{
  "type": "Domain",
  "indicator": "liveupdt.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/liveupdt.com",
    "alexa": "http://www.alexa.com/siteinfo/liveupdt.com",
    "indicator": "liveupdt.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3300243141,
      "indicator": "liveupdt.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 17,
      "pulses": [
        {
          "id": "69c081afa2bd54a9599b7c07",
          "name": "PhishDestroy \u2014 Active Phishing & Crypto Scam Domains",
          "description": "Real-time feed of phishing, crypto drainer, and scam domains detected by PhishDestroy (phishdestroy.io). Updated hourly. 108K+ domains tracked, 55K+ currently active. Source: github.com/phishdestroy/destroylist",
          "modified": "2026-05-24T00:00:03.049000",
          "created": "2026-03-22T23:56:29.438000",
          "tags": [
            "phishing",
            "crypto",
            "scam",
            "drainer",
            "fraud",
            "blocklist",
            "phishdestroy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 33,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "phishdestroy",
            "id": "348394",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 93266,
            "hostname": 57600
          },
          "indicator_count": 150866,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 99,
          "modified_text": "7 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69c08867316c564ade394c69",
          "name": "PhishDestroy \u2014 Content Active Threats (Live)",
          "description": "Live feed of phishing and crypto scam domains with ACTIVE malicious content from PhishDestroy. These domains are verified to have live phishing/scam pages. Updated hourly. Source: github.com/phishdestroy/destroylist/dns/content_active.json",
          "modified": "2026-05-21T12:06:19.702000",
          "created": "2026-03-23T00:25:09.116000",
          "tags": [
            "phishing",
            "crypto",
            "scam",
            "drainer",
            "fraud",
            "blocklist",
            "phishdestroy",
            "active",
            "content"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "phishdestroy",
            "id": "348394",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 132502,
            "hostname": 66217
          },
          "indicator_count": 198719,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "9 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f83cb0ce73bef5c452bfb0",
          "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
          "description": "",
          "modified": "2026-05-04T06:29:04.332000",
          "created": "2026-05-04T06:29:04.332000",
          "tags": [
            "phishing",
            "crypto",
            "scam",
            "drainer",
            "fraud",
            "blocklist",
            "phishdestroy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "69c081afa2bd54a9599b7c07",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 88564,
            "hostname": 54516
          },
          "indicator_count": 143080,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "26 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f83caf1bef3609f0eb79e2",
          "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
          "description": "",
          "modified": "2026-05-04T06:29:03.120000",
          "created": "2026-05-04T06:29:03.120000",
          "tags": [
            "phishing",
            "crypto",
            "scam",
            "drainer",
            "fraud",
            "blocklist",
            "phishdestroy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "69c081afa2bd54a9599b7c07",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 88564,
            "hostname": 54516
          },
          "indicator_count": 143080,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "26 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f83cac7d6c947de6c080f9",
          "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
          "description": "",
          "modified": "2026-05-04T06:29:00.417000",
          "created": "2026-05-04T06:29:00.417000",
          "tags": [
            "phishing",
            "crypto",
            "scam",
            "drainer",
            "fraud",
            "blocklist",
            "phishdestroy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "69c081afa2bd54a9599b7c07",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 88564,
            "hostname": 54516
          },
          "indicator_count": 143080,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f83cab9769e92b3285a2b4",
          "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
          "description": "",
          "modified": "2026-05-04T06:28:59.770000",
          "created": "2026-05-04T06:28:59.770000",
          "tags": [
            "phishing",
            "crypto",
            "scam",
            "drainer",
            "fraud",
            "blocklist",
            "phishdestroy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "69c081afa2bd54a9599b7c07",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 88564,
            "hostname": 54516
          },
          "indicator_count": 143080,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f83cab7e03b19c5f1078e3",
          "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
          "description": "",
          "modified": "2026-05-04T06:28:59.113000",
          "created": "2026-05-04T06:28:59.113000",
          "tags": [
            "phishing",
            "crypto",
            "scam",
            "drainer",
            "fraud",
            "blocklist",
            "phishdestroy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "69c081afa2bd54a9599b7c07",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 88564,
            "hostname": 54516
          },
          "indicator_count": 143080,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "26 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f83ca9411c8ab5d294a7e2",
          "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
