{
  "type": "Domain",
  "indicator": "msiidentity.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/msiidentity.com",
    "alexa": "http://www.alexa.com/siteinfo/msiidentity.com",
    "indicator": "msiidentity.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4344026160,
      "indicator": "msiidentity.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 15,
      "pulses": [
        {
          "id": "69f9f99c0dc1060430bf089e",
          "name": "UAT-8302 and its box full of malware",
          "description": "UAT-8302 is a sophisticated China-nexus advanced persistent threat group targeting government entities in South America since late 2024 and southeastern Europe in 2025. The actor deploys multiple custom-made malware families including NetDraft, a .NET-based backdoor variant of FinalDraft/SquidDoor, and CloudSorcerer version 3. Post-compromise activities involve extensive reconnaissance, credential extraction, information collection from Active Directory, and network proliferation using tools like Impacket. The group establishes persistence through scheduled tasks and deploys additional malware including VSHELL, SNAPPYBEE/DeedRAT, and ZingDoor. UAT-8302 demonstrates connections to several China-nexus threat clusters through shared tooling, including Draculoader and SNOWLIGHT stager. The actor uses legitimate services like MS Graph and OneDrive for command-and-control infrastructure and establishes backdoor access through proxy servers using tools written in Simplified Chinese.",
          "modified": "2026-05-05T15:55:09.079000",
          "created": "2026-05-05T14:07:24.061000",
          "tags": [
            "fringeporch",
            "netdraft",
            "draculoader",
            "snowrust",
            "snowlight",
            "zingdoor",
            "finaldraft",
            "nosydoor",
            "vshell",
            "deedrat",
            "cloudsorcerer",
            "squiddoor",
            "snappybee"
          ],
          "references": [
            "https://blog.talosintelligence.com/uat-8302/"
          ],
          "public": 1,
          "adversary": "UAT-8302",
          "targeted_countries": [
            "Japan",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "NetDraft",
              "display_name": "NetDraft",
              "target": null
            },
            {
              "id": "FringePorch",
              "display_name": "FringePorch",
              "target": null
            },
            {
              "id": "CloudSorcerer",
              "display_name": "CloudSorcerer",
              "target": null
            },
            {
              "id": "VSHELL",
              "display_name": "VSHELL",
              "target": null
            },
            {
              "id": "SNOWLIGHT",
              "display_name": "SNOWLIGHT",
              "target": null
            },
            {
              "id": "SNOWRUST",
              "display_name": "SNOWRUST",
              "target": null
            },
            {
              "id": "DeedRAT",
              "display_name": "DeedRAT",
              "target": null
            },
            {
              "id": "SNAPPYBEE",
              "display_name": "SNAPPYBEE",
              "target": null
            },
            {
              "id": "ZingDoor",
              "display_name": "ZingDoor",
              "target": null
            },
            {
              "id": "Draculoader",
              "display_name": "Draculoader",
              "target": null
            },
            {
              "id": "FinalDraft",
              "display_name": "FinalDraft",
              "target": null
            },
            {
              "id": "SquidDoor",
              "display_name": "SquidDoor",
              "target": null
            },
            {
              "id": "NosyDoor",
              "display_name": "NosyDoor",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1053.005",
              "name": "Scheduled Task",
              "display_name": "T1053.005 - Scheduled Task"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1087.002",
              "name": "Domain Account",
              "display_name": "T1087.002 - Domain Account"
            },
            {
              "id": "T1087.001",
              "name": "Local Account",
              "display_name": "T1087.001 - Local Account"
            },
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1482",
              "name": "Domain Trust Discovery",
              "display_name": "T1482 - Domain Trust Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1570",
              "name": "Lateral Tool Transfer",
              "display_name": "T1570 - Lateral Tool Transfer"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [
            "Government",
            "Telecommunications",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 8,
            "CVE": 3,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 20,
            "URL": 4,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 50,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386452,
          "modified_text": "25 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "5fa1852d337eca8e99c2ec32",
