{
  "type": "Domain",
  "indicator": "lyrytun.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/lyrytun.com",
    "alexa": "http://www.alexa.com/siteinfo/lyrytun.com",
    "indicator": "lyrytun.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 144246880,
      "indicator": "lyrytun.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 40,
      "pulses": [
        {
          "id": "63456c2a30b92337ea1670e0",
          "name": "IOC Records Provided by @NextRayAI",
          "description": "This IOC report provided and daily updated by NextRay AI Detection & Response Inc.",
          "modified": "2026-06-01T00:38:49.108000",
          "created": "2022-10-11T13:14:18.676000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1330,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "NextRay-AI",
            "id": "210822",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_210822/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 498917,
            "IPv4": 64327,
            "IPv6": 459,
            "hostname": 59385,
            "URL": 166783,
            "CIDR": 5266,
            "FileHash-MD5": 29699,
            "FileHash-SHA256": 50449,
            "CVE": 348,
            "email": 914,
            "Mutex": 49,
            "FileHash-SHA1": 3453,
            "FilePath": 34
          },
          "indicator_count": 880083,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 301,
          "modified_text": "23 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "688c8526be7a4df33863b5c5",
          "name": "VirusTotal - Shiz.ivr",
          "description": "*Win.Trojan.Shiz.ivr\n*PWS:Win32/Simda.D\n*virtool #injection#infostealer #network #cnc #block_not #virustotal_google #cnc #checking #procmem_yara\n#injection_inter_process\n#injection_create_remote_thread\n#antidebug_windows\n#multiple_useragents\n#network_fake_useragent\n#persistence_autorun\n#cape_detected_threat\n#antiav_detectfile\n#modify_proxy\n#deletes_self\n#infostealer_cookies\n#injection_createremotethread\n#suricata_alert\n~ vashti",
          "modified": "2025-08-31T08:01:04.297000",
          "created": "2025-08-01T09:13:10.510000",
          "tags": [
            "dynamicloader",
            "unknown",
            "msie",
            "windows nt",
            "slcc2",
            "media center",
            "suspicious",
            "search",
            "high",
            "show",
            "copy",
            "possible",
            "write",
            "internal",
            "malware",
            "push",
            "local",
            "next",
            "contacted",
            "domains",
            "pulses",
            "related tags",
            "file type",
            "date april",
            "pm size",
            "sha1 sha256",
            "imphash pehash",
            "virustotal api",
            "bq jul",
            "united",
            "trojan",
            "backdoor",
            "virtool",
            "cnc beacon",
            "entries",
            "path max",
            "passive dns",
            "next associated",
            "cookie",
            "twitter",
            "body",
            "date",
            "medium",
            "simda",
            "global"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 10303,
            "hostname": 1413,
            "FileHash-SHA256": 1868,
            "domain": 1877,
            "FileHash-MD5": 357,
            "FileHash-SHA1": 348,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 16168,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 149,
          "modified_text": "274 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "5daf09a6d16f1e2c5c594c22",
          "name": "Simda - Malware Domain Feed V2",
          "description": "Command and Control domains for malware known as Simda. These domains are extracted from malware sandbox reports using                             a Machine Learning model trained on a corpus of good and bad domains.",
          "modified": "2025-07-15T21:13:57.066000",
          "created": "2019-10-22T13:52:38.770000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 33,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "otxrobottwo",
            "id": "78495",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_78495/resized/80/avatar_ba5a8acdbd.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 209,
            "hostname": 5
          },
          "indicator_count": 214,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1085,
          "modified_text": "321 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67fb185eb96e9791cf24ced4",
          "name": "Shiz/Packy",
          "description": "",
          "modified": "2025-05-13T01:03:15.390000",
          "created": "2025-04-13T01:50:22.707000",
          "tags": [],
          "references": [
            "https://www.virustotal.com/graph/gf9fb2090ae8e450dadda45c0596ab774ed1984e89aab4679bc3fc02096e22fa3"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 26,
            "URL": 191,
            "domain": 344,
            "hostname": 2
          },
          "indicator_count": 563,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 184,
          "modified_text": "384 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a4293d5bc5c915eac829e0",
          "name": "Ransom:Win32/Crowti.A : Android Windows | Win.Trojan.Simda CnC",
          "description": "",
          "modified": "2024-08-25T21:00:52.039000",
          "created": "2024-07-26T22:54:53.598000",
          "tags": [
            "united",
            "unknown",
            "a domains",
            "accept",
            "link",
            "passive dns",
            "encrypt",
            "trmp",
            "ok server",
            "date",
            "meta",
            "whois lookup",
            "create date",
            "domain",
            "expiry date",
            "update date",
            "update",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr10",
            "validity",
            "public key",
            "info",
            "key algorithm",
            "dns replication",
            "subdomains",
            "first",
            "historical ssl",
            "record type",
            "ttl value",
            "cname",
            "certificates",
            "show",
            "entries",
            "yara rule",
            "delete",
            "search",
            "intel",
            "ms windows",
            "copy",
            "binary file",
            "get updates",
            "write",
            "as44273 host",
            "redacted for",
            "moved",
            "record value",
            "as54113",
            "body",
            "scan endpoints",
            "all scoreblue",
            "pulse submit",
            "url analysis",
            "urls",
            "files",
            "ip address",
            "files ip",
            "address domain",
            "as61969 team",
            "germany unknown",
            "msie",
            "chrome",
            "precondition",
            "gmt content",
            "united kingdom",
            "as396982 google",
            "as8075",
            "ireland unknown",
            "as21301",
            "aaaa",
            "status",
            "sha1",
            "windows nt",
            "sha256",
            "size",
            "ascii text",
            "pattern match",
            "mitre att",
            "ck id",
            "show technique",
            "span",
            "format",
            "click",
            "hybrid",
            "twitter",
            "generator",
            "tsvt",
            "strings",
            "download",
            "path",
            "contact",
            "suspicious",
            "invalid url",
            "open ports",
            "body html",
            "head title",
            "title head",
            "body h1",
            "reference",
            "bad request",
            "server",
            "version",
            "trojandropper",
            "ransom",
            "checkin",
            "ipv4",
            "trojan",
            "virtool",
            "http post",
            "theme directory",
            "without referer",
            "cycbot",
            "http response",
            "final url",
            "status code",
            "body length",
            "kb body",
            "headers server",
            "gmt etag",
            "gmt date",
            "referrer",
            "code signing",
            "serial number",
            "ca valid",
            "from",
            "valid",
            "valid usage",
            "verisign time",
            "stamping",
            "thumbprint",
            "class",
            "error",
            "info header",
            "name md5",
            "type",
            "language",
            "contained",
            "overlay",
            "gandi sas",
            "dynadot",
            "registrar",
            "dynadot inc",
            "cloudflare",
            "net technology",
            "corporation",
            "bigrock",
            "dynadot llc",
            "namecheap",
            "ip detections",
            "country",
            "contacted",
            "defense evasion",
            "access ta0006",
            "ta0009 command",
            "control ta0011",
            "impact ta0034",
            "impact ta0040",
            "ta0040",
            "samplepath",
            "pattern urls",
            "pattern domains",
            "memory pattern",
            "domains domain",
            "ip traffic",
            "typo squatting",
            "realteck audio",
            "phish",
            "mr windows",
            "partru",
            "goog mal",
            "android windows",
            "maze",
            "apple",
            "malware",
            "worm",
            "skynet",
            "microsoft",
            "trojan evader",
            "simda cnc",
            "showing",
            "filehash",
            "pulse pulses",
            "av detections",
            "ids detections",
            "delphi",
            "network",
            "crowdstrike"
          ],
          "references": [
            "43.204.54.95 AS 16509 (AMAZON-02), http://r10.i.lencr.org/, www.maketrumppresidentagain.site",
            "trojan.shiz/razy: FileHash-SHA256 02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8",
            "trojan.shiz/razy | CS Sigma: Matches rule System File Execution Location Anomaly by Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Benche",
            "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst",
            "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
            "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
            "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
            "trojan.shiz/razy | CS IDS: Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
            "trojan.shiz/razy | Capabilities Collection Log keystrokes via polling",
            "https://www.virustotal.com/gui/file/02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8/detection",
            "https://otx.alienvault.com/indicator/file/e6f8e2706058064d8f38d12923e52cec7a128218b39ca1fe60a2dde7ac3d158f | binary_yara mpress_2_xx_x86",
            "Ransom:Win32/Crowti.A: FileHash-SHA256 1ffa6a3f8844b5955fc5e7329a6fb766cc1f35b39201ceaf0bca282b5b0b8cf6",
            "Ransom:Win32/Crowti.A: FileHash-MD5 d34cf3663902900ddf46b937449472b9",
            "Ransom:Win32/Crowti.A: FileHash-SHA1 05a49b7502099932ff628ca5a8583397b7e2dca2",
            "VirTool:Win32/Injector: FileHash-SHA256 0806653f8af2e9c2530e453f8b1fea47f62f86b5b0b65487ddcfd014eea8e9fe",
            "VirTool:Win32/Injector: FileHash-MD5 baa1a920d33eee94e123f5dfb6bbe7456692e020d682ae45f0de66130f9ea0da",
            "VirTool:Win32/Injector: FileHash-SHA1 3e7124373729e9ec90ea1d01222bfdd84b0484e5",
            "BigRock: gadyzyh.com",
            "Matches rule ET INFO Namecheap URL",
            "POLICY Unsupported/Fake Internet Explorer Version MSIE 2",
            "Win.Trojan.Simda: FileHash-SHA256 0187e1392266fff224de9e3d3fbbe1a05cea8b823906ad27ff577c6e348f6e3b",
            "Win.Trojan.Simda: FileHash-SHA1 fec01e5e59034cafc2b1e95c23068e075f9dbe69",
            "Win.Trojan.Simda: FileHash-MD5 efe12fc770fb8647e22adb7f814666e7",
            "TEL:Win32/Qjwmonkey.A: FileHash-SHA256 30ffb056ad64037a918d80c120db5d0032b29feb7db97ed19824646381165a5d",
            "TEL:Win32/Qjwmonkey.A: FileHash-SHA1 51efdae4ba6bfec8e6f4ae2d7f6dc8cca42db1da",
            "TEL:Win32/Qjwmonkey.A: FileHash-MD5 535ce96e43fe532e1ddfd804dbde9c6a",
            "Matches rule Files With System Process Name In Unsuspected Locations by Sander Wiebing, Tim Shelton, Nasreddine Bencherch",
            "Matches rule Windows Processes Suspicious Parent Directory by vburov"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Australia",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "TrojanDownloader:Win32/Upatre.E",