          "description": "",
          "modified": "2026-05-04T06:28:57.479000",
          "created": "2026-05-04T06:28:57.479000",
          "tags": [
            "phishing",
            "crypto",
            "scam",
            "drainer",
            "fraud",
            "blocklist",
            "phishdestroy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "69c081afa2bd54a9599b7c07",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 88564,
            "hostname": 54516
          },
          "indicator_count": 143080,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f83ca77d6c947de6c080f8",
          "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
          "description": "",
          "modified": "2026-05-04T06:28:55.093000",
          "created": "2026-05-04T06:28:55.093000",
          "tags": [
            "phishing",
            "crypto",
            "scam",
            "drainer",
            "fraud",
            "blocklist",
            "phishdestroy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "69c081afa2bd54a9599b7c07",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 88564,
            "hostname": 54516
          },
          "indicator_count": 143080,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "696789e6dcb2731cd68ff7a6",
          "name": "DarkSpectre: Unmasking the Threat Actor Behind 8.8 Million Infected Browsers",
          "description": "Back Koi Research has uncovered a new network of malicious browser extensions connected to a well-funded criminal group that has infected more than 8.8 million users in the past year, and is stealing corporate meeting intelligence.",
          "modified": "2026-02-13T12:01:49.694000",
          "created": "2026-01-14T12:19:48.245000",
          "tags": [
            "darkspectre",
            "zoom stealer",
            "chrome",
            "edge",
            "ghostposter",
            "shadypanda",
            "firefox",
            "javascript",
            "taobao",
            "opera browser",
            "webex",
            "sarah",
            "cluster",
            "baidu",
            "panda",
            "zoom"
          ],
          "references": [
            "https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GhostPoster",
              "display_name": "GhostPoster",
              "target": null
            },
            {
              "id": "Zoom",
              "display_name": "Zoom",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1123",
              "name": "Audio Capture",
              "display_name": "T1123 - Audio Capture"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "SunderSingh",
            "id": "313014",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 16,
            "email": 3,
            "hostname": 4
          },
          "indicator_count": 23,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 0,
          "modified_text": "106 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954f6327327f544a6b3a3a2",
          "name": "DarkSpectre: Unmasking the Threat Actor Behind 8.8 Million Infected Browsers",
          "description": "",
          "modified": "2026-01-30T10:04:07.167000",
          "created": "2025-12-31T10:08:50.720000",
          "tags": [
            "darkspectre",
            "zoom stealer",
            "chrome",
            "edge",
            "ghostposter",
            "shadypanda",
            "javascript",
            "firefox",
            "taobao",
            "opera browser",
            "webex",
            "sarah",
            "cluster",
            "baidu",
            "panda"
          ],
          "references": [
            "https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Jellybean123",
            "id": "359279",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 14,
            "email": 3,
            "hostname": 2
          },
          "indicator_count": 19,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 22,
          "modified_text": "120 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "696c07cab98b34d6bf0aa726",
          "name": "ACTIVIDAD MALICIOSA | Relacionada con Operaci\u00f3n Hidden Plugin 17012026",
          "description": "Operaci\u00f3n Hidden Plugin es una campa\u00f1a de malware de larga duraci\u00f3n y gran escala que ha comprometido a m\u00e1s de 840,000 usuarios mediante la distribuci\u00f3n de extensiones maliciosas para los navegadores Google Chrome, Mozilla Firefox y Microsoft Edge.",
          "modified": "2026-01-17T22:06:37.189000",
          "created": "2026-01-17T22:06:02.204000",
          "tags": [
            "ghostposter",
            "free vpn",
            "javascript",
            "forever",
            "firefox",
            "firefox addons",
            "c server",
            "swap",
            "injection",
            "captcha solver",
            "code",
            "loader",
            "baidu",
            "final",
            "koidex",
            "tcticas mitre",
            "ck ta0002",
            "ta0003",
            "ta0005",
            "ta0007",
            "ta0040",
            "impact tcnicas",
            "mitre att",
            "ck t1622",
            "t1140"
          ],
          "references": [
            "https://darfe.es/ciberwiki/index.php?title=Operaci%C3%B3n_Hidden_Plugin",
            "https://www.virustotal.com/graph/embed/g74949c4476bc482d86c673aed9f5e7aa40cc8be7248a4e5c8c0b83016c3222a6?theme=light"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Koidex",
              "display_name": "Koidex",
              "target": null
            },
            {
              "id": "GhostPoster",
              "display_name": "GhostPoster",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1559",
              "name": "Inter-Process Communication",
              "display_name": "T1559 - Inter-Process Communication"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "esoporteingenieria2020",
            "id": "121604",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_121604/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2,
            "domain": 3,
