf7locale",
            "wpcf7unittag",
            "reflect",
            "math",
            "array",
            "object",
            "typeerror",
            "symbol",
            "function",
            "null",
            "title",
            "body",
            "click",
            "lecount",
            "count",
            "typeof define",
            "typeof t",
            "this",
            "close",
            "twitter",
            "open",
            "next",
            "blank",
            "xpercent0",
            "failure",
            "xpercent50",
            "essential grid",
            "blackberry",
            "author",
            "themepunch",
            "android",
            "typeof module",
            "tweenlite",
            "version",
            "onull",
            "updates and",
            "tools",
            "linear",
            "ticker",
            "bounce",
            "alpha",
            "fancybox",
            "plugin",
            "janis skarnelis",
            "100n",
            "right",
            "bottom",
            "left",
            "html tags",
            "ox20trnf",
            "dom element",
            "class",
            "attr",
            "pseudo",
            "child",
            "js foundation",
            "udc66udc67",
            "ud83d",
            "ufe0f",
            "ud83e",
            "udc68udc69",
            "udfcbudfcc",
            "u2640u2642",
            "source",
            "image",
            "ud83dudc6cud83c"
          ],
          "references": [
            "xfe-URL-anyweb.co.il-stix2-2.1-export.json",
            "https://anyweb.co.il/wp-includes/js/wp-emoji-release.min.js?ver=5.7.3",
            "https://anyweb.co.il/wp-includes/js/jquery/jquery.min.js?ver=3.5.1",
            "https://anyweb.co.il/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2",
            "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/lightbox.js?ver=2.0.9.1",
            "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.tools.min.js?ver=2.0.9.1",
            "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.essential.min.js?ver=2.0.9.1",
            "https://anyweb.co.il/wp-content/themes/superfine/assets/js/assets.js?ver=5.7.3",
            "https://anyweb.co.il/wp-content/themes/superfine/assets/js/post-like.min.js?ver=1.0",
            "https://anyweb.co.il/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=7.4.4",
            "https://anyweb.co.il/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4.1",
            "https://anyweb.co.il/wp-content/themes/superfine/assets/js/script.js",
            "https://anyweb.co.il/wp-includes/js/wp-embed.min.js?ver=5.7.3",
            "https://anyweb.co.il/wp-includes/css/dist/block-library/style.min.css?ver=5.7.3",
            "https://topweb.co.il/",
            "https://www.googletagmanager.com/gtm.js?id=GTM-NQNVC6K",
            "https://topweb.co.il/wp-content/plugins/litespeed-cache/assets/js/webfontloader.min.js",
            "https://topweb.co.il/wp-content/litespeed/js/c3a18f91ebd798da3e120a12aec7c615.js?ver=7c615",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/363516812/?random=1650901467024&cv=9&fst=1650901467024&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2oa4k0&sendb=1&ig=1&data=event%3Dgtag.config&frm=0&url=https%3A%2F%2Ftopweb.co.il%2F&tiba=%D7%9E%D7%A9%D7%A8%D7%93%20%D7%A4%D7%A8%D7%A1%D7%95%D7%9D%20%D7%95%D7%91%D7%A0%D7%99%D7%99%D7%AA%20%D7%90%D7%AA%D7%A8%D7%99%D7%9D%20%7C%20TOPWEB%20-%20%D7%98%D"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1158,
            "FileHash-SHA256": 671,
            "hostname": 304,
            "domain": 329,
            "email": 2
          },
          "indicator_count": 2464,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "1468 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.googletagmanager.com/gtm.js?id=GTM-NQNVC6K",
        "https://anyweb.co.il/wp-includes/js/jquery/jquery.min.js?ver=3.5.1",
        "https://anyweb.co.il/wp-includes/js/wp-embed.min.js?ver=5.7.3",
        "https://anyweb.co.il/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4.1",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/script.js",
        "https://anyweb.co.il/wp-includes/css/dist/block-library/style.min.css?ver=5.7.3",
        "https://anyweb.co.il/wp-includes/js/wp-emoji-release.min.js?ver=5.7.3",
        "https://anyweb.co.il/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2",