              "display_name": "TrojanDownloader:Win32/Upatre.E",
              "target": "/malware/TrojanDownloader:Win32/Upatre.E"
            },
            {
              "id": "Ransom:Win32/Crowti.A",
              "display_name": "Ransom:Win32/Crowti.A",
              "target": "/malware/Ransom:Win32/Crowti.A"
            },
            {
              "id": "Cycbot",
              "display_name": "Cycbot",
              "target": null
            },
            {
              "id": "VirTool:Win32/Injector",
              "display_name": "VirTool:Win32/Injector",
              "target": "/malware/VirTool:Win32/Injector"
            },
            {
              "id": "Win.Trojan.Simda",
              "display_name": "Win.Trojan.Simda",
              "target": null
            },
            {
              "id": "TEL:Win32/Qjwmonkey.A",
              "display_name": "TEL:Win32/Qjwmonkey.A",
              "target": "/malware/TEL:Win32/Qjwmonkey.A"
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0008",
              "name": "Lateral Movement",
              "display_name": "TA0008 - Lateral Movement"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 549,
            "domain": 1182,
            "hostname": 590,
            "URL": 961,
            "FileHash-SHA256": 2466,
            "FileHash-MD5": 562,
            "SSLCertFingerprint": 7,
            "email": 4
          },
          "indicator_count": 6321,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "645 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d3acf32e1088e76165a307",
          "name": "Locky: File Deletion targeting incriminating archived files.",
          "description": "",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T19:33:07.504000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65d34c91868744aa1449fef2",
          "export_count": 64,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 234,
          "modified_text": "803 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d34c8a64436a7aee2e25a1",
          "name": "Locky: File Deletion targeting incriminating archived files.",
          "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T12:41:46.707000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 65,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "803 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d34c91868744aa1449fef2",
          "name": "Locky: File Deletion targeting incriminating archived files.",
          "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T12:41:52.846000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 57,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "803 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d3c31230455f6d8da3a9f0",
          "name": "Locky: File Deletion targeting incriminating archived files II",
          "description": "",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T21:07:30.887000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65d34c8a64436a7aee2e25a1",
          "export_count": 73,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Enqrypted",
            "id": "272105",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_272105/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 62,
          "modified_text": "803 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65f5828f8217ecbe6ce3a89b",
          "name": "IOCs Industriales",
          "description": "",
          "modified": "2024-03-16T11:29:19.302000",
          "created": "2024-03-16T11:29:19.302000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 81,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dtatov00",
            "id": "256758",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "807 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65f5827a4e23b095e5af5f44",
          "name": "IOCs Industriales",
          "description": "",
          "modified": "2024-03-16T11:28:58.984000",
          "created": "2024-03-16T11:28:58.984000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dtatov00",
            "id": "256758",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 50,
          "modified_text": "807 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65f582700d35b0e7c8dd9df8",
          "name": "IOCs Industriales",
          "description": "",
          "modified": "2024-03-16T11:28:48.062000",
          "created": "2024-03-16T11:28:48.062000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dtatov00",
            "id": "256758",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 50,
          "modified_text": "807 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65f5823b9d7bc6b422256296",
          "name": "IOCs Industriales",
          "description": "",
          "modified": "2024-03-16T11:27:55.808000",
          "created": "2024-03-16T11:27:55.808000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dtatov00",
            "id": "256758",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 45,
          "modified_text": "807 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "658449d3f6ec1af2f3aace46",
          "name": "Qakbot | Reddit",
          "description": "Qbot URL: https://seedbeej.pk/tin/index.php?QBOT.zip Qbot zip found in Reddit Honeypot link: https://www.reddit.com/user backdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork with many capabilities, attack methods and demands. An unsuspecting victim always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware  malvertizing, fraud services, leads to full control of badly compromised digital profile.",
          "modified": "2024-01-20T02:02:19.559000",
          "created": "2023-12-21T14:21:07.435000",
          "tags": [
            "ssl certificate",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "threat",
            "paste",
            "blacklist https",
            "qakbot",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "ascii text",
            "pattern match",
            "file",
            "windows nt",
            "appdata",
            "indicator",
            "crlf line",
            "unicode text",
            "jpeg image",
            "mitre att",
            "hybrid",
            "general",
            "local",
            "error",
            "click",
            "strings",
            "microsoft",
            "threat analyzer",
            "urls https",
            "no data",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "heur",
            "malware site",
            "malicious site",
            "safe site",
            "malware",
            "html",
            "phishing site",
            "site top",
            "riskware",
            "unsafe",
            "artemis",
            "quasar rat",
            "downldr",
            "agent",
            "presenoker",
            "applicunwnt",
            "crack",
            "cve201711882",
            "win64",
            "iframe",
            "quasar",
            "trojanspy",
            "exit",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "traffic",
            "anonymizer",
            "brasil",
            "phishing three",
            "united",
            "phishing bank",
            "virustotal",
            "tech",
            "bank",
            "maltiverse",
            "hidelink",
            "samples",
            "spyware",
            "injector",
            "mon jan",
            "tld count",
            "wed dec",
            "download",
            "first",
            "team",
            "simda",
            "bambernek",
            "simda simda",
            "infy",
            "alexa",
            "gregory",
            "cyber threat",
            "phishing",
            "engineering",
            "covid19",
            "telefonica co",
            "malicious",
            "zbot",
            "zeus",
            "betabot",
            "suppobox",
            "citadel",
            "pony",
            "kraken",
            "redline stealer",
            "ransomware",
            "vawtrak",
            "athena",
            "neutrino",
            "alina",
            "andromeda",
            "dexter",
            "unknown",
            "keylogger",
            "hawkeye",
            "phase",
            "jackpos",
            "plasma",
            "spyeye",
            "spitmo",
            "slingshot",
            "ramnit",
            "emotet",
            "pykspa",
            "virut",
            "installcore",
            "dorkbot",
            "bondat",
            "union",
            "vskimmer",
            "xtrat",
            "solar",
            "grandcrab",
            "nymaim",
            "matsnu",
            "cutwail",
            "cobalt strike",
            "hydra",
            "tinba",
            "nsis",
            "memscan",
            "deepscan",
            "runescape",
            "backdoor",
            "reddit",
            "tulach",
            "password stealer",
            "active threat",
            "apple",
            "pinkslipbot",
            "icloud",
            "free",
            "apple"
          ],
          "references": [
            "https://seedbeej.pk/tin/index.php?QBOT.zip.  [Qbot zip]",
            "https://tulach.cc/  [Botnet phishing]",
            "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
            "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
            "198.54.115.46            [exploit_source]",
            "gadyniw.com          [command_and_control]",
            "gahyqah.com          [command_and_control]",
            "galyqaz.com            [command_and_control]",
            "lyvyxor.com             [command_and_control]",
            "puzylyp.com           [command_and_control]",
            "malicious.high.ml   [dropper]",
            "https://www.reddit.com/user [honeypot]",
            "beacons.bcp.gvt.com   [tracking]",
            "https://www.norad.mil/   [tracking]",
            "www.norad.mil   [tracking]",
            "www.apple.com  [API property call]",
            "https://www.apple.com/qtactivex/qtplugin.cab   [https://www.icloud.com .cab]",
            "yesporn.fun",
            "http://114.114.114.114:90/p/cdbdd4a09a64909694281aec503746fd/mobile_index.html?MTE0LjExNC4xMTQuMTE0L2xvZ2luP2hhc19vcmlfdXJp [Tulach | Malicious]",
            "114.114.114.114  [Tulach | Virus Network IP]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Quasar",
              "display_name": "Quasar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Gregory",
              "display_name": "Gregory",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Matsnu",
              "display_name": "Matsnu",
              "target": null
            },
            {
              "id": "Vawtrak",
              "display_name": "Vawtrak",
              "target": null
            },
            {
              "id": "XRat",
              "display_name": "XRat",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "vSkimmer",
              "display_name": "vSkimmer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "SpyEye",
              "display_name": "SpyEye",
              "target": null
            },
            {
              "id": "Spitmo",
              "display_name": "Spitmo",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "DorkBot",
              "display_name": "DorkBot",
              "target": null
            },
            {
              "id": "Slingshot",
              "display_name": "Slingshot",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Plasma RAT",
              "display_name": "Plasma RAT",
              "target": null
            },
            {
              "id": "Neutrino",
              "display_name": "Neutrino",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "GrandCrab",
              "display_name": "GrandCrab",
              "target": null
            },
            {
              "id": "Andromeda",
              "display_name": "Andromeda",
              "target": null
            },
            {
              "id": "Alinaos",
              "display_name": "Alinaos",
              "target": null
            },
            {
              "id": "HawkEye",
              "display_name": "HawkEye",
              "target": null
            },
            {
              "id": "Kraken",
              "display_name": "Kraken",
              "target": null
            },
            {
              "id": "Infy",
              "display_name": "Infy",
              "target": null
            },
            {
              "id": "Dexter",
              "display_name": "Dexter",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "ASCII",
              "display_name": "ASCII",
              "target": null
            },
            {
              "id": "Athena",
              "display_name": "Athena",
              "target": null
            },
            {
              "id": "Bambernek",
              "display_name": "Bambernek",
              "target": null
            },
            {