            "hostname": 2
          },
          "indicator_count": 7,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 266,
          "modified_text": "133 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "696be7d09cba93c20522c114",
          "name": "ACTIVIDAD MALICIOSA | Relacionada con GhostPoster 17012026",
          "description": "GhostPoster es un malware de navegador sofisticado que se distribu\u00eda como una extensi\u00f3n leg\u00edtima, notable por utilizar esteganograf\u00eda para evadir la detecci\u00f3n durante a\u00f1os. Su caracter\u00edstica principal era ocultar su carga \u00fatil maliciosa dentro del archivo de imagen del logotipo (logo.png) de la propia extensi\u00f3n. Al cargarse, el c\u00f3digo leg\u00edtimo de la extensi\u00f3n extra\u00eda y ejecutaba instrucciones ocultas en los datos binarios de esa imagen, un m\u00e9todo que burlaba los an\u00e1lisis de seguridad est\u00e1ticos de las tiendas oficiales de Chrome, Firefox y Edge.",
          "modified": "2026-01-17T19:49:36.701000",
          "created": "2026-01-17T19:49:36.701000",
          "tags": [
            "tcticas ta0001",
            "access ta0005",
            "defense evasion",
            "ta0003",
            "command",
            "control ta0040",
            "impact tcnicas",
            "t1176",
            "t1027",
            "password"
          ],
          "references": [
            "https://darfe.es/ciberwiki/index.php?title=GhostPoster",
            "https://www.virustotal.com/graph/embed/g20860de641ea4389ab972fdd9ae43135b5c2954803f040c781dad8a5bf6151ac?theme=light"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GhostPoster",
              "display_name": "GhostPoster",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1467",
              "name": "Rogue Cellular Base Station",
              "display_name": "T1467 - Rogue Cellular Base Station"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "esoporteingenieria2020",
            "id": "121604",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_121604/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1,
            "hostname": 1
          },
          "indicator_count": 2,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 266,
          "modified_text": "133 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "694220c104a217e5b738c063",
          "name": "The Firefox Extension Attack No One Saw Coming",
          "description": "",
          "modified": "2025-12-17T03:57:08.414000",
          "created": "2025-12-17T03:17:20.999000",
          "tags": [
            "javascript",
            "vpn forever",
            "firefox",
            "ghostposter",
            "firefox addons",
            "c server",
            "wings",
            "free vpn",
            "forever",
            "png file",
            "code",
            "baidu"
          ],
          "references": [
            "https://www.koi.ai/blog/inside-ghostposter-how-a-png-icon-infected-50-000-firefox-browser-users"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CODERED_VTA",
            "id": "349568",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_349568/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2,
            "domain": 3,
            "hostname": 2
          },
          "indicator_count": 7,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 58,
          "modified_text": "164 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64dd9c1d76a7807782a691d3",
          "name": "IOC's found on my pesonal devices; week starting 08/14/23",
          "description": "I had wrapped the majority of the files i'd run since the 14th into the Pulse of the same date, but at over 17k indicators i think it was time to put that one to rest. Obviously time and life allowing my intention is to keep updating and creating more of these as long as i'm kept flush with content. At current i'm pretty damned flush. This is just a preliminary dump of my /tmp folder on Arch. part of the infection chain is process hallowing and then hijacking a program close to the user, with decent call ability to the rest of the system.",
          "modified": "2024-02-14T21:44:02.852000",
          "created": "2023-08-17T04:03:41.985000",
          "tags": [
            "o cloexec",
            "r procversion",
            "cachyos",
            "gnu ld",
            "gnu binutils",
            "microsoft",
            "f lockfd",
            "cygwin",
            "u respfd",
            "procselffd13",
            "procselffd14",
            "x8664",
            "uname",
            "linux",
            "getconf",
            "cpus32",
            "case",
            "m x8664",
            "s linux",
            "x8664 o",
            "z linux",
            "z x8664",
            "replying",
            "timing",
            "successfully",
            "shift",
            "procselffd16",
            "empty",
            "head",
            "dirty",
            "found",
            "splitting",
            "license",
            "index",
            "kill",
            "zfrm",
            "argv"
          ],
          "references": [
            ".ICE-unix",
            ".org.chromium.Chromium.12ZdF3",
            ".vbox-mrkd-ipc",
            "@tmp",
            ".org.chromium.Chromium.T2jdbS",
            ".X11-unix",
            "albert_yt_ynb2tftv",
            "fish.root",
            "20230816_202710-scantemp.b14ff4bc3a",
            "plasma-csd-generator.LTvjbT",
            "pytest-of-mrkd",
            "runtime-root",
            "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-ananicy-cpp.service-U5RKxp",
            ".org.chromium.Chromium.coQnti",
            "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-bluetooth.service-7fh2tg",
            "bauh@mrkd",
            "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-iwd.service-jnpcHR",
            ".org.chromium.Chromium.8GBhMA",
            "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-polkit.service-CfCUQZ",
            "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-systemd-logind.service-Q9OYbj",