        "https://dnschecker.org/ip-location.php?ip=31.204.146.148",
        "https://www.criminalip.io/domain/report?scan_id=8544746",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.essential.min.js?ver=2.0.9.1",
        "https://hybrid-analysis.com/sample/ab4672795b872e01bc7411fec294eab22d54e97b133769a3de306d9633fa24d6/5efec3f6b03bcb74f200310b",
        "https://anyweb.co.il/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=7.4.4",
        "https://topweb.co.il/wp-content/plugins/litespeed-cache/assets/js/webfontloader.min.js",
        "https://topweb.co.il/",
        "https://hybrid-analysis.com/sample/ab4672795b872e01bc7411fec294eab22d54e97b133769a3de306d9633fa24d6/653366aac5f632cbbf0f0000",
        "https://www.criminalip.io/images/search/domain/category/icon_page_redirections.svg",
        "https://topweb.co.il/wp-content/litespeed/js/c3a18f91ebd798da3e120a12aec7c615.js?ver=7c615",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/lightbox.js?ver=2.0.9.1",
        "https://www.criminalip.io/domain/report?scan_id=8544687",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/post-like.min.js?ver=1.0",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.tools.min.js?ver=2.0.9.1",
        "https://www.criminalip.io/asset/report/69.166.14.38",
        "https://hybrid-analysis.com/sample/020fe56e2d49ead60b67a1e20b43ee0846c493c7edb3118b34c5c964fc131794/6533667318fa4c29320ec174",
        "https://www.criminalip.io/asset/report/114.215.222.125",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/363516812/?random=1650901467024&cv=9&fst=1650901467024&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2oa4k0&sendb=1&ig=1&data=event%3Dgtag.config&frm=0&url=https%3A%2F%2Ftopweb.co.il%2F&tiba=%D7%9E%D7%A9%D7%A8%D7%93%20%D7%A4%D7%A8%D7%A1%D7%95%D7%9D%20%D7%95%D7%91%D7%A0%D7%99%D7%99%D7%AA%20%D7%90%D7%AA%D7%A8%D7%99%D7%9D%20%7C%20TOPWEB%20-%20%D7%98%D",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/assets.js?ver=5.7.3",
        "xfe-URL-anyweb.co.il-stix2-2.1-export.json",
        "https://hybrid-analysis.com/sample/2acab1228e8935d5dfdd1756b8a19698b6c8b786c90f87993ce9799a67a96e4e"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Gc",
            "Unknown"
          ],
          "industries": [
            "Individuals"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "65336ac2b48ca82aeb55aeed",
      "name": "Woodynet.net,Id3.net and me.",
      "description": "The saga continues - But without invoking the jinx I'll focus on the data: Woodynet.net and Id3.net have been my (notso)friendly unoptoutable-dns-resolvers i'm assuming since all of this kicked off now nearing over 1.5+ years ago. I was finally able to dump my iPhone12 in which I had had since this all started and with that really gain some leg and breathing room. But, I'm still being pumped malicious software in the form of ISO's, linux packages, Windows Updates, and so on. And these are the nexus right here. I was able to net a solid bounty from Hybrid-Analysis including 15+ trojans, about 10 different backdoors, and a slew of other collateral that honestly surprised me as Criminalip and OTX weren't wanting to speak the same language in terms of IOC translations from them to the pulse. I'm trying in vain to find the beacon(s) or whatever they're using to keep persistence.",
      "modified": "2024-02-14T21:43:43.324000",
      "created": "2023-10-21T06:08:02.798000",
      "tags": [
        "ip lookup",
        "port check",
        "vulnerability scanner",
        "attack surface",
        "cyber threat intelligence",
        "cti",
        "asm",
        "domain",
        "exploit",
        "phishing",
        "ip address",
        "united",
        "criminal",
        "historical",
        "information",
        "ai spera",
        "search engine",
        "ip search",
        "english english",
        "franais",
        "contact",
        "china",
        "ip location",
        "ip owner",
        "internet",
        "ip locator",
        "remember",
        "dp ip",
        "ip checker",
        "lookup",
        "strong",
        "summary",
        "ip information",
        "pricing login",
        "score",
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "ansi",
        "data",
        "decrypted ssl",
        "windows nt",
        "threat level",
        "runtime data",
        "okserver",
        "date",
        "ffffff",
        "plugin",
        "path",