              "id": "BetaBot",
              "display_name": "BetaBot",
              "target": null
            },
            {
              "id": "COVID19",
              "display_name": "COVID19",
              "target": null
            },
            {
              "id": "Citadel",
              "display_name": "Citadel",
              "target": null
            },
            {
              "id": "Bondat",
              "display_name": "Bondat",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Hydra",
              "display_name": "Hydra",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Pinkslipbot",
              "display_name": "Pinkslipbot",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 124,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8736,
            "FileHash-MD5": 953,
            "FileHash-SHA1": 489,
            "FileHash-SHA256": 3566,
            "domain": 1516,
            "hostname": 2221,
            "CVE": 6
          },
          "indicator_count": 17487,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "863 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6583e3acc7f464d48a3503d1",
          "name": "Qkbot | Reddit",
          "description": "Qbot URL:  https://seedbeej.pk/tin/index.php?QBOT.zip found in Reddit Honeypot link: https://www.reddit.com/user\nbackdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork  with many capabilities, attack methods and demands.  An unsuspecting victim  always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware, malvertizing, fraud services, full control of badly compromised digital profiles which have been discovered.",
          "modified": "2024-01-20T02:02:19.559000",
          "created": "2023-12-21T07:05:16.695000",
          "tags": [
            "ssl certificate",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "threat",
            "paste",
            "blacklist https",
            "qakbot",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "ascii text",
            "pattern match",
            "file",
            "windows nt",
            "appdata",
            "indicator",
            "crlf line",
            "unicode text",
            "jpeg image",
            "mitre att",
            "hybrid",
            "general",
            "local",
            "error",
            "click",
            "strings",
            "microsoft",
            "threat analyzer",
            "urls https",
            "no data",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "heur",
            "malware site",
            "malicious site",
            "safe site",
            "malware",
            "html",
            "phishing site",
            "site top",
            "riskware",
            "unsafe",
            "artemis",
            "quasar rat",
            "downldr",
            "agent",
            "presenoker",
            "applicunwnt",
            "crack",
            "cve201711882",
            "win64",
            "iframe",
            "quasar",
            "trojanspy",
            "exit",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "traffic",
            "anonymizer",
            "brasil",
            "phishing three",
            "united",
            "phishing bank",
            "virustotal",
            "tech",
            "bank",
            "maltiverse",
            "hidelink",
            "samples",
            "spyware",
            "injector",
            "mon jan",
            "tld count",
            "wed dec",
            "download",
            "first",
            "team",
            "simda",
            "bambernek",
            "simda simda",
            "infy",
            "alexa",
            "gregory",
            "cyber threat",
            "phishing",
            "engineering",
            "covid19",
            "telefonica co",
            "malicious",
            "zbot",
            "zeus",
            "betabot",
            "suppobox",
            "citadel",
            "pony",
            "kraken",
            "redline stealer",
            "ransomware",
            "vawtrak",
            "athena",
            "neutrino",
            "alina",
            "andromeda",
            "dexter",
            "unknown",
            "keylogger",
            "hawkeye",
            "phase",
            "jackpos",
            "plasma",
            "spyeye",
            "spitmo",
            "slingshot",
            "ramnit",
            "emotet",
            "pykspa",
            "virut",
            "installcore",
            "dorkbot",
            "bondat",
            "union",
            "vskimmer",
            "xtrat",
            "solar",
            "grandcrab",
            "nymaim",
            "matsnu",
            "cutwail",
            "cobalt strike",
            "hydra",
            "tinba",
            "nsis",
            "memscan",
            "deepscan",
            "runescape",
            "backdoor",
            "reddit",
            "tulach"
          ],
          "references": [
            "https://seedbeej.pk/tin/index.php?QBOT.zip",
            "https://tulach.cc/ [phishing, exploits, malware spreader]",
            "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
            "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
            "198.54.115.46            [exploit_source]",
            "gadyniw.com          [command_and_control]",
            "gahyqah.com          [command_and_control]",
            "galyqaz.com            [command_and_control]",
            "lyvyxor.com             [command_and_control]",
            "puzylyp.com           [command_and_control]",
            "malicious.high.ml   [dropper]",
            "https://www.reddit.com/user"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Quasar",
              "display_name": "Quasar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Gregory",
              "display_name": "Gregory",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Matsnu",
              "display_name": "Matsnu",
              "target": null
            },
            {
              "id": "Vawtrak",
              "display_name": "Vawtrak",
              "target": null
            },
            {
              "id": "XRat",
              "display_name": "XRat",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "vSkimmer",
              "display_name": "vSkimmer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "SpyEye",
              "display_name": "SpyEye",
              "target": null
            },
            {
              "id": "Spitmo",
              "display_name": "Spitmo",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "DorkBot",
              "display_name": "DorkBot",
              "target": null
            },
            {
              "id": "Slingshot",
              "display_name": "Slingshot",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Plasma RAT",
              "display_name": "Plasma RAT",
              "target": null
            },
            {
              "id": "Neutrino",
              "display_name": "Neutrino",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "GrandCrab",
              "display_name": "GrandCrab",
              "target": null
            },
            {
              "id": "Andromeda",
              "display_name": "Andromeda",
              "target": null
            },
            {
              "id": "Alinaos",
              "display_name": "Alinaos",
              "target": null
            },
            {
              "id": "HawkEye",
              "display_name": "HawkEye",
              "target": null
            },
            {
              "id": "Kraken",
              "display_name": "Kraken",
              "target": null
            },
            {
              "id": "Infy",
              "display_name": "Infy",
              "target": null
            },
            {
              "id": "Dexter",
              "display_name": "Dexter",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "ASCII",
              "display_name": "ASCII",
              "target": null
            },
            {
              "id": "Athena",
              "display_name": "Athena",
              "target": null
            },
            {
              "id": "Bambernek",
              "display_name": "Bambernek",
              "target": null
            },
            {
              "id": "BetaBot",
              "display_name": "BetaBot",
              "target": null
            },
            {
              "id": "COVID19",
              "display_name": "COVID19",
              "target": null
            },
            {
              "id": "Citadel",
              "display_name": "Citadel",
              "target": null
            },
            {
              "id": "Bondat",
              "display_name": "Bondat",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Hydra",
              "display_name": "Hydra",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 101,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8343,
            "FileHash-MD5": 953,
            "FileHash-SHA1": 489,
            "FileHash-SHA256": 3565,
            "domain": 1494,
            "hostname": 2218,
            "CVE": 6
          },
          "indicator_count": 17068,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "863 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6583e3a2d1432cbf9054d26d",
          "name": "Qkbot | Reddit",
          "description": "Qbot URL:  https://seedbeej.pk/tin/index.php?QBOT.zip found in Reddit Honeypot link: https://www.reddit.com/user\nbackdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork  with many capabilities, attack methods and demands.  An unsuspecting victim  always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware, malvertizing, fraud services, full control of badly compromised digital profiles which have been discovered.",
          "modified": "2024-01-20T02:02:19.559000",
          "created": "2023-12-21T07:05:06.936000",
          "tags": [
            "ssl certificate",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "threat",
            "paste",
            "blacklist https",
            "qakbot",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "ascii text",
            "pattern match",
            "file",
            "windows nt",
            "appdata",
            "indicator",
            "crlf line",
            "unicode text",
            "jpeg image",
            "mitre att",
            "hybrid",
            "general",
            "local",
            "error",
            "click",
            "strings",
            "microsoft",
            "threat analyzer",
            "urls https",
            "no data",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "heur",
            "malware site",
            "malicious site",
            "safe site",
            "malware",
            "html",
            "phishing site",
            "site top",
            "riskware",
            "unsafe",
            "artemis",
            "quasar rat",
            "downldr",
            "agent",
            "presenoker",
            "applicunwnt",
            "crack",
            "cve201711882",
            "win64",
            "iframe",
            "quasar",
            "trojanspy",
            "exit",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "traffic",
            "anonymizer",
            "brasil",
            "phishing three",
            "united",
            "phishing bank",
            "virustotal",
            "tech",
            "bank",
            "maltiverse",
            "hidelink",
            "samples",
            "spyware",
            "injector",
            "mon jan",
            "tld count",
            "wed dec",
            "download",
            "first",
            "team",
            "simda",
            "bambernek",
            "simda simda",
            "infy",
            "alexa",
            "gregory",
            "cyber threat",
            "phishing",
            "engineering",
            "covid19",
            "telefonica co",
            "malicious",
            "zbot",
            "zeus",
            "betabot",
            "suppobox",
            "citadel",
            "pony",
            "kraken",
            "redline stealer",
            "ransomware",
            "vawtrak",
            "athena",
            "neutrino",
            "alina",
            "andromeda",
            "dexter",
            "unknown",
            "keylogger",
            "hawkeye",
            "phase",
            "jackpos",
            "plasma",
            "spyeye",
            "spitmo",
            "slingshot",
            "ramnit",
            "emotet",
            "pykspa",
            "virut",
            "installcore",
            "dorkbot",
            "bondat",
            "union",
            "vskimmer",
            "xtrat",
            "solar",
            "grandcrab",
            "nymaim",
            "matsnu",
            "cutwail",