            "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-power-profiles-daemon.service-hSCDr7",
            ".org.chromium.Chromium.HMzFxo",
            "Temp-0c3dc677-7d66-4234-b14e-f604605b2d0c",
            "tmp.D4NXyZ3U4J",
            "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-uksmd.service-oAjI9s",
            "Temp-0148ee46-b3e0-4c4b-aa55-b60c6b63eb6f",
            "tmp.ziktUZeKXL",
            "v8-compile-cache-0",
            "tmp90lfbdek",
            "tst-bz26353KOtJVp",
            "v8-compile-cache-1000",
            ".X0-lock",
            "gitstatus.POWERLEVEL9K.1000.6339.1692232717.2.xtrace.log",
            "Temp-4d7e99a7-2d45-4347-a3b6-b64e3ae65e2e",
            "gitstatus.POWERLEVEL9K.1000.6339.1692232717.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.8928.1692232861.2.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.8928.1692232861.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.6339.1692232717.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.6339.1692232717.2.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.9950.1692233029.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.10525.1692233087.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.10291.1692217508.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.9950.1692233029.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.10858.1692217566.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.11926.1692233325.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.11270.1692217597.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.12470.1692233381.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.8928.1692232861.2.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.10858.1692217566.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.11926.1692233325.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.12928.1692233448.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.10525.1692233087.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.13309.1692233456.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.13878.1692218150.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.28823.1692223670.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.12470.1692233381.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.23930.1692220492.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.13878.1692218150.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.28463.1692223667.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.75659.1692225165.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.28463.1692223667.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.78332.1692225277.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.82162.1692225750.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.81737.1692225737.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.75659.1692225165.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.81737.1692225737.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.78332.1692225277.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.82565.1692225764.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.82565.1692225764.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.82162.1692225750.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.83486.1692225808.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.83486.1692225808.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.83038.1692225779.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.83896.1692225820.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.83038.1692225779.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.84305.1692225848.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.84754.1692225891.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.122089.1692235219.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.84305.1692225848.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.154521.1692237692.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.84754.1692225891.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.122089.1692235219.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.155609.1692237756.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.83896.1692225820.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.237594.1692238521.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.154521.1692237692.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.155609.1692237756.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.237594.1692238521.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.240024.1692238828.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.237952.1692238535.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.240024.1692238828.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.241161.1692238939.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.240792.1692238921.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.247194.1692239163.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.237952.1692238535.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.248323.1692239206.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.247194.1692239163.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.253137.1692239505.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.248323.1692239206.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.263981.1692240121.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.253137.1692239505.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.263981.1692240117.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.263981.1692240121.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.267109.1692240136.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.267109.1692240136.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.267109.1692240155.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.267109.1692240155.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.267442.1692240150.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.267442.1692240143.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.263981.1692240117.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.268412.1692240156.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.317097.1692240795.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.267442.1692240150.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.268412.1692240179.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.2586196.1692243336.1.xtrace.log",