          "name": "Malware - Malware Domain Feed V2 - November 03 2020",
          "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
          "modified": "2026-05-30T03:19:46.084000",
          "created": "2020-11-03T16:28:29.011000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 552123,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 3,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "otxrobottwo",
            "id": "78495",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_78495/resized/80/avatar_ba5a8acdbd.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 49967,
            "domain": 75353
          },
          "indicator_count": 125320,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1727,
          "modified_text": "18 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a05d87e1a72136955395ca3",
          "name": "Botnet_C2 | May 15, 2026",
          "description": "Botnet_C2 indicators. Date: May 15, 2026. Total: 1254 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-14T14:13:18.368000",
          "created": "2026-05-14T14:13:18.368000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "domain": 114,
            "hostname": 159,
            "URL": 111
          },
          "indicator_count": 389,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "16 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a04873aa32e956eec586c77",
          "name": "Botnet_C2 | May 14, 2026",
          "description": "Botnet_C2 indicators. Date: May 14, 2026. Total: 1170 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-13T14:14:18.218000",
          "created": "2026-05-13T14:14:18.218000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "hostname": 161,
            "URL": 112,
            "domain": 134
          },
          "indicator_count": 412,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "17 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0335a9ce1b312bb85367f7",
          "name": "Botnet_C2 | May 13, 2026",
          "description": "Botnet_C2 indicators. Date: May 13, 2026. Total: 1052 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-12T14:14:01.762000",
          "created": "2026-05-12T14:14:01.762000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "URL": 102,
            "domain": 140,
            "hostname": 165
          },
          "indicator_count": 412,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "18 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a02a0b3dd97f4bd74ca7622",
          "name": "IOC - UAT-8302 and its box full of malware",
          "description": "",
          "modified": "2026-05-12T03:38:27.036000",
          "created": "2026-05-12T03:38:27.036000",
          "tags": [
            "fringeporch",
            "netdraft",
            "draculoader",
            "snowrust",
            "snowlight",
            "zingdoor",
            "finaldraft",
            "nosydoor",
            "vshell",
            "deedrat",
            "cloudsorcerer",
            "squiddoor",
            "snappybee"
          ],
          "references": [
            "https://blog.talosintelligence.com/uat-8302/"
          ],
          "public": 1,
          "adversary": "UAT-8302",
          "targeted_countries": [
            "Japan",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "NetDraft",
              "display_name": "NetDraft",
              "target": null
            },
            {
              "id": "FringePorch",
              "display_name": "FringePorch",
              "target": null
            },
            {
              "id": "CloudSorcerer",
              "display_name": "CloudSorcerer",
              "target": null
            },
            {
              "id": "VSHELL",
              "display_name": "VSHELL",
              "target": null
            },
            {
              "id": "SNOWLIGHT",
              "display_name": "SNOWLIGHT",
              "target": null
            },
            {
              "id": "SNOWRUST",
              "display_name": "SNOWRUST",
              "target": null
            },
            {
              "id": "DeedRAT",
              "display_name": "DeedRAT",
              "target": null
            },
            {
              "id": "SNAPPYBEE",
              "display_name": "SNAPPYBEE",
              "target": null
            },
            {
              "id": "ZingDoor",
              "display_name": "ZingDoor",
              "target": null
            },
            {
              "id": "Draculoader",
              "display_name": "Draculoader",
              "target": null
            },
            {
              "id": "FinalDraft",
              "display_name": "FinalDraft",
              "target": null
            },
            {
              "id": "SquidDoor",
              "display_name": "SquidDoor",
              "target": null
            },
            {
              "id": "NosyDoor",
              "display_name": "NosyDoor",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1053.005",
              "name": "Scheduled Task",
              "display_name": "T1053.005 - Scheduled Task"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1087.002",
              "name": "Domain Account",
              "display_name": "T1087.002 - Domain Account"
