{
  "type": "Domain",
  "indicator": "layer1.icu",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/layer1.icu",
    "alexa": "http://www.alexa.com/siteinfo/layer1.icu",
    "indicator": "layer1.icu",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4168125797,
      "indicator": "layer1.icu",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "69bbb1e7ff6cad955292ee7f",
          "name": "EbeeMar2026 Pt1",
          "description": "Multiple APT/threat actors, Malware and Campaigns",
          "modified": "2026-04-18T08:06:12.483000",
          "created": "2026-03-19T08:20:55.172000",
          "tags": [
            "filehashmd5",
            "filehashsha256",
            "filehashsha1",
            "computername",
            "date",
            "time",
            "username",
            "generatedbotid",
            "uwhi6jqzqh7",
            "encoded url"
          ],
          "references": [
            "IOCs.2026.1.csv"
          ],
          "public": 1,
          "adversary": "Forbidden Hyena, Fake FileZilla site, TAXISPY RAT, InstallFix, Lone wolf, BoryptGrab",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 58,
            "FileHash-MD5": 262,
            "FileHash-SHA1": 197,
            "FileHash-SHA256": 270,
            "CVE": 6,
            "domain": 58,
            "email": 4,
            "hostname": 52
          },
          "indicator_count": 907,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 40,
          "modified_text": "45 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69afb2f231a2d3c5dc3277e0",
          "name": "IOC - FakeGit: LuaJIT malware distributed via GitHub at scale",
          "description": "A Vietnamese-speaking operator has been distributing LuaJIT-based malware through GitHub since March 2025. The repos impersonate cracked browser extensions for SaaS tools, gaming cheats, developer utilities, and adult content. Each contains a ZIP archive with a LuaJIT loader chain. BitDefender tracks the archives as Gen:Heur.FakeGit.1 (as of March 2026). ESET tracks the Lua payloads as Lua/Agent.Z through Lua/Agent.BT (as of March 2026) -- 16 distinct obfuscator generations across the campaign.",
          "modified": "2026-04-09T05:08:41.771000",
          "created": "2026-03-10T05:58:10.665000",
          "tags": [
            "fakegit",
            "luajit",
            "polygon",
            "ip etherhiding",
            "github",
            "xoraesprocess",
            "token",
            "stealc",
            "sha256 filename",
            "pe crypter",
            "sha256 variant",
            "v2b buyhatke",
            "lua payload",
            "zips",
            "trojanized",
            "wave",
            "stealer",
            "copy",
            "lua"
          ],
          "references": [
            "https://www.derp.ca/research/fakegit-luajit-github-campaign/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lua",
              "display_name": "Lua",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "celestre",
            "id": "295357",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 18,
            "FileHash-SHA1": 18,
            "FileHash-SHA256": 37,
            "email": 1,
            "domain": 1
          },
          "indicator_count": 75,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 141,
          "modified_text": "54 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "691b8869e00b107fa20d9482",
          "name": "ThreatFix",
          "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
          "modified": "2026-01-23T11:01:07.175000",
          "created": "2025-11-17T20:41:11.797000",
          "tags": [
            "",
            "ransomware",
            "malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "",
              "display_name": "",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "zlepos384",
            "id": "103244",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8010,
            "FileHash-SHA1": 7922,
            "FileHash-SHA256": 8893,
            "URL": 57004,
            "domain": 36018,
            "hostname": 96473
          },
          "indicator_count": 214320,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "130 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.derp.ca/research/fakegit-luajit-github-campaign/",
        "IOCs.2026.1.csv"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Forbidden Hyena, Fake FileZilla site, TAXISPY RAT, InstallFix, Lone wolf, BoryptGrab"
          ],
          "malware_families": [
            "",
            "Lua"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "69bbb1e7ff6cad955292ee7f",
      "name": "EbeeMar2026 Pt1",
      "description": "Multiple APT/threat actors, Malware and Campaigns",
      "modified": "2026-04-18T08:06:12.483000",
      "created": "2026-03-19T08:20:55.172000",
      "tags": [
        "filehashmd5",
        "filehashsha256",
        "filehashsha1",
        "computername",
        "date",
        "time",
        "username",
        "generatedbotid",
        "uwhi6jqzqh7",
        "encoded url"
      ],
      "references": [
        "IOCs.2026.1.csv"
      ],
      "public": 1,
      "adversary": "Forbidden Hyena, Fake FileZilla site, TAXISPY RAT, InstallFix, Lone wolf, BoryptGrab",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "IMEBEEIMFINE",
        "id": "343873",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 58,
        "FileHash-MD5": 262,
        "FileHash-SHA1": 197,
        "FileHash-SHA256": 270,
        "CVE": 6,
        "domain": 58,
        "email": 4,
        "hostname": 52
      },
      "indicator_count": 907,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 40,
      "modified_text": "45 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69afb2f231a2d3c5dc3277e0",
      "name": "IOC - FakeGit: LuaJIT malware distributed via GitHub at scale",
      "description": "A Vietnamese-speaking operator has been distributing LuaJIT-based malware through GitHub since March 2025. The repos impersonate cracked browser extensions for SaaS tools, gaming cheats, developer utilities, and adult content. Each contains a ZIP archive with a LuaJIT loader chain. BitDefender tracks the archives as Gen:Heur.FakeGit.1 (as of March 2026). ESET tracks the Lua payloads as Lua/Agent.Z through Lua/Agent.BT (as of March 2026) -- 16 distinct obfuscator generations across the campaign.",
      "modified": "2026-04-09T05:08:41.771000",
      "created": "2026-03-10T05:58:10.665000",
      "tags": [
        "fakegit",
        "luajit",
        "polygon",
        "ip etherhiding",
        "github",
        "xoraesprocess",
        "token",
        "stealc",
        "sha256 filename",
        "pe crypter",
        "sha256 variant",
        "v2b buyhatke",
        "lua payload",
        "zips",
        "trojanized",
        "wave",
        "stealer",
        "copy",
        "lua"
      ],
      "references": [
        "https://www.derp.ca/research/fakegit-luajit-github-campaign/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Lua",
          "display_name": "Lua",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "celestre",
        "id": "295357",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 18,
        "FileHash-SHA1": 18,
        "FileHash-SHA256": 37,
        "email": 1,
        "domain": 1
      },
      "indicator_count": 75,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 141,
      "modified_text": "54 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "691b8869e00b107fa20d9482",
      "name": "ThreatFix",
      "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
      "modified": "2026-01-23T11:01:07.175000",
      "created": "2025-11-17T20:41:11.797000",
      "tags": [
        "",
        "ransomware",
        "malware"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "",
          "display_name": "",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "zlepos384",
        "id": "103244",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8010,
        "FileHash-SHA1": 7922,
        "FileHash-SHA256": 8893,
        "URL": 57004,
        "domain": 36018,
        "hostname": 96473
      },
      "indicator_count": 214320,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 44,
      "modified_text": "130 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "layer1.icu",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "layer1.icu",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780411871.8303676
}