            "gitstatus.POWERLEVEL9K.1000.268412.1692240179.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.345673.1692241474.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.2703415.1692243471.1.daemon.log",
            "qtsingleapp-Notifi-4c42-3e8",
            "gitstatus.POWERLEVEL9K.1000.2588447.1692243345.1.xtrace.log",
            "memmemY_2MMv.c",
            "gitstatus.POWERLEVEL9K.1000.2586196.1692243336.1.daemon.log",
            "gitstatus.POWERLEVEL9K.1000.2703415.1692243471.1.xtrace.log",
            "qtsingleapp-Notifi-4c42-3e8-lockfile",
            "stdbool.hcc0B2j.c",
            "strlcatmMvE1V.c",
            "qtsingleapp-Octopi-1d88-3e8-lockfile",
            "strlcpydb8x03.c",
            "stdbool.ht64kj6qw.c",
            "qtsingleapp-Octopi-1d88-3e8",
            "gitstatus.POWERLEVEL9K.1000.267442.1692240143.1.daemon.log",
            "https://hybrid-analysis.com/sample/43b03483bf2b292ebb1b33469ab4b19e2ac84b1c86c0f34f60adab4bc64176b9",
            "https://hybrid-analysis.com/sample/320a60044adeccec22937423e859d2b095e976698133e37a83e019ce08c8bc0c",
            "https://hybrid-analysis.com/file-collection/64dfee6a3329552c91026445",
            "https://hybrid-analysis.com/sample/79e3317a07b12a977f7fda3463779055bbfec748e7fae4c2c1d1cb9bb8e408ca",
            "https://hybrid-analysis.com/sample/8c7c7246468ffeffe01617b597622cd237fa334fb24dc4977fcac398bbe0df80",
            "https://hybrid-analysis.com/sample/79e3317a07b12a977f7fda3463779055bbfec748e7fae4c2c1d1cb9bb8e408ca/64dff1fbeab7dc252b0e56a6",
            "https://www.virustotal.com/gui/file/79e3317a07b12a977f7fda3463779055bbfec748e7fae4c2c1d1cb9bb8e408ca/details",
            "https://otx.alienvault.com/indicator/file/5820da0bbae4f091dc0248e566d8f1076fd81485d1893effa14cdc1dc122f1fd"
          ],
          "public": 1,
          "adversary": "N/A",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "BV:TelegramBot-A\\ [Trj]",
              "display_name": "BV:TelegramBot-A\\ [Trj]",
              "target": null
            },
            {
              "id": "Ransom:Linux/DarkRadiation.A!MTB",
              "display_name": "Ransom:Linux/DarkRadiation.A!MTB",
              "target": "/malware/Ransom:Linux/DarkRadiation.A!MTB"
            },
            {
              "id": "SLF:MamacseMacro.A",
              "display_name": "SLF:MamacseMacro.A",
              "target": null
            },
            {
              "id": "TrojanDownloader:Linux/Morila!MTB",
              "display_name": "TrojanDownloader:Linux/Morila!MTB",
              "target": "/malware/TrojanDownloader:Linux/Morila!MTB"
            },
            {
              "id": "Backdoor:Win32/R2d2.A",
              "display_name": "Backdoor:Win32/R2d2.A",
              "target": "/malware/Backdoor:Win32/R2d2.A"
            },
            {
              "id": "Sf:ShellCode-DZ\\ [Trj]",
              "display_name": "Sf:ShellCode-DZ\\ [Trj]",
              "target": null
            },
            {
              "id": "NETexecutableMicrosoft",
              "display_name": "NETexecutableMicrosoft",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/FakeFlexnet.A",
              "display_name": "TrojanDropper:Win32/FakeFlexnet.A",
              "target": "/malware/TrojanDropper:Win32/FakeFlexnet.A"
            },
            {
              "id": "Delphi",
              "display_name": "Delphi",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "individuals"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 33,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Merkd1904",
            "id": "196517",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 206,
            "domain": 5129,
            "FileHash-MD5": 177,
            "FileHash-SHA1": 114,
            "URL": 646,
            "hostname": 2078,
            "CVE": 412,
            "email": 4
          },
          "indicator_count": 8766,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 82,
          "modified_text": "836 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65709ffcf3ffe737f8cb8dfd",
          "name": "IOC's found on my pesonal devices; week starting 08/14/23",
          "description": "",
          "modified": "2023-12-06T16:23:24.919000",
          "created": "2023-12-06T16:23:24.919000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 103,
            "hostname": 524,
            "domain": 1292,
            "FileHash-SHA256": 95,
            "FileHash-MD5": 54,
            "FileHash-SHA1": 39,
            "URL": 169,
            "email": 1
          },
          "indicator_count": 2277,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62c2a296d3cea258c9f1c2ad",
          "name": "Malicious Sites, PUPs, Malware, Brower Hijackers, Phishing Sites",
          "description": "",
          "modified": "2022-07-04T08:19:34.791000",
          "created": "2022-07-04T08:19:34.791000",
          "tags": [
            "malware",
            "info",
            "pups",
            "phishing sites",
            "am cst",
            "shadowwhisperer",
            "curl",
            "wget"
          ],
          "references": [
            "https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Malware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 44,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 10,
            "FileHash-SHA1": 47,
            "domain": 34626,
            "hostname": 19
          },
          "indicator_count": 34702,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 890,
          "modified_text": "1426 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "gitstatus.POWERLEVEL9K.1000.83896.1692225820.1.daemon.log",
        "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-ananicy-cpp.service-U5RKxp",