        "stop",
        "mask",
        "accept",
        "click",
        "prop",
        "error",
        "template",
        "class",
        "core",
        "span",
        "body",
        "suspicious",
        "back",
        "cluster",
        "null",
        "form",
        "zbot",
        "bounce",
        "this",
        "linear",
        "window",
        "ticker",
        "tick",
        "import",
        "orbit",
        "config",
        "main",
        "android",
        "cookie",
        "trident",
        "vidc",
        "hybrid",
        "close",
        "hosts",
        "general",
        "local",
        "mozilla",
        "strings",
        "podcast",
        "team",
        "june",
        "criminal ip",
        "engine",
        "resource",
        "dropped file",
        "pattern match",
        "script",
        "noscript",
        "connectivity",
        "bare metal",
        "iframe",
        "enterprise",
        "discord",
        "twitter",
        "facebook",
        "meta",
        "media",
        "story",
        "tools",
        "tokyo",
        "rocket",
        "fullscreen",
        "next",
        "small",
        "bare",
        "font",
        "helvetica",
        "arial",
        "tbody",
        "dnssec",
        "woodynet",
        "paris",
        "hong",
        "hybrid analysis",
        "api key",
        "vetting process",
        "please note",
        "please"
      ],
      "references": [
        "https://www.criminalip.io/asset/report/69.166.14.38",
        "https://www.criminalip.io/asset/report/114.215.222.125",
        "https://dnschecker.org/ip-location.php?ip=31.204.146.148",
        "https://www.criminalip.io/domain/report?scan_id=8544746",
        "https://hybrid-analysis.com/sample/ab4672795b872e01bc7411fec294eab22d54e97b133769a3de306d9633fa24d6/5efec3f6b03bcb74f200310b",
        "https://www.criminalip.io/images/search/domain/category/icon_page_redirections.svg",
        "https://www.criminalip.io/domain/report?scan_id=8544687",
        "https://hybrid-analysis.com/sample/ab4672795b872e01bc7411fec294eab22d54e97b133769a3de306d9633fa24d6/653366aac5f632cbbf0f0000",
        "https://hybrid-analysis.com/sample/020fe56e2d49ead60b67a1e20b43ee0846c493c7edb3118b34c5c964fc131794/6533667318fa4c29320ec174",
        "https://hybrid-analysis.com/sample/2acab1228e8935d5dfdd1756b8a19698b6c8b786c90f87993ce9799a67a96e4e"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Unknown",
          "display_name": "Unknown",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1035",
          "name": "Service Execution",
          "display_name": "T1035 - Service Execution"
        },
        {
          "id": "T1043",
          "name": "Commonly Used Port",
          "display_name": "T1043 - Commonly Used Port"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        }
      ],
      "industries": [
        "individuals"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 42,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Merkd1904",
        "id": "196517",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 268,
        "hostname": 50,
        "domain": 61,
        "FileHash-MD5": 112,
        "FileHash-SHA1": 110,
        "FileHash-SHA256": 110,
        "email": 9
      },
      "indicator_count": 720,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 74,
      "modified_text": "838 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6266c416c4598fa139868c64",
      "name": "\u05de\u05e9\u05e8\u05d3 \u05e4\u05e8\u05e1\u05d5\u05dd \u05d5\u05d1\u05e0\u05d9\u05d9\u05ea \u05d0\u05ea\u05e8\u05d9\u05dd | TOPWEB - \u05d8\u05d5\u05e4 \u05d5\u05d5\u05d1- \u05d4\u05d5\u05e4\u05db\u05d9\u05dd \u05e2\u05e1\u05e7\u05d9\u05dd \u05dc\u05de\u05d5\u05ea\u05d2\u05d9\u05dd \u05d1\u05d3\u05d9\u05d2\u05d9\u05d8\u05dc",
      "description": "New RegExp(M) is a new type, and it will change any of the elements to the same type if you want to add them to your HTML page or add a third element.",
      "modified": "2022-05-25T00:04:03.622000",
      "created": "2022-04-25T15:53:58.206000",
      "tags": [
        "init",
        "803911410135716",
        "pageview",
        "date",
        "datalayer",
        "gtmnqnvc6k",
        "copyright",
        "closure library",
        "facebook",
        "google",
        "linkedin",
        "reddit",
        "tumblr",
        "digg",
        "stumbleupon",
        "telegram",
        "whatsapp",
        "email",