            "cobalt strike",
            "hydra",
            "tinba",
            "nsis",
            "memscan",
            "deepscan",
            "runescape",
            "backdoor",
            "reddit",
            "tulach"
          ],
          "references": [
            "https://seedbeej.pk/tin/index.php?QBOT.zip",
            "https://tulach.cc/ [phishing, exploits, malware spreader]",
            "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
            "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
            "198.54.115.46            [exploit_source]",
            "gadyniw.com          [command_and_control]",
            "gahyqah.com          [command_and_control]",
            "galyqaz.com            [command_and_control]",
            "lyvyxor.com             [command_and_control]",
            "puzylyp.com           [command_and_control]",
            "malicious.high.ml   [dropper]",
            "https://www.reddit.com/user"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Quasar",
              "display_name": "Quasar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Gregory",
              "display_name": "Gregory",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Matsnu",
              "display_name": "Matsnu",
              "target": null
            },
            {
              "id": "Vawtrak",
              "display_name": "Vawtrak",
              "target": null
            },
            {
              "id": "XRat",
              "display_name": "XRat",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "vSkimmer",
              "display_name": "vSkimmer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "SpyEye",
              "display_name": "SpyEye",
              "target": null
            },
            {
              "id": "Spitmo",
              "display_name": "Spitmo",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "DorkBot",
              "display_name": "DorkBot",
              "target": null
            },
            {
              "id": "Slingshot",
              "display_name": "Slingshot",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Plasma RAT",
              "display_name": "Plasma RAT",
              "target": null
            },
            {
              "id": "Neutrino",
              "display_name": "Neutrino",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "GrandCrab",
              "display_name": "GrandCrab",
              "target": null
            },
            {
              "id": "Andromeda",
              "display_name": "Andromeda",
              "target": null
            },
            {
              "id": "Alinaos",
              "display_name": "Alinaos",
              "target": null
            },
            {
              "id": "HawkEye",
              "display_name": "HawkEye",
              "target": null
            },
            {
              "id": "Kraken",
              "display_name": "Kraken",
              "target": null
            },
            {
              "id": "Infy",
              "display_name": "Infy",
              "target": null
            },
            {
              "id": "Dexter",
              "display_name": "Dexter",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "ASCII",
              "display_name": "ASCII",
              "target": null
            },
            {
              "id": "Athena",
              "display_name": "Athena",
              "target": null
            },
            {
              "id": "Bambernek",
              "display_name": "Bambernek",
              "target": null
            },
            {
              "id": "BetaBot",
              "display_name": "BetaBot",
              "target": null
            },
            {
              "id": "COVID19",
              "display_name": "COVID19",
              "target": null
            },
            {
              "id": "Citadel",
              "display_name": "Citadel",
              "target": null
            },
            {
              "id": "Bondat",
              "display_name": "Bondat",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Hydra",
              "display_name": "Hydra",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 98,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8343,
            "FileHash-MD5": 953,
            "FileHash-SHA1": 489,
            "FileHash-SHA256": 3565,
            "domain": 1494,
            "hostname": 2218,
            "CVE": 6
          },
          "indicator_count": 17068,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "863 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e7995af8d4a3461031898b",
          "name": "IOC Records \u2192Provided by @NextRayAI",
          "description": "",
          "modified": "2023-10-02T00:00:29.692000",
          "created": "2023-08-24T17:54:34.404000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 233,
          "modified_text": "973 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6507dcf477ef9466c2de35e3",
          "name": "HIVE           (Pulse created by RVS_i_am)",
          "description": "For more information, please see:\n\nContact info: wnd5xkus@duck.com / kcqhf2ok@duck.com (Email & Phone has 'not been very effective' means of communication)\nTwitter: @NorrisN60014\nDiscord: inawj_2\nMastadon: Disable_Duck@nerdculture.de\n\nOther:\nAlienVault: DISABLE_DUCK\nFileScan: DISABLE_DUCK\nMetadefender: red_snow_ak3jzram",
          "modified": "2023-09-18T05:15:32.926000",
          "created": "2023-09-18T05:15:32.926000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "64fa30d707f35d3c9d8bd1cd",
          "export_count": 43,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 234,
          "modified_text": "987 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6507dcf100d8bde09b555013",
          "name": "HIVE           (Pulse created by RVS_i_am)",
          "description": "",
          "modified": "2023-09-18T05:15:29.671000",
          "created": "2023-09-18T05:15:29.671000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "64fa30d707f35d3c9d8bd1cd",
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "987 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64fa30d7bc2e4d93884b2a4c",
          "name": "HIVE",
          "description": "",
          "modified": "2023-09-07T20:21:43.678000",
          "created": "2023-09-07T20:21:43.678000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "RVS_i_am",
            "id": "251642",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 49,
          "modified_text": "998 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64fa30d707f35d3c9d8bd1cd",
          "name": "HIVE",
          "description": "",
          "modified": "2023-09-07T20:21:43.271000",
          "created": "2023-09-07T20:21:43.271000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "RVS_i_am",
            "id": "251642",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 47,
          "modified_text": "998 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64fa30cce362cbd8ba18c887",
          "name": "HIVE",
          "description": "",
          "modified": "2023-09-07T20:21:32.701000",
          "created": "2023-09-07T20:21:32.701000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "RVS_i_am",
            "id": "251642",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 45,
          "modified_text": "998 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64fa30c8b0f038985fbce564",
          "name": "HIVE",
          "description": "",
          "modified": "2023-09-07T20:21:28.946000",
          "created": "2023-09-07T20:21:28.946000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "RVS_i_am",
            "id": "251642",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 45,
          "modified_text": "998 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64fa30b1c5599ae3fd943671",
          "name": "HIVE",
          "description": "",
          "modified": "2023-09-07T20:21:05.125000",
          "created": "2023-09-07T20:21:05.125000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "RVS_i_am",
            "id": "251642",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 46,
          "modified_text": "998 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64fa30a3429961426a8c9f3f",
          "name": "HIVE",
          "description": "",
          "modified": "2023-09-07T20:20:51.389000",
          "created": "2023-09-07T20:20:51.389000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "RVS_i_am",
            "id": "251642",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 45,
          "modified_text": "998 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64fa309b486cb2d0cacbc33e",
          "name": "HIVE",
          "description": "",
          "modified": "2023-09-07T20:20:43.518000",
          "created": "2023-09-07T20:20:43.518000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "RVS_i_am",
            "id": "251642",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 47,
          "modified_text": "998 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64fa309b8869335d1a9e6293",
          "name": "HIVE",
          "description": "",
          "modified": "2023-09-07T20:20:43.122000",
          "created": "2023-09-07T20:20:43.122000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "RVS_i_am",
            "id": "251642",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "998 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64fa3090d3eb1de3bad58767",
          "name": "HIVE",
          "description": "",
          "modified": "2023-09-07T20:20:32.583000",
          "created": "2023-09-07T20:20:32.583000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "RVS_i_am",
            "id": "251642",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 46,
          "modified_text": "998 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64fa308c07f35d3c9d8bd1cc",
          "name": "HIVE",
          "description": "",
          "modified": "2023-09-07T20:20:28.541000",
          "created": "2023-09-07T20:20:28.541000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "RVS_i_am",
            "id": "251642",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 45,
          "modified_text": "998 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e799845f4ca1eaee3b9957",
          "name": "IOC Records \u2192Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:55:16.165000",
          "created": "2023-08-24T17:55:16.165000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e79960d336b6a4b53c561e",
          "name": "IOC Records \u2192Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:54:40.425000",
          "created": "2023-08-24T17:54:40.425000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e7995f5e8231aa87cdddc5",
          "name": "IOC Records \u2192Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:54:39.765000",
          "created": "2023-08-24T17:54:39.765000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e7995ece1da1e24e444a27",
          "name": "IOC Records \u2192Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:54:38.909000",
          "created": "2023-08-24T17:54:38.909000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e799540d4697a46f8f230c",
          "name": "IOC Records \u2192Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:54:28.757000",
          "created": "2023-08-24T17:54:28.757000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e799240e77a37a1a1fd255",
          "name": "IOC Records \u2192 Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:53:40.054000",
          "created": "2023-08-24T17:53:40.054000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e79923528ad3eb11ea884c",
          "name": "IOC Records \u2192 Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:53:39.444000",
          "created": "2023-08-24T17:53:39.444000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e7992247e0b22db4bd642a",
          "name": "IOC Records \u2192 Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:53:38.528000",
          "created": "2023-08-24T17:53:38.528000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e7991e0e88ef39bef95a12",
          "name": "IOC Records \u2192 Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:53:34.071000",
          "created": "2023-08-24T17:53:34.071000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e79918d81a265ff4d3d514",
          "name": "IOC Records \u2192 Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:53:28.601000",
          "created": "2023-08-24T17:53:28.601000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e7990cbf87cda6c38013cf",
          "name": "IOC Records \u2192 Provided by @NextRayAI",
          "description": "",
          "modified": "2023-08-24T17:53:16.082000",
          "created": "2023-08-24T17:53:16.082000",
          "tags": [
            "Nextray",
            "cyber security",
            "ioc",