        ".X0-lock",
        "qtsingleapp-Notifi-4c42-3e8-lockfile",
        ".vbox-mrkd-ipc",
        "Temp-4d7e99a7-2d45-4347-a3b6-b64e3ae65e2e",
        "gitstatus.POWERLEVEL9K.1000.237952.1692238535.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.10858.1692217566.1.xtrace.log",
        "Temp-0148ee46-b3e0-4c4b-aa55-b60c6b63eb6f",
        "gitstatus.POWERLEVEL9K.1000.84754.1692225891.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.237594.1692238521.1.daemon.log",
        "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-bluetooth.service-7fh2tg",
        "v8-compile-cache-0",
        "gitstatus.POWERLEVEL9K.1000.82162.1692225750.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.75659.1692225165.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.6339.1692232717.2.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.240024.1692238828.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.155609.1692237756.1.daemon.log",
        "https://darfe.es/ciberwiki/index.php?title=GhostPoster",
        "gitstatus.POWERLEVEL9K.1000.267442.1692240143.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.28463.1692223667.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.267109.1692240136.1.daemon.log",
        "https://www.virustotal.com/gui/file/79e3317a07b12a977f7fda3463779055bbfec748e7fae4c2c1d1cb9bb8e408ca/details",
        ".ICE-unix",
        "gitstatus.POWERLEVEL9K.1000.122089.1692235219.1.xtrace.log",
        "fish.root",
        "bauh@mrkd",
        "gitstatus.POWERLEVEL9K.1000.9950.1692233029.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.240792.1692238921.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.241161.1692238939.1.xtrace.log",
        ".org.chromium.Chromium.8GBhMA",
        "gitstatus.POWERLEVEL9K.1000.10291.1692217508.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.10858.1692217566.1.daemon.log",
        ".X11-unix",
        "gitstatus.POWERLEVEL9K.1000.240024.1692238828.1.daemon.log",
        ".org.chromium.Chromium.T2jdbS",
        "https://hybrid-analysis.com/sample/8c7c7246468ffeffe01617b597622cd237fa334fb24dc4977fcac398bbe0df80",
        "https://www.koi.ai/blog/inside-ghostposter-how-a-png-icon-infected-50-000-firefox-browser-users",
        "gitstatus.POWERLEVEL9K.1000.267442.1692240143.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.13878.1692218150.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.317097.1692240795.1.xtrace.log",
        "pytest-of-mrkd",
        "https://darfe.es/ciberwiki/index.php?title=Operaci%C3%B3n_Hidden_Plugin",
        "gitstatus.POWERLEVEL9K.1000.12470.1692233381.1.daemon.log",
        ".org.chromium.Chromium.12ZdF3",
        "gitstatus.POWERLEVEL9K.1000.268412.1692240179.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.263981.1692240121.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.82565.1692225764.1.xtrace.log",
        "https://otx.alienvault.com/indicator/file/5820da0bbae4f091dc0248e566d8f1076fd81485d1893effa14cdc1dc122f1fd",
        "albert_yt_ynb2tftv",
        "gitstatus.POWERLEVEL9K.1000.237952.1692238535.1.daemon.log",
        "tst-bz26353KOtJVp",
        "gitstatus.POWERLEVEL9K.1000.83038.1692225779.1.xtrace.log",
        "tmp.ziktUZeKXL",
        "gitstatus.POWERLEVEL9K.1000.83486.1692225808.1.xtrace.log",
        "tmp90lfbdek",
        "20230816_202710-scantemp.b14ff4bc3a",
        "https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers",
        "gitstatus.POWERLEVEL9K.1000.84754.1692225891.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.83896.1692225820.1.xtrace.log",
        "qtsingleapp-Octopi-1d88-3e8",
        "v8-compile-cache-1000",
        "https://hybrid-analysis.com/file-collection/64dfee6a3329552c91026445",
        "gitstatus.POWERLEVEL9K.1000.122089.1692235219.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.267442.1692240150.1.daemon.log",
        "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-power-profiles-daemon.service-hSCDr7",
        "gitstatus.POWERLEVEL9K.1000.12470.1692233381.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.13878.1692218150.1.daemon.log",
        ".org.chromium.Chromium.HMzFxo",
        "gitstatus.POWERLEVEL9K.1000.8928.1692232861.2.xtrace.log",
        "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-uksmd.service-oAjI9s",
        "gitstatus.POWERLEVEL9K.1000.268412.1692240179.1.xtrace.log",
        "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-iwd.service-jnpcHR",
        "https://www.virustotal.com/graph/embed/g20860de641ea4389ab972fdd9ae43135b5c2954803f040c781dad8a5bf6151ac?theme=light",
        "strlcpydb8x03.c",
        "gitstatus.POWERLEVEL9K.1000.267109.1692240136.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.267109.1692240155.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.82162.1692225750.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.81737.1692225737.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.253137.1692239505.1.daemon.log",
        "qtsingleapp-Octopi-1d88-3e8-lockfile",
        "stdbool.ht64kj6qw.c",
        "gitstatus.POWERLEVEL9K.1000.12928.1692233448.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.253137.1692239505.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.8928.1692232861.2.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.2703415.1692243471.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.11926.1692233325.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.84305.1692225848.1.xtrace.log",
        "runtime-root",
        "gitstatus.POWERLEVEL9K.1000.345673.1692241474.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.267442.1692240150.1.xtrace.log",
        "Temp-0c3dc677-7d66-4234-b14e-f604605b2d0c",
        "gitstatus.POWERLEVEL9K.1000.2588447.1692243345.1.xtrace.log",
        "tmp.D4NXyZ3U4J",
        "https://hybrid-analysis.com/sample/320a60044adeccec22937423e859d2b095e976698133e37a83e019ce08c8bc0c",