        "kfunction",
        "u05deu05dcu05d0",
        "aw363516812",
        "error",
        "promise",
        "inull",
        "webfontconfig",
        "webfont",
        "gc",
        "number",
        "string",
        "uint8array",
        "regexp",
        "xhfunction",
        "yhfunction",
        "host",
        "path",
        "code",
        "topweb",
        "top web",
        "beyond",
        "forex",
        "hackeru",
        "one stop",
        "shop",
        "bgroup",
        "typesubmit",
        "datasecret",
        "shape",
        "html",
        "span",
        "false",
        "scrl",
        "haschildren",
        "zoomindown",
        "show hide",
        "dark",
        "checkbox",
        "back",
        "light",
        "typeof e",
        "formdata",
        "typeof symbol",
        "customevent",
        "post",
        "refill",
        "wpcf7",
        "wpcf7locale",
        "wpcf7unittag",
        "reflect",
        "math",
        "array",
        "object",
        "typeerror",
        "symbol",
        "function",
        "null",
        "title",
        "body",
        "click",
        "lecount",
        "count",
        "typeof define",
        "typeof t",
        "this",
        "close",
        "twitter",
        "open",
        "next",
        "blank",
        "xpercent0",
        "failure",
        "xpercent50",
        "essential grid",
        "blackberry",
        "author",
        "themepunch",
        "android",
        "typeof module",
        "tweenlite",
        "version",
        "onull",
        "updates and",
        "tools",
        "linear",
        "ticker",
        "bounce",
        "alpha",
        "fancybox",
        "plugin",
        "janis skarnelis",
        "100n",
        "right",
        "bottom",
        "left",
        "html tags",
        "ox20trnf",
        "dom element",
        "class",
        "attr",
        "pseudo",
        "child",
        "js foundation",
        "udc66udc67",
        "ud83d",
        "ufe0f",
        "ud83e",
        "udc68udc69",
        "udfcbudfcc",
        "u2640u2642",
        "source",
        "image",
        "ud83dudc6cud83c"
      ],
      "references": [
        "xfe-URL-anyweb.co.il-stix2-2.1-export.json",
        "https://anyweb.co.il/wp-includes/js/wp-emoji-release.min.js?ver=5.7.3",
        "https://anyweb.co.il/wp-includes/js/jquery/jquery.min.js?ver=3.5.1",
        "https://anyweb.co.il/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/lightbox.js?ver=2.0.9.1",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.tools.min.js?ver=2.0.9.1",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.essential.min.js?ver=2.0.9.1",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/assets.js?ver=5.7.3",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/post-like.min.js?ver=1.0",
        "https://anyweb.co.il/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=7.4.4",
        "https://anyweb.co.il/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4.1",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/script.js",
        "https://anyweb.co.il/wp-includes/js/wp-embed.min.js?ver=5.7.3",
        "https://anyweb.co.il/wp-includes/css/dist/block-library/style.min.css?ver=5.7.3",
        "https://topweb.co.il/",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NQNVC6K",
        "https://topweb.co.il/wp-content/plugins/litespeed-cache/assets/js/webfontloader.min.js",
        "https://topweb.co.il/wp-content/litespeed/js/c3a18f91ebd798da3e120a12aec7c615.js?ver=7c615",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/363516812/?random=1650901467024&cv=9&fst=1650901467024&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2oa4k0&sendb=1&ig=1&data=event%3Dgtag.config&frm=0&url=https%3A%2F%2Ftopweb.co.il%2F&tiba=%D7%9E%D7%A9%D7%A8%D7%93%20%D7%A4%D7%A8%D7%A1%D7%95%D7%9D%20%D7%95%D7%91%D7%A0%D7%99%D7%99%D7%AA%20%D7%90%D7%AA%D7%A8%D7%99%D7%9D%20%7C%20TOPWEB%20-%20%D7%98%D"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1158,
        "FileHash-SHA256": 671,
        "hostname": 304,
        "domain": 329,
        "email": 2
      },
      "indicator_count": 2464,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 70,
      "modified_text": "1468 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "kill.call",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "kill.call",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780355056.5258098
}