            "phishing",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Turkey",
            "Ukraine",
            "Romania",
            "Czechia",
            "United Kingdom of Great Britain and Northern Ireland",
            "Norway",
            "Lithuania",
            "Estonia",
            "Latvia",
            "Poland",
            "Germany",
            "Canada",
            "France",
            "Denmark"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Industrial",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "63456c2a30b92337ea1670e0",
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 493080,
            "IPv4": 3458,
            "IPv6": 519,
            "hostname": 41105,
            "URL": 155223,
            "CIDR": 5266
          },
          "indicator_count": 698651,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 231,
          "modified_text": "1012 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "gahyqah.com          [command_and_control]",
        "Ransom:Win32/Crowti.A: FileHash-MD5 d34cf3663902900ddf46b937449472b9",
        "43.204.54.95 AS 16509 (AMAZON-02), http://r10.i.lencr.org/, www.maketrumppresidentagain.site",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://tulach.cc/ [phishing, exploits, malware spreader]",
        "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
        "Ransom:Win32/Crowti.A: FileHash-SHA1 05a49b7502099932ff628ca5a8583397b7e2dca2",
        "Win.Trojan.Simda: FileHash-SHA256 0187e1392266fff224de9e3d3fbbe1a05cea8b823906ad27ff577c6e348f6e3b",
        "VirTool:Win32/Injector: FileHash-SHA1 3e7124373729e9ec90ea1d01222bfdd84b0484e5",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA1 51efdae4ba6bfec8e6f4ae2d7f6dc8cca42db1da",
        "https://tulach.cc/  [Botnet phishing]",
        "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
        "puzylyp.com           [command_and_control]",
        "https://www.virustotal.com/graph/gf9fb2090ae8e450dadda45c0596ab774ed1984e89aab4679bc3fc02096e22fa3",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA256 30ffb056ad64037a918d80c120db5d0032b29feb7db97ed19824646381165a5d",
        "https://www.apple.com/qtactivex/qtplugin.cab   [https://www.icloud.com .cab]",
        "trojan.shiz/razy | CS Sigma: Matches rule System File Execution Location Anomaly by Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Benche",
        "https://www.reddit.com/user",
        "198.54.115.46            [exploit_source]",
        "VirTool:Win32/Injector: FileHash-MD5 baa1a920d33eee94e123f5dfb6bbe7456692e020d682ae45f0de66130f9ea0da",
        "TEL:Win32/Qjwmonkey.A: FileHash-MD5 535ce96e43fe532e1ddfd804dbde9c6a",
        "https://www.reddit.com/user [honeypot]",
        "gadyniw.com          [command_and_control]",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695",
        "beacons.bcp.gvt.com   [tracking]",
        "trojan.shiz/razy: FileHash-SHA256 02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8",
        "https://www.norad.mil/   [tracking]",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "Matches rule ET INFO Namecheap URL",
        "https://seedbeej.pk/tin/index.php?QBOT.zip.  [Qbot zip]",
        "lyvyxor.com             [command_and_control]",
        "Win.Trojan.Simda: FileHash-SHA1 fec01e5e59034cafc2b1e95c23068e075f9dbe69",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "galyqaz.com            [command_and_control]",
        "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
        "Matches rule Windows Processes Suspicious Parent Directory by vburov",
        "114.114.114.114  [Tulach | Virus Network IP]",
        "POLICY Unsupported/Fake Internet Explorer Version MSIE 2",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "yesporn.fun",
        "https://seedbeej.pk/tin/index.php?QBOT.zip",
        "trojan.shiz/razy | Capabilities Collection Log keystrokes via polling",
        "www.norad.mil   [tracking]",
        "Win.Trojan.Simda: FileHash-MD5 efe12fc770fb8647e22adb7f814666e7",
        "http://114.114.114.114:90/p/cdbdd4a09a64909694281aec503746fd/mobile_index.html?MTE0LjExNC4xMTQuMTE0L2xvZ2luP2hhc19vcmlfdXJp [Tulach | Malicious]",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst",
        "Matches rule Files With System Process Name In Unsuspected Locations by Sander Wiebing, Tim Shelton, Nasreddine Bencherch",
        "https://otx.alienvault.com/indicator/file/e6f8e2706058064d8f38d12923e52cec7a128218b39ca1fe60a2dde7ac3d158f | binary_yara mpress_2_xx_x86",
        "malicious.high.ml   [dropper]",
        "www.apple.com  [API property call]",
        "https://www.virustotal.com/gui/file/02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8/detection",
        "VirTool:Win32/Injector: FileHash-SHA256 0806653f8af2e9c2530e453f8b1fea47f62f86b5b0b65487ddcfd014eea8e9fe",
        "trojan.shiz/razy | CS IDS: Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "redhatdelete.com",
        "BigRock: gadyzyh.com",
        "Ransom:Win32/Crowti.A: FileHash-SHA256 1ffa6a3f8844b5955fc5e7329a6fb766cc1f35b39201ceaf0bca282b5b0b8cf6"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Hydra",
            "Gregory",
            "Win.ransomware.locky-7766366-0",
            "Ransom:win32/wannacrypt.a!rsm",
            "Qakbot",
            "Vawtrak",
            "Slingshot",
            "Nsis",
            "Andromeda",
            "Hawkeye",
            "Neutrino",
            "Alinaos",
            "Spyeye",
            "Virtool",
            "Matsnu",
            "Covid19",
            "Maltiverse",
            "Pykspa",
            "Trojanspy",
            "Quasar",
            "Nymaim",
            "Ascii",
            "Installcore",
            "Cutwail",
            "Plasma rat",
            "Solar",
            "Pony",
            "Virut",
            "Cycbot",
            "Vskimmer",
            "Suppobox",
            "Tel:win32/qjwmonkey.a",
            "Mitre attack",
            "Kraken",
            "Athena",
            "Bambernek",
            "Betabot",
            "Spitmo",
            "Simda",
            "Mirai",
            "Ransom:win32/crowti.a",
            "Hidelink",
            "Zbot",
            "Bondat",
            "Infy",
            "Tulach",
            "Dorkbot",
            "Zeus",
            "Alf:e5.spikeaex.rhh_pid",
            "Ramnit",
            "Win.trojan.simda",
            "Xrat",
            "Redline stealer",
            "Rostpay",
            "Chaos (elf)",
            "Trojandownloader:win32/upatre.e",
            "Trojan-ransom.win32.blocker.jgb checkin",
            "Trojandropper:win32/gamehack",
            "Grandcrab",
            "Emotet",
            "Dexter",
            "Artemis",
            "Citadel",
            "Virtool:win32/injector",
            "Pinkslipbot"
          ],
          "industries": [
            "Government",
            "Industrial",
            "Defense"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 40,
  "pulses": [
    {
      "id": "63456c2a30b92337ea1670e0",
      "name": "IOC Records Provided by @NextRayAI",
      "description": "This IOC report provided and daily updated by NextRay AI Detection & Response Inc.",
      "modified": "2026-06-01T00:38:49.108000",
      "created": "2022-10-11T13:14:18.676000",
      "tags": [
        "Nextray",
        "cyber security",
        "ioc",
        "phishing",
        "malicious"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Turkey",
        "Ukraine",
        "Romania",
        "Czechia",
        "United Kingdom of Great Britain and Northern Ireland",
        "Norway",
        "Lithuania",
        "Estonia",
        "Latvia",
        "Poland",
        "Germany",
        "Canada",
        "France",
        "Denmark"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Defense",
        "Industrial",
        "Government"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1330,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "NextRay-AI",
        "id": "210822",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_210822/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 498917,
        "IPv4": 64327,
        "IPv6": 459,
        "hostname": 59385,
        "URL": 166783,
        "CIDR": 5266,
        "FileHash-MD5": 29699,
        "FileHash-SHA256": 50449,
        "CVE": 348,
        "email": 914,
        "Mutex": 49,
        "FileHash-SHA1": 3453,
        "FilePath": 34
      },
      "indicator_count": 880083,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 301,
      "modified_text": "23 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "688c8526be7a4df33863b5c5",
      "name": "VirusTotal - Shiz.ivr",
      "description": "*Win.Trojan.Shiz.ivr\n*PWS:Win32/Simda.D\n*virtool #injection#infostealer #network #cnc #block_not #virustotal_google #cnc #checking #procmem_yara\n#injection_inter_process\n#injection_create_remote_thread\n#antidebug_windows\n#multiple_useragents\n#network_fake_useragent\n#persistence_autorun\n#cape_detected_threat\n#antiav_detectfile\n#modify_proxy\n#deletes_self\n#infostealer_cookies\n#injection_createremotethread\n#suricata_alert\n~ vashti",
      "modified": "2025-08-31T08:01:04.297000",
      "created": "2025-08-01T09:13:10.510000",
      "tags": [
        "dynamicloader",
        "unknown",
        "msie",
        "windows nt",
        "slcc2",
        "media center",
        "suspicious",
        "search",
        "high",
        "show",
        "copy",
        "possible",
        "write",
        "internal",
        "malware",
        "push",
        "local",
        "next",
        "contacted",
        "domains",
        "pulses",
        "related tags",
        "file type",
        "date april",
        "pm size",
        "sha1 sha256",
        "imphash pehash",
        "virustotal api",
        "bq jul",
        "united",
        "trojan",
        "backdoor",
        "virtool",
        "cnc beacon",
        "entries",
        "path max",
        "passive dns",
        "next associated",
        "cookie",
        "twitter",
        "body",
        "date",
        "medium",
        "simda",
        "global"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 10303,
        "hostname": 1413,
        "FileHash-SHA256": 1868,
        "domain": 1877,
        "FileHash-MD5": 357,
        "FileHash-SHA1": 348,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 16168,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 149,
      "modified_text": "274 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "5daf09a6d16f1e2c5c594c22",
      "name": "Simda - Malware Domain Feed V2",
      "description": "Command and Control domains for malware known as Simda. These domains are extracted from malware sandbox reports using                             a Machine Learning model trained on a corpus of good and bad domains.",
      "modified": "2025-07-15T21:13:57.066000",
      "created": "2019-10-22T13:52:38.770000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 33,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "otxrobottwo",
        "id": "78495",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_78495/resized/80/avatar_ba5a8acdbd.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 209,
        "hostname": 5
      },
      "indicator_count": 214,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1085,
      "modified_text": "321 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67fb185eb96e9791cf24ced4",
      "name": "Shiz/Packy",
      "description": "",
      "modified": "2025-05-13T01:03:15.390000",
      "created": "2025-04-13T01:50:22.707000",
      "tags": [],
      "references": [
        "https://www.virustotal.com/graph/gf9fb2090ae8e450dadda45c0596ab774ed1984e89aab4679bc3fc02096e22fa3"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 26,
        "URL": 191,
        "domain": 344,
        "hostname": 2
      },
      "indicator_count": 563,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 184,
      "modified_text": "384 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66a4293d5bc5c915eac829e0",
      "name": "Ransom:Win32/Crowti.A : Android Windows | Win.Trojan.Simda CnC",
      "description": "",
      "modified": "2024-08-25T21:00:52.039000",
      "created": "2024-07-26T22:54:53.598000",
      "tags": [
        "united",
        "unknown",
        "a domains",
        "accept",
        "link",
        "passive dns",
        "encrypt",
        "trmp",
        "ok server",
        "date",
        "meta",
        "whois lookup",
        "create date",
        "domain",
        "expiry date",
        "update date",
        "update",
        "algorithm",
        "data",
        "v3 serial",
        "number",
        "cus olet",
        "encrypt cnr10",
        "validity",
        "public key",
        "info",
        "key algorithm",
        "dns replication",
        "subdomains",
        "first",
        "historical ssl",
        "record type",
        "ttl value",
        "cname",
        "certificates",
        "show",
        "entries",
        "yara rule",
        "delete",