        "gitstatus.POWERLEVEL9K.1000.248323.1692239206.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.82565.1692225764.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.81737.1692225737.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.263981.1692240121.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.13309.1692233456.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.2586196.1692243336.1.xtrace.log",
        "memmemY_2MMv.c",
        "https://hybrid-analysis.com/sample/79e3317a07b12a977f7fda3463779055bbfec748e7fae4c2c1d1cb9bb8e408ca/64dff1fbeab7dc252b0e56a6",
        "gitstatus.POWERLEVEL9K.1000.10525.1692233087.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.23930.1692220492.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.78332.1692225277.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.154521.1692237692.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.155609.1692237756.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.263981.1692240117.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.6339.1692232717.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.75659.1692225165.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.267109.1692240155.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.83038.1692225779.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.6339.1692232717.2.daemon.log",
        "plasma-csd-generator.LTvjbT",
        "gitstatus.POWERLEVEL9K.1000.154521.1692237692.1.daemon.log",
        "https://hybrid-analysis.com/sample/79e3317a07b12a977f7fda3463779055bbfec748e7fae4c2c1d1cb9bb8e408ca",
        "gitstatus.POWERLEVEL9K.1000.11926.1692233325.1.xtrace.log",
        "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-polkit.service-CfCUQZ",
        "gitstatus.POWERLEVEL9K.1000.268412.1692240156.1.xtrace.log",
        "qtsingleapp-Notifi-4c42-3e8",
        "gitstatus.POWERLEVEL9K.1000.10525.1692233087.1.xtrace.log",
        "systemd-private-28f1c54986a24a4fa12e1cfe0bb09aa0-systemd-logind.service-Q9OYbj",
        "gitstatus.POWERLEVEL9K.1000.247194.1692239163.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.2586196.1692243336.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.9950.1692233029.1.xtrace.log",
        "@tmp",
        "gitstatus.POWERLEVEL9K.1000.6339.1692232717.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.247194.1692239163.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.237594.1692238521.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.11270.1692217597.1.daemon.log",
        "https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Malware",
        "gitstatus.POWERLEVEL9K.1000.2703415.1692243471.1.xtrace.log",
        "https://hybrid-analysis.com/sample/43b03483bf2b292ebb1b33469ab4b19e2ac84b1c86c0f34f60adab4bc64176b9",
        "gitstatus.POWERLEVEL9K.1000.248323.1692239206.1.xtrace.log",
        ".org.chromium.Chromium.coQnti",
        "gitstatus.POWERLEVEL9K.1000.28823.1692223670.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.8928.1692232861.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.28463.1692223667.1.xtrace.log",
        "https://www.virustotal.com/graph/embed/g74949c4476bc482d86c673aed9f5e7aa40cc8be7248a4e5c8c0b83016c3222a6?theme=light",
        "strlcatmMvE1V.c",
        "gitstatus.POWERLEVEL9K.1000.78332.1692225277.1.xtrace.log",
        "gitstatus.POWERLEVEL9K.1000.263981.1692240117.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.84305.1692225848.1.daemon.log",
        "gitstatus.POWERLEVEL9K.1000.83486.1692225808.1.daemon.log",
        "stdbool.hcc0B2j.c"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "N/A"
          ],
          "malware_families": [
            "Ghostposter",
            "Trojandownloader:linux/morila!mtb",
            "Slf:mamacsemacro.a",
            "Zoom",
            "Ransom:linux/darkradiation.a!mtb",
            "Delphi",
            "Sf:shellcode-dz\\ [trj]",
            "Koidex",
            "Bv:telegrambot-a\\ [trj]",
            "Backdoor:win32/r2d2.a",
            "Netexecutablemicrosoft",
            "Trojandropper:win32/fakeflexnet.a"
          ],
          "industries": [
            "Individuals"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 17,
  "pulses": [
    {
      "id": "69c081afa2bd54a9599b7c07",
      "name": "PhishDestroy \u2014 Active Phishing & Crypto Scam Domains",
      "description": "Real-time feed of phishing, crypto drainer, and scam domains detected by PhishDestroy (phishdestroy.io). Updated hourly. 108K+ domains tracked, 55K+ currently active. Source: github.com/phishdestroy/destroylist",
      "modified": "2026-05-24T00:00:03.049000",
      "created": "2026-03-22T23:56:29.438000",
      "tags": [
        "phishing",
        "crypto",
        "scam",
        "drainer",
        "fraud",
        "blocklist",
        "phishdestroy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 33,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "phishdestroy",
        "id": "348394",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 93266,
        "hostname": 57600
      },
      "indicator_count": 150866,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 99,
      "modified_text": "7 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69c08867316c564ade394c69",
      "name": "PhishDestroy \u2014 Content Active Threats (Live)",
      "description": "Live feed of phishing and crypto scam domains with ACTIVE malicious content from PhishDestroy. These domains are verified to have live phishing/scam pages. Updated hourly. Source: github.com/phishdestroy/destroylist/dns/content_active.json",
      "modified": "2026-05-21T12:06:19.702000",
      "created": "2026-03-23T00:25:09.116000",
      "tags": [
        "phishing",
        "crypto",
        "scam",
        "drainer",
        "fraud",
        "blocklist",
        "phishdestroy",
        "active",
        "content"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "phishdestroy",
        "id": "348394",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 132502,
        "hostname": 66217
      },
      "indicator_count": 198719,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 44,
      "modified_text": "9 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f83cb0ce73bef5c452bfb0",
      "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
