{
  "type": "Domain",
  "indicator": "layarnusa.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/layarnusa.com",
    "alexa": "http://www.alexa.com/siteinfo/layarnusa.com",
    "indicator": "layarnusa.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4018732947,
      "indicator": "layarnusa.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "6891980740656e8b21b31d0a",
          "name": "Tracker | Mirai | Virtool | Tofsee | Phishing +",
          "description": "Tracker found in \u2018alleged \u2018 Jefferson County, Co website also a single link was found in a collection of phishing websites by a OTX researcher in 2023. \nI can\u2019t comment much. \n#overreach\n#https://reviewable.io/reviews/palantir/godel-conjure-plugin/549",
          "modified": "2025-09-04T05:03:13.563000",
          "created": "2025-08-05T05:35:03.786000",
          "tags": [
            "url https",
            "passive dns",
            "urls",
            "url add",
            "pulse pulses",
            "http",
            "hostname",
            "files domain",
            "files related",
            "pulses none",
            "related tags",
            "date",
            "for privacy",
            "redacted for",
            "status",
            "hostname add",
            "pulse submit",
            "url analysis",
            "files",
            "united",
            "entries",
            "search",
            "unknown aaaa",
            "overview ip",
            "address",
            "location united",
            "asn as35916",
            "whois registrar",
            "showing",
            "next associated",
            "meta http",
            "content",
            "index",
            "th th",
            "443 ma2592000",
            "body",
            "ip address",
            "asn as54113",
            "name servers",
            "expiration date",
            "resources whois",
            "urlvoid",
            "related",
            "comments",
            "whois show",
            "present jun",
            "script urls",
            "enom",
            "record value",
            "certificate",
            "formbook cnc",
            "checkin",
            "neue",
            "ipv4",
            "exploit",
            "trojan",
            "virtool",
            "ransom",
            "win32",
            "ipv4 add",
            "unknown cname",
            "unknown ns",
            "script domains",
            "meta",
            "config",
            "associated urls",
            "show",
            "date checked",
            "url hostname",
            "server response",
            "google safe",
            "results jul",
            "next http",
            "present may",
            "present oct",
            "present jul",
            "aaaa",
            "present sep",
            "domain",
            "creation date",
            "expiration",
            "url http",
            "present dec",
            "present jan",
            "reverse dns",
            "present mar",
            "present nov",
            "a domains",
            "verdict",
            "files ip",
            "next related",
            "domains show",
            "domain related",
            "cryp",
            "date hash",
            "avast avg",
            "entries related",
            "mtb may",
            "trojandropper",
            "lowfi",
            "gmt cache",
            "sameorigin",
            "files show",
            "none google",
            "safe browsing",
            "death",
            "indicator facts",
            "historical otx",
            "twitter running",
            "open ports",
            "memcommit",
            "medium",
            "read c",
            "post http",
            "delete",
            "windows nt",
            "malware",
            "copy",
            "write",
            "msie",
            "chrome",
            "backdoor",
            "junkpoly",
            "worm"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4488,
            "hostname": 1442,
            "domain": 746,
            "email": 6,
            "FileHash-SHA256": 1122,
            "FileHash-MD5": 345,
            "FileHash-SHA1": 337,
            "CVE": 2
          },
          "indicator_count": 8488,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "269 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6771ee72c1d2d32573a2f1d8",
          "name": "AS45839 Shinjiru Technology Sdn Bhd",
          "description": "",
          "modified": "2025-05-27T19:17:27.186000",
          "created": "2024-12-30T00:50:58.856000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 930,
            "domain": 496,
            "hostname": 308
          },
          "indicator_count": 1734,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 182,
          "modified_text": "368 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "6891980740656e8b21b31d0a",
      "name": "Tracker | Mirai | Virtool | Tofsee | Phishing +",
      "description": "Tracker found in \u2018alleged \u2018 Jefferson County, Co website also a single link was found in a collection of phishing websites by a OTX researcher in 2023. \nI can\u2019t comment much. \n#overreach\n#https://reviewable.io/reviews/palantir/godel-conjure-plugin/549",
      "modified": "2025-09-04T05:03:13.563000",
      "created": "2025-08-05T05:35:03.786000",
      "tags": [
        "url https",
        "passive dns",
        "urls",
        "url add",
        "pulse pulses",
        "http",
        "hostname",
        "files domain",
        "files related",
        "pulses none",
        "related tags",
        "date",
        "for privacy",
        "redacted for",
        "status",
        "hostname add",
        "pulse submit",
        "url analysis",
        "files",
        "united",
        "entries",
        "search",
        "unknown aaaa",
        "overview ip",
        "address",
        "location united",
        "asn as35916",
        "whois registrar",
        "showing",
        "next associated",
        "meta http",
        "content",
        "index",
        "th th",
        "443 ma2592000",
        "body",
        "ip address",
        "asn as54113",
        "name servers",
        "expiration date",
        "resources whois",
        "urlvoid",
        "related",
        "comments",
        "whois show",
        "present jun",
        "script urls",
        "enom",
        "record value",
        "certificate",
        "formbook cnc",
        "checkin",
        "neue",
        "ipv4",
        "exploit",
        "trojan",
        "virtool",
        "ransom",
        "win32",
        "ipv4 add",
        "unknown cname",
        "unknown ns",
        "script domains",
        "meta",
        "config",
        "associated urls",
        "show",
        "date checked",
        "url hostname",
        "server response",
        "google safe",
        "results jul",
        "next http",
        "present may",
        "present oct",
        "present jul",
        "aaaa",
        "present sep",
        "domain",
        "creation date",
        "expiration",
        "url http",
        "present dec",
        "present jan",
        "reverse dns",
        "present mar",
        "present nov",
        "a domains",
        "verdict",
        "files ip",
        "next related",
        "domains show",
        "domain related",
        "cryp",
        "date hash",
        "avast avg",
        "entries related",
        "mtb may",
        "trojandropper",
        "lowfi",
        "gmt cache",
        "sameorigin",
        "files show",
        "none google",
        "safe browsing",
        "death",
        "indicator facts",
        "historical otx",
        "twitter running",
        "open ports",
        "memcommit",
        "medium",
        "read c",
        "post http",
        "delete",
        "windows nt",
        "malware",
        "copy",
        "write",
        "msie",
        "chrome",
        "backdoor",
        "junkpoly",
        "worm"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4488,
        "hostname": 1442,
        "domain": 746,
        "email": 6,
        "FileHash-SHA256": 1122,
        "FileHash-MD5": 345,
        "FileHash-SHA1": 337,
        "CVE": 2
      },
      "indicator_count": 8488,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "269 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6771ee72c1d2d32573a2f1d8",
      "name": "AS45839 Shinjiru Technology Sdn Bhd",
      "description": "",
      "modified": "2025-05-27T19:17:27.186000",
      "created": "2024-12-30T00:50:58.856000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 930,
        "domain": 496,
        "hostname": 308
      },
      "indicator_count": 1734,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 182,
      "modified_text": "368 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "layarnusa.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "layarnusa.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780227012.513161
}