        "search",
        "intel",
        "ms windows",
        "copy",
        "binary file",
        "get updates",
        "write",
        "as44273 host",
        "redacted for",
        "moved",
        "record value",
        "as54113",
        "body",
        "scan endpoints",
        "all scoreblue",
        "pulse submit",
        "url analysis",
        "urls",
        "files",
        "ip address",
        "files ip",
        "address domain",
        "as61969 team",
        "germany unknown",
        "msie",
        "chrome",
        "precondition",
        "gmt content",
        "united kingdom",
        "as396982 google",
        "as8075",
        "ireland unknown",
        "as21301",
        "aaaa",
        "status",
        "sha1",
        "windows nt",
        "sha256",
        "size",
        "ascii text",
        "pattern match",
        "mitre att",
        "ck id",
        "show technique",
        "span",
        "format",
        "click",
        "hybrid",
        "twitter",
        "generator",
        "tsvt",
        "strings",
        "download",
        "path",
        "contact",
        "suspicious",
        "invalid url",
        "open ports",
        "body html",
        "head title",
        "title head",
        "body h1",
        "reference",
        "bad request",
        "server",
        "version",
        "trojandropper",
        "ransom",
        "checkin",
        "ipv4",
        "trojan",
        "virtool",
        "http post",
        "theme directory",
        "without referer",
        "cycbot",
        "http response",
        "final url",
        "status code",
        "body length",
        "kb body",
        "headers server",
        "gmt etag",
        "gmt date",
        "referrer",
        "code signing",
        "serial number",
        "ca valid",
        "from",
        "valid",
        "valid usage",
        "verisign time",
        "stamping",
        "thumbprint",
        "class",
        "error",
        "info header",
        "name md5",
        "type",
        "language",
        "contained",
        "overlay",
        "gandi sas",
        "dynadot",
        "registrar",
        "dynadot inc",
        "cloudflare",
        "net technology",
        "corporation",
        "bigrock",
        "dynadot llc",
        "namecheap",
        "ip detections",
        "country",
        "contacted",
        "defense evasion",
        "access ta0006",
        "ta0009 command",
        "control ta0011",
        "impact ta0034",
        "impact ta0040",
        "ta0040",
        "samplepath",
        "pattern urls",
        "pattern domains",
        "memory pattern",
        "domains domain",
        "ip traffic",
        "typo squatting",
        "realteck audio",
        "phish",
        "mr windows",
        "partru",
        "goog mal",
        "android windows",
        "maze",
        "apple",
        "malware",
        "worm",
        "skynet",
        "microsoft",
        "trojan evader",
        "simda cnc",
        "showing",
        "filehash",
        "pulse pulses",
        "av detections",
        "ids detections",
        "delphi",
        "network",
        "crowdstrike"
      ],
      "references": [
        "43.204.54.95 AS 16509 (AMAZON-02), http://r10.i.lencr.org/, www.maketrumppresidentagain.site",
        "trojan.shiz/razy: FileHash-SHA256 02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8",
        "trojan.shiz/razy | CS Sigma: Matches rule System File Execution Location Anomaly by Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Benche",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
        "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
        "trojan.shiz/razy | CS IDS: Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "trojan.shiz/razy | Capabilities Collection Log keystrokes via polling",
        "https://www.virustotal.com/gui/file/02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8/detection",
        "https://otx.alienvault.com/indicator/file/e6f8e2706058064d8f38d12923e52cec7a128218b39ca1fe60a2dde7ac3d158f | binary_yara mpress_2_xx_x86",
        "Ransom:Win32/Crowti.A: FileHash-SHA256 1ffa6a3f8844b5955fc5e7329a6fb766cc1f35b39201ceaf0bca282b5b0b8cf6",
        "Ransom:Win32/Crowti.A: FileHash-MD5 d34cf3663902900ddf46b937449472b9",
        "Ransom:Win32/Crowti.A: FileHash-SHA1 05a49b7502099932ff628ca5a8583397b7e2dca2",
        "VirTool:Win32/Injector: FileHash-SHA256 0806653f8af2e9c2530e453f8b1fea47f62f86b5b0b65487ddcfd014eea8e9fe",
        "VirTool:Win32/Injector: FileHash-MD5 baa1a920d33eee94e123f5dfb6bbe7456692e020d682ae45f0de66130f9ea0da",
        "VirTool:Win32/Injector: FileHash-SHA1 3e7124373729e9ec90ea1d01222bfdd84b0484e5",
        "BigRock: gadyzyh.com",
        "Matches rule ET INFO Namecheap URL",
        "POLICY Unsupported/Fake Internet Explorer Version MSIE 2",
        "Win.Trojan.Simda: FileHash-SHA256 0187e1392266fff224de9e3d3fbbe1a05cea8b823906ad27ff577c6e348f6e3b",
        "Win.Trojan.Simda: FileHash-SHA1 fec01e5e59034cafc2b1e95c23068e075f9dbe69",
        "Win.Trojan.Simda: FileHash-MD5 efe12fc770fb8647e22adb7f814666e7",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA256 30ffb056ad64037a918d80c120db5d0032b29feb7db97ed19824646381165a5d",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA1 51efdae4ba6bfec8e6f4ae2d7f6dc8cca42db1da",
        "TEL:Win32/Qjwmonkey.A: FileHash-MD5 535ce96e43fe532e1ddfd804dbde9c6a",
        "Matches rule Files With System Process Name In Unsuspected Locations by Sander Wiebing, Tim Shelton, Nasreddine Bencherch",
        "Matches rule Windows Processes Suspicious Parent Directory by vburov"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Australia",
        "Netherlands"
      ],
      "malware_families": [
        {
          "id": "TrojanDownloader:Win32/Upatre.E",
          "display_name": "TrojanDownloader:Win32/Upatre.E",
          "target": "/malware/TrojanDownloader:Win32/Upatre.E"
        },
        {
          "id": "Ransom:Win32/Crowti.A",
          "display_name": "Ransom:Win32/Crowti.A",
          "target": "/malware/Ransom:Win32/Crowti.A"
        },
        {
          "id": "Cycbot",
          "display_name": "Cycbot",
          "target": null
        },
        {
          "id": "VirTool:Win32/Injector",
          "display_name": "VirTool:Win32/Injector",
          "target": "/malware/VirTool:Win32/Injector"
        },
        {
          "id": "Win.Trojan.Simda",
          "display_name": "Win.Trojan.Simda",
          "target": null
        },
        {
          "id": "TEL:Win32/Qjwmonkey.A",
          "display_name": "TEL:Win32/Qjwmonkey.A",
          "target": "/malware/TEL:Win32/Qjwmonkey.A"
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0008",
          "name": "Lateral Movement",
          "display_name": "TA0008 - Lateral Movement"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 549,
        "domain": 1182,
        "hostname": 590,
        "URL": 961,
        "FileHash-SHA256": 2466,
        "FileHash-MD5": 562,
        "SSLCertFingerprint": 7,
        "email": 4
      },
      "indicator_count": 6321,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 230,
      "modified_text": "645 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65d3acf32e1088e76165a307",
      "name": "Locky: File Deletion targeting incriminating archived files.",
      "description": "",
      "modified": "2024-03-20T12:00:39.809000",
      "created": "2024-02-19T19:33:07.504000",
      "tags": [
        "it consultant",
        "uk collection",
        "dns intel",
        "ips collection",
        "suspicous ip",
        "whois file",
        "cname",
        "record type",
        "ttl value",
        "algorithm",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "whois lookup",
        "region create",
        "domain",
        "name server",
        "registrant name",
        "technical city",
        "region update",
        "united",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "ck id",
        "cookie",
        "meta",
        "february",
        "hybrid",
        "general",
        "click",
        "strings",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "dns replication",
        "code",
        "namecheap",
        "registrar abuse",
        "namecheap inc",
        "privacy service",
        "withheld",
        "privacy",
        "dnssec",
        "email",
        "first",
        "bodis",
        "unknown",
        "creation date",
        "search",
        "emails",
        "as397240",
        "date",
        "next",
        "all octoseek",
        "threat roundup",
        "january",
        "june",
        "historical ssl",
        "referrer",
        "contacted",
        "group",
        "execution",
        "phishing",
        "malware",
        "core",
        "malicious",
        "dark power",
        "play ransomware",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 linker",
        "gnu linker",
        "compiler",
        "info header",
        "name md5",
        "overlay",
        "passive dns",
        "entries",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "trojan",
        "location united",
        "query",
        "activity dns",
        "observed dns",
        "msie",
        "high",
        "copy",
        "write",
        "win32",
        "hashes",
        "host interaction",
        "sabey type",
        "hallrender",
        "brian sabey",
        "memory pattern",
        "http requests",
        "http method",
        "get response",
        "dns resolutions",
        "ip traffic",
        "domains",
        "mutex",
        "samplepath",
        "created",
        "shell commands",
        "r processes",
        "tree",
        "analyze",
        "hostnames",
        "url https",
        "samples",
        "hostname",
        "pattern urls",
        "memory",
        "pattern",
        "pattern domains",
        "roundup",
        "formbook",
        "mirai",
        "ben c",
        "injection",
        "server",
        "scan endpoints",
        "show",
        "august",
        "bq feb",
        "chrome",
        "precondition",
        "virtool",
        "downloadmr",
        "body",
        "status",
        "servers",
        "record value",
        "name servers",
        "showing",
        "mailrubar",
        "trojanclicker",
        "slcc2",
        "media center",
        "delete c",
        "malware beacon",
        "suspicious",
        "class",
        "internal",
        "local",
        "encrypt",
        "as15169 google",
        "gmt cache",
        "twitter",
        "rostpay",
        "date hash",
        "avast avg",
        "mtb may",
        "susp",
        "cryp",
        "win32upatre may",
        "mtb showing",
        "lowfi",
        "aaaa",
        "win32pcmega jan",
        "urlshortner dec",
        "urlshortner sep",
        "as133618",
        "nxdomain",
        "as133775 xiamen",
        "germany unknown",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "whois record",
        "ssl certificate",
        "tsara brashears",
        "resolutions",
        "critical risk",
        "apple phone",
        "unlocker",
        "shell code",
        "installer",
        "ursnif",
        "hacktool",
        "emotet",
        "tracker",
        "chaos",
        "ransomexx",
        "xor ddos",
        "xorddos",
        "mitre attack",
        "parent domain",
        "urls url",
        "siblings",
        "metro",
        "communicating",
        "collection",
        "dropped",
        "skynet",
        "youth",
        "com laude",
        "ltd dba",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "akamaias",
        "digitaloceanasn",
        "csc corporate",
        "pt mora",
        "univjos",
        "etisalat misr",
        "acurix networks",
        "pty ltd",
        "beijing baidu",
        "highly targeted",
        "http",
        "network hijacks",
        "redline stealer",
        "whois sslcert",
        "contacted urls",
        "whois whois",
        "september",
        "hidden cobra",
        "threats",
        "kimsuky",
        "service",
        "read c",
        "create c",
        "write c",
        "regsetvalueexa",
        "mozilla",
        "capture",
        "asnone",
        "domain http",
        "request",
        "malware dns",
        "lookup wannacry",
        "default",
        "ransom",
        "push",
        "playgame",
        "command",
        "email document",
        "exploit domain",
        "owner exploit",
        "kit exploit",
        "source file",
        "hacking tools",
        "hunting macro",
        "malware hosting",
        "memory scanning",
        "yara detections",
        "debug",
        "icmp traffic",
        "pdb path",
        "pe section",
        "low software",
        "packing t1045",
        "ransomware",
        "egregor",
        "find",
        "false",
        "psexec",
        "powershell",
        "qakbot",
        "qbot",
        "icedid"
      ],