      "description": "",
      "modified": "2026-05-04T06:29:04.332000",
      "created": "2026-05-04T06:29:04.332000",
      "tags": [
        "phishing",
        "crypto",
        "scam",
        "drainer",
        "fraud",
        "blocklist",
        "phishdestroy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "69c081afa2bd54a9599b7c07",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 88564,
        "hostname": 54516
      },
      "indicator_count": 143080,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "26 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f83caf1bef3609f0eb79e2",
      "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
      "description": "",
      "modified": "2026-05-04T06:29:03.120000",
      "created": "2026-05-04T06:29:03.120000",
      "tags": [
        "phishing",
        "crypto",
        "scam",
        "drainer",
        "fraud",
        "blocklist",
        "phishdestroy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "69c081afa2bd54a9599b7c07",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 88564,
        "hostname": 54516
      },
      "indicator_count": 143080,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "26 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f83cac7d6c947de6c080f9",
      "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
      "description": "",
      "modified": "2026-05-04T06:29:00.417000",
      "created": "2026-05-04T06:29:00.417000",
      "tags": [
        "phishing",
        "crypto",
        "scam",
        "drainer",
        "fraud",
        "blocklist",
        "phishdestroy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "69c081afa2bd54a9599b7c07",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 88564,
        "hostname": 54516
      },
      "indicator_count": 143080,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f83cab9769e92b3285a2b4",
      "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
      "description": "",
      "modified": "2026-05-04T06:28:59.770000",
      "created": "2026-05-04T06:28:59.770000",
      "tags": [
        "phishing",
        "crypto",
        "scam",
        "drainer",
        "fraud",
        "blocklist",
        "phishdestroy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "69c081afa2bd54a9599b7c07",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 88564,
        "hostname": 54516
      },
      "indicator_count": 143080,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f83cab7e03b19c5f1078e3",
      "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
      "description": "",
      "modified": "2026-05-04T06:28:59.113000",
      "created": "2026-05-04T06:28:59.113000",
      "tags": [
        "phishing",
        "crypto",
        "scam",
        "drainer",
        "fraud",
        "blocklist",
        "phishdestroy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "69c081afa2bd54a9599b7c07",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 88564,
        "hostname": 54516
      },
      "indicator_count": 143080,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "26 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f83ca9411c8ab5d294a7e2",
      "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
      "description": "",
      "modified": "2026-05-04T06:28:57.479000",
      "created": "2026-05-04T06:28:57.479000",
      "tags": [
        "phishing",
        "crypto",
        "scam",
        "drainer",
        "fraud",
        "blocklist",
        "phishdestroy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "69c081afa2bd54a9599b7c07",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 88564,
        "hostname": 54516
      },
      "indicator_count": 143080,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f83ca77d6c947de6c080f8",
      "name": "Credit: PhishDestroy Clone [\"phish detroy- open domains\"]",
      "description": "",
      "modified": "2026-05-04T06:28:55.093000",
      "created": "2026-05-04T06:28:55.093000",
      "tags": [
        "phishing",
        "crypto",
        "scam",
        "drainer",
        "fraud",
        "blocklist",
        "phishdestroy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "69c081afa2bd54a9599b7c07",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 88564,
        "hostname": 54516
      },
      "indicator_count": 143080,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "696789e6dcb2731cd68ff7a6",
      "name": "DarkSpectre: Unmasking the Threat Actor Behind 8.8 Million Infected Browsers",
      "description": "Back Koi Research has uncovered a new network of malicious browser extensions connected to a well-funded criminal group that has infected more than 8.8 million users in the past year, and is stealing corporate meeting intelligence.",
      "modified": "2026-02-13T12:01:49.694000",
      "created": "2026-01-14T12:19:48.245000",
      "tags": [
        "darkspectre",
        "zoom stealer",
        "chrome",
        "edge",
        "ghostposter",
        "shadypanda",
        "firefox",
        "javascript",
        "taobao",
        "opera browser",
        "webex",
        "sarah",
        "cluster",
        "baidu",
        "panda",
        "zoom"
      ],
      "references": [
        "https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "GhostPoster",
          "display_name": "GhostPoster",
          "target": null
        },
        {
          "id": "Zoom",
          "display_name": "Zoom",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1123",
          "name": "Audio Capture",
          "display_name": "T1123 - Audio Capture"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "SunderSingh",
        "id": "313014",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 16,
        "email": 3,
        "hostname": 4
      },
      "indicator_count": 23,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 0,
      "modified_text": "106 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "liveupdt.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "liveupdt.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780192692.4254785
}