      "references": [
        "redhatdelete.com",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Australia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "target": null
        },
        {
          "id": "Rostpay",
          "display_name": "Rostpay",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Mitre Attack",
          "display_name": "Mitre Attack",
          "target": null
        },
        {
          "id": "Chaos (ELF)",
          "display_name": "Chaos (ELF)",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/GameHack",
          "display_name": "TrojanDropper:Win32/GameHack",
          "target": "/malware/TrojanDropper:Win32/GameHack"
        },
        {
          "id": "Win.Ransomware.Locky-7766366-0",
          "display_name": "Win.Ransomware.Locky-7766366-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "ALF:E5.SpikeAex.rhh_pid",
          "display_name": "ALF:E5.SpikeAex.rhh_pid",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1107",
          "name": "File Deletion",
          "display_name": "T1107 - File Deletion"
        },
        {
          "id": "T1563",
          "name": "Remote Service Session Hijacking",
          "display_name": "T1563 - Remote Service Session Hijacking"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65d34c91868744aa1449fef2",
      "export_count": 64,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1848,
        "FileHash-SHA1": 1783,
        "FileHash-SHA256": 7170,
        "domain": 1649,
        "hostname": 1191,
        "email": 9,
        "URL": 729,
        "CVE": 2,
        "SSLCertFingerprint": 2,
        "CIDR": 1
      },
      "indicator_count": 14384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 234,
      "modified_text": "803 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65d34c8a64436a7aee2e25a1",
      "name": "Locky: File Deletion targeting incriminating archived files.",
      "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
      "modified": "2024-03-20T12:00:39.809000",
      "created": "2024-02-19T12:41:46.707000",
      "tags": [
        "it consultant",
        "uk collection",
        "dns intel",
        "ips collection",
        "suspicous ip",
        "whois file",
        "cname",
        "record type",
        "ttl value",
        "algorithm",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "whois lookup",
        "region create",
        "domain",
        "name server",
        "registrant name",
        "technical city",
        "region update",
        "united",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "ck id",
        "cookie",
        "meta",
        "february",
        "hybrid",
        "general",
        "click",
        "strings",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "dns replication",
        "code",
        "namecheap",
        "registrar abuse",
        "namecheap inc",
        "privacy service",
        "withheld",
        "privacy",
        "dnssec",
        "email",
        "first",
        "bodis",
        "unknown",
        "creation date",
        "search",
        "emails",
        "as397240",
        "date",
        "next",
        "all octoseek",
        "threat roundup",
        "january",
        "june",
        "historical ssl",
        "referrer",
        "contacted",
        "group",
        "execution",
        "phishing",
        "malware",
        "core",
        "malicious",
        "dark power",
        "play ransomware",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 linker",
        "gnu linker",
        "compiler",
        "info header",
        "name md5",
        "overlay",
        "passive dns",
        "entries",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "trojan",
        "location united",
        "query",
        "activity dns",
        "observed dns",
        "msie",
        "high",
        "copy",
        "write",
        "win32",
        "hashes",
        "host interaction",
        "sabey type",
        "hallrender",
        "brian sabey",
        "memory pattern",
        "http requests",
        "http method",
        "get response",
        "dns resolutions",
        "ip traffic",
        "domains",
        "mutex",
        "samplepath",
        "created",
        "shell commands",
        "r processes",
        "tree",
        "analyze",
        "hostnames",
        "url https",
        "samples",
        "hostname",
        "pattern urls",
        "memory",
        "pattern",
        "pattern domains",
        "roundup",
        "formbook",
        "mirai",
        "ben c",
        "injection",
        "server",
        "scan endpoints",
        "show",
        "august",
        "bq feb",
        "chrome",
        "precondition",
        "virtool",
        "downloadmr",
        "body",
        "status",
        "servers",
        "record value",
        "name servers",
        "showing",
        "mailrubar",
        "trojanclicker",
        "slcc2",
        "media center",
        "delete c",
        "malware beacon",
        "suspicious",
        "class",
        "internal",
        "local",
        "encrypt",
        "as15169 google",
        "gmt cache",
        "twitter",
        "rostpay",
        "date hash",
        "avast avg",
        "mtb may",
        "susp",
        "cryp",
        "win32upatre may",
        "mtb showing",
        "lowfi",
        "aaaa",
        "win32pcmega jan",
        "urlshortner dec",
        "urlshortner sep",
        "as133618",
        "nxdomain",
        "as133775 xiamen",
        "germany unknown",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "whois record",
        "ssl certificate",
        "tsara brashears",
        "resolutions",
        "critical risk",
        "apple phone",
        "unlocker",
        "shell code",
        "installer",
        "ursnif",
        "hacktool",
        "emotet",
        "tracker",
        "chaos",
        "ransomexx",
        "xor ddos",
        "xorddos",
        "mitre attack",
        "parent domain",
        "urls url",
        "siblings",
        "metro",
        "communicating",
        "collection",
        "dropped",
        "skynet",
        "youth",
        "com laude",
        "ltd dba",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "akamaias",
        "digitaloceanasn",
        "csc corporate",
        "pt mora",
        "univjos",
        "etisalat misr",
        "acurix networks",
        "pty ltd",
        "beijing baidu",
        "highly targeted",
        "http",
        "network hijacks",
        "redline stealer",
        "whois sslcert",
        "contacted urls",
        "whois whois",
        "september",
        "hidden cobra",
        "threats",
        "kimsuky",
        "service",
        "read c",
        "create c",
        "write c",
        "regsetvalueexa",
        "mozilla",
        "capture",
        "asnone",
        "domain http",
        "request",
        "malware dns",
        "lookup wannacry",
        "default",
        "ransom",
        "push",
        "playgame",
        "command",
        "email document",
        "exploit domain",
        "owner exploit",
        "kit exploit",
        "source file",
        "hacking tools",
        "hunting macro",
        "malware hosting",
        "memory scanning",
        "yara detections",
        "debug",
        "icmp traffic",
        "pdb path",
        "pe section",
        "low software",
        "packing t1045",
        "ransomware",
        "egregor",
        "find",
        "false",
        "psexec",
        "powershell",
        "qakbot",
        "qbot",
        "icedid"
      ],
      "references": [
        "redhatdelete.com",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Australia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "target": null
        },
        {
          "id": "Rostpay",
          "display_name": "Rostpay",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Mitre Attack",
          "display_name": "Mitre Attack",
          "target": null
        },
        {
          "id": "Chaos (ELF)",
          "display_name": "Chaos (ELF)",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/GameHack",
          "display_name": "TrojanDropper:Win32/GameHack",
          "target": "/malware/TrojanDropper:Win32/GameHack"
        },
        {
          "id": "Win.Ransomware.Locky-7766366-0",
          "display_name": "Win.Ransomware.Locky-7766366-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "ALF:E5.SpikeAex.rhh_pid",
          "display_name": "ALF:E5.SpikeAex.rhh_pid",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1107",
          "name": "File Deletion",
          "display_name": "T1107 - File Deletion"
        },
        {
          "id": "T1563",
          "name": "Remote Service Session Hijacking",
          "display_name": "T1563 - Remote Service Session Hijacking"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 65,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1848,
        "FileHash-SHA1": 1783,
        "FileHash-SHA256": 7170,
        "domain": 1649,
        "hostname": 1191,
        "email": 9,
        "URL": 729,
        "CVE": 2,
        "SSLCertFingerprint": 2,
        "CIDR": 1
      },
      "indicator_count": 14384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "803 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65d34c91868744aa1449fef2",
      "name": "Locky: File Deletion targeting incriminating archived files.",
      "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
      "modified": "2024-03-20T12:00:39.809000",
      "created": "2024-02-19T12:41:52.846000",
      "tags": [
        "it consultant",
        "uk collection",
        "dns intel",
        "ips collection",
        "suspicous ip",
        "whois file",
        "cname",
        "record type",
        "ttl value",
        "algorithm",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "whois lookup",
        "region create",
        "domain",
        "name server",
        "registrant name",
        "technical city",
        "region update",
        "united",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "ck id",
        "cookie",
        "meta",
        "february",
        "hybrid",
        "general",
        "click",
        "strings",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "dns replication",
        "code",
        "namecheap",
        "registrar abuse",
        "namecheap inc",
        "privacy service",
        "withheld",
        "privacy",
        "dnssec",
        "email",
        "first",
        "bodis",
        "unknown",
        "creation date",
        "search",
        "emails",
        "as397240",
        "date",
        "next",
        "all octoseek",
        "threat roundup",
        "january",
        "june",
        "historical ssl",
        "referrer",
        "contacted",
        "group",
        "execution",
        "phishing",
        "malware",
        "core",
        "malicious",
        "dark power",
        "play ransomware",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 linker",
        "gnu linker",
        "compiler",
        "info header",
        "name md5",
        "overlay",
        "passive dns",
        "entries",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "trojan",
        "location united",
        "query",
        "activity dns",
        "observed dns",
        "msie",
        "high",
        "copy",
        "write",
        "win32",
        "hashes",
        "host interaction",
        "sabey type",
        "hallrender",
        "brian sabey",
        "memory pattern",
        "http requests",
        "http method",
        "get response",
        "dns resolutions",
        "ip traffic",
        "domains",
        "mutex",
        "samplepath",
        "created",
        "shell commands",
        "r processes",
        "tree",
        "analyze",
        "hostnames",
        "url https",
        "samples",
        "hostname",
        "pattern urls",
        "memory",
        "pattern",
        "pattern domains",
        "roundup",
        "formbook",
        "mirai",
        "ben c",
        "injection",
        "server",
        "scan endpoints",
        "show",
        "august",
        "bq feb",
        "chrome",
        "precondition",
        "virtool",
        "downloadmr",
        "body",
        "status",
        "servers",
        "record value",
        "name servers",
        "showing",
        "mailrubar",
        "trojanclicker",
        "slcc2",
        "media center",
        "delete c",
        "malware beacon",
        "suspicious",
        "class",
        "internal",
        "local",
        "encrypt",
        "as15169 google",
        "gmt cache",
        "twitter",
        "rostpay",
        "date hash",
        "avast avg",
        "mtb may",
        "susp",
        "cryp",
        "win32upatre may",
        "mtb showing",
        "lowfi",
        "aaaa",
        "win32pcmega jan",
        "urlshortner dec",
        "urlshortner sep",
        "as133618",
        "nxdomain",
        "as133775 xiamen",
        "germany unknown",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "whois record",
        "ssl certificate",
        "tsara brashears",
        "resolutions",
        "critical risk",
        "apple phone",
        "unlocker",
        "shell code",
        "installer",
        "ursnif",
        "hacktool",
        "emotet",
        "tracker",
        "chaos",
        "ransomexx",
        "xor ddos",
        "xorddos",
        "mitre attack",
        "parent domain",
        "urls url",
        "siblings",
        "metro",
        "communicating",
        "collection",
        "dropped",
        "skynet",
        "youth",
        "com laude",
        "ltd dba",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "akamaias",
        "digitaloceanasn",
        "csc corporate",
        "pt mora",
        "univjos",
        "etisalat misr",
        "acurix networks",
        "pty ltd",
        "beijing baidu",
        "highly targeted",
        "http",
        "network hijacks",
        "redline stealer",
        "whois sslcert",
        "contacted urls",
        "whois whois",
        "september",
        "hidden cobra",
        "threats",
        "kimsuky",
        "service",
        "read c",
        "create c",
        "write c",
        "regsetvalueexa",
        "mozilla",
        "capture",
        "asnone",
        "domain http",
        "request",
        "malware dns",
        "lookup wannacry",
        "default",
        "ransom",
        "push",
        "playgame",
        "command",
        "email document",
        "exploit domain",
        "owner exploit",
        "kit exploit",
        "source file",
        "hacking tools",
        "hunting macro",
        "malware hosting",
        "memory scanning",
        "yara detections",
        "debug",
        "icmp traffic",
        "pdb path",
        "pe section",
        "low software",
        "packing t1045",
        "ransomware",
        "egregor",
        "find",
        "false",
        "psexec",
        "powershell",
        "qakbot",
        "qbot",
        "icedid"
      ],
      "references": [
        "redhatdelete.com",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Australia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "target": null
        },
        {
          "id": "Rostpay",
          "display_name": "Rostpay",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Mitre Attack",
          "display_name": "Mitre Attack",
          "target": null
        },
        {
          "id": "Chaos (ELF)",
          "display_name": "Chaos (ELF)",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/GameHack",
          "display_name": "TrojanDropper:Win32/GameHack",
          "target": "/malware/TrojanDropper:Win32/GameHack"
        },
        {
          "id": "Win.Ransomware.Locky-7766366-0",
          "display_name": "Win.Ransomware.Locky-7766366-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "ALF:E5.SpikeAex.rhh_pid",
          "display_name": "ALF:E5.SpikeAex.rhh_pid",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1107",
          "name": "File Deletion",
          "display_name": "T1107 - File Deletion"
        },
        {
          "id": "T1563",
          "name": "Remote Service Session Hijacking",
          "display_name": "T1563 - Remote Service Session Hijacking"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 57,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1848,
        "FileHash-SHA1": 1783,
        "FileHash-SHA256": 7170,
        "domain": 1649,
        "hostname": 1191,
        "email": 9,
        "URL": 729,
        "CVE": 2,
        "SSLCertFingerprint": 2,
        "CIDR": 1
      },
      "indicator_count": 14384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "803 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65d3c31230455f6d8da3a9f0",
      "name": "Locky: File Deletion targeting incriminating archived files II",
      "description": "",
      "modified": "2024-03-20T12:00:39.809000",
      "created": "2024-02-19T21:07:30.887000",
      "tags": [
        "it consultant",
        "uk collection",
        "dns intel",
        "ips collection",
        "suspicous ip",
        "whois file",
        "cname",
        "record type",
        "ttl value",
        "algorithm",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "whois lookup",
        "region create",
        "domain",
        "name server",
        "registrant name",
        "technical city",
        "region update",
        "united",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "ck id",
        "cookie",
        "meta",
        "february",
        "hybrid",
        "general",
        "click",
        "strings",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "dns replication",
        "code",
        "namecheap",
        "registrar abuse",
        "namecheap inc",
        "privacy service",
        "withheld",
        "privacy",
        "dnssec",
        "email",
        "first",
        "bodis",
        "unknown",
        "creation date",
        "search",
        "emails",
        "as397240",
        "date",
        "next",
        "all octoseek",
        "threat roundup",
        "january",
        "june",
        "historical ssl",
        "referrer",
        "contacted",
        "group",
        "execution",
        "phishing",
        "malware",
        "core",
        "malicious",
        "dark power",
        "play ransomware",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 linker",
        "gnu linker",
        "compiler",
        "info header",
        "name md5",
        "overlay",
        "passive dns",
        "entries",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "trojan",
        "location united",
        "query",
        "activity dns",
        "observed dns",
        "msie",
        "high",
        "copy",
        "write",
        "win32",
        "hashes",
        "host interaction",
        "sabey type",
        "hallrender",
        "brian sabey",
        "memory pattern",
        "http requests",
        "http method",
        "get response",
        "dns resolutions",
        "ip traffic",
        "domains",
        "mutex",
        "samplepath",
        "created",
        "shell commands",
        "r processes",
        "tree",
        "analyze",
        "hostnames",
        "url https",
        "samples",
        "hostname",
        "pattern urls",
        "memory",
        "pattern",
        "pattern domains",
        "roundup",
        "formbook",
        "mirai",
        "ben c",
        "injection",
        "server",
        "scan endpoints",
        "show",
        "august",
        "bq feb",
        "chrome",
        "precondition",
        "virtool",
        "downloadmr",
        "body",
        "status",
        "servers",
        "record value",
        "name servers",
        "showing",
        "mailrubar",
        "trojanclicker",
        "slcc2",
        "media center",
        "delete c",
        "malware beacon",
        "suspicious",
        "class",
        "internal",
        "local",
        "encrypt",
        "as15169 google",
        "gmt cache",
        "twitter",
        "rostpay",
        "date hash",
        "avast avg",
        "mtb may",
        "susp",
        "cryp",
        "win32upatre may",
        "mtb showing",
        "lowfi",
        "aaaa",
        "win32pcmega jan",
        "urlshortner dec",
        "urlshortner sep",
        "as133618",
        "nxdomain",
        "as133775 xiamen",
        "germany unknown",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "whois record",
        "ssl certificate",
        "tsara brashears",
        "resolutions",
        "critical risk",
        "apple phone",
        "unlocker",
        "shell code",
        "installer",
        "ursnif",
        "hacktool",
        "emotet",
        "tracker",
        "chaos",
        "ransomexx",
        "xor ddos",
        "xorddos",
        "mitre attack",
        "parent domain",
        "urls url",
        "siblings",
        "metro",
        "communicating",
        "collection",
        "dropped",
        "skynet",
        "youth",
        "com laude",
        "ltd dba",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "akamaias",
        "digitaloceanasn",
        "csc corporate",
        "pt mora",
        "univjos",
        "etisalat misr",
        "acurix networks",
        "pty ltd",
        "beijing baidu",
        "highly targeted",
        "http",
        "network hijacks",
        "redline stealer",
        "whois sslcert",
        "contacted urls",
        "whois whois",
        "september",
        "hidden cobra",
        "threats",
        "kimsuky",
        "service",
        "read c",
        "create c",
        "write c",
        "regsetvalueexa",
        "mozilla",
        "capture",
        "asnone",
        "domain http",
        "request",
        "malware dns",
        "lookup wannacry",
        "default",
        "ransom",
        "push",
        "playgame",
        "command",
        "email document",
        "exploit domain",
        "owner exploit",
        "kit exploit",
        "source file",
        "hacking tools",
        "hunting macro",
        "malware hosting",
        "memory scanning",
        "yara detections",
        "debug",
        "icmp traffic",
        "pdb path",
        "pe section",
        "low software",
        "packing t1045",
        "ransomware",
        "egregor",
        "find",
        "false",
        "psexec",
        "powershell",
        "qakbot",
        "qbot",
        "icedid"
      ],
      "references": [
        "redhatdelete.com",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Australia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "target": null
        },
        {
          "id": "Rostpay",
          "display_name": "Rostpay",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Mitre Attack",
          "display_name": "Mitre Attack",
          "target": null
        },
        {
          "id": "Chaos (ELF)",
          "display_name": "Chaos (ELF)",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/GameHack",
          "display_name": "TrojanDropper:Win32/GameHack",
          "target": "/malware/TrojanDropper:Win32/GameHack"
        },
        {
          "id": "Win.Ransomware.Locky-7766366-0",
          "display_name": "Win.Ransomware.Locky-7766366-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "ALF:E5.SpikeAex.rhh_pid",
          "display_name": "ALF:E5.SpikeAex.rhh_pid",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1107",
          "name": "File Deletion",
          "display_name": "T1107 - File Deletion"
        },
        {
          "id": "T1563",
          "name": "Remote Service Session Hijacking",
          "display_name": "T1563 - Remote Service Session Hijacking"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65d34c8a64436a7aee2e25a1",
      "export_count": 73,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Enqrypted",
        "id": "272105",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_272105/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1848,
        "FileHash-SHA1": 1783,
        "FileHash-SHA256": 7170,
        "domain": 1649,
        "hostname": 1191,
        "email": 9,
        "URL": 729,
        "CVE": 2,
        "SSLCertFingerprint": 2,
        "CIDR": 1
      },
      "indicator_count": 14384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 62,
      "modified_text": "803 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65f5828f8217ecbe6ce3a89b",
      "name": "IOCs Industriales",
      "description": "",
      "modified": "2024-03-16T11:29:19.302000",
      "created": "2024-03-16T11:29:19.302000",
      "tags": [
        "Nextray",
        "cyber security",
        "ioc",
        "phishing",
        "malicious"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Turkey",
        "Ukraine",
        "Romania",
        "Czechia",
        "United Kingdom of Great Britain and Northern Ireland",
        "Norway",
        "Lithuania",
        "Estonia",
        "Latvia",
        "Poland",
        "Germany",
        "Canada",
        "France",
        "Denmark"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Defense",
        "Industrial",
        "Government"
      ],
      "TLP": "white",
      "cloned_from": "63456c2a30b92337ea1670e0",
      "export_count": 81,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dtatov00",
        "id": "256758",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 493080,
        "IPv4": 3458,
        "IPv6": 519,
        "hostname": 41105,
        "URL": 155223,
        "CIDR": 5266
      },
      "indicator_count": 698651,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 57,
      "modified_text": "807 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "lyrytun.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "lyrytun.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780358198.2819626
}