            },
            {
              "id": "T1087.001",
              "name": "Local Account",
              "display_name": "T1087.001 - Local Account"
            },
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1482",
              "name": "Domain Trust Discovery",
              "display_name": "T1482 - Domain Trust Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1570",
              "name": "Lateral Tool Transfer",
              "display_name": "T1570 - Lateral Tool Transfer"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [
            "Government",
            "Telecommunications",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "69f9f99c0dc1060430bf089e",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "celestre",
            "id": "295357",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 8,
            "CVE": 3,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 20,
            "URL": 4,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 50,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 139,
          "modified_text": "18 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a01e4064798f56d423e2d96",
          "name": "Botnet_C2 | May 12, 2026",
          "description": "Botnet_C2 indicators. Date: May 12, 2026. Total: 945 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-11T14:13:26.060000",
          "created": "2026-05-11T14:13:26.060000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "hostname": 96,
            "domain": 145,
            "URL": 124
          },
          "indicator_count": 370,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "19 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a00928de04e9ba4cac1d6eb",
          "name": "Botnet_C2 | May 11, 2026",
          "description": "Botnet_C2 indicators. Date: May 11, 2026. Total: 861 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-10T14:13:33.465000",
          "created": "2026-05-10T14:13:33.465000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "URL": 133,
            "hostname": 112,
            "domain": 125
          },
          "indicator_count": 375,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 94,
          "modified_text": "20 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ff40f444f57576283e05ff",
          "name": "Botnet_C2 | May 10, 2026",
          "description": "Botnet_C2 indicators. Date: May 10, 2026. Total: 850 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-09T14:13:08.467000",
          "created": "2026-05-09T14:13:08.467000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "URL": 130,
            "hostname": 126,
            "domain": 107
          },
          "indicator_count": 368,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "21 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fdef814e48bf9214326ebd",
          "name": "Botnet_C2 | May 9, 2026",
          "description": "Botnet_C2 indicators. Date: May 9, 2026. Total: 890 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-08T14:13:21.488000",
          "created": "2026-05-08T14:13:21.488000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "hostname": 138,
            "URL": 133,
            "domain": 103
          },
          "indicator_count": 379,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "22 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fc4cf52edcbd28c6d1ee10",
          "name": "sgwrfsdf",
          "description": "Photography: Kaspersky/Google.com/Kasperska.org/Naspersy/RKP.net. and a list of other sites on the web that users can check.",
          "modified": "2026-05-07T08:27:33.317000",
          "created": "2026-05-07T08:27:33.317000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "harshandc123",
            "id": "378589",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 7,
            "FileHash-MD5": 12,
            "FileHash-SHA1": 12,
            "FileHash-SHA256": 12,
            "URL": 4,
            "domain": 2,
            "hostname": 3
          },
          "indicator_count": 52,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 16,
          "modified_text": "23 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fbad82234fc33123b0ce6d",
          "name": "EbeeMay2026 Pt1",
          "description": "Multiple APT/threat actors, Malware and Campaigns",
          "modified": "2026-05-06T21:07:14.769000",
          "created": "2026-05-06T21:07:14.769000",
          "tags": [
            "filehashsha256",
            "filehashmd5",
            "filehashsha1",
            "filepath",
            "localappdata",
            "cve20250994 cve",
            "temp",
            "mutex",
            "local"
          ],
          "references": [
            "IOCs-May1.csv"
          ],
          "public": 1,
          "adversary": "Trigona, PowerCod RAT, APT34, PhantomRaven, Hacked sites deliver infostealer, CloudZ RAT",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 80,
            "CIDR": 3,
            "CVE": 10,
            "FileHash-MD5": 154,
            "FileHash-SHA1": 140,
            "FileHash-SHA256": 219,
            "URL": 80,
            "domain": 82,
            "email": 8,
            "hostname": 60
          },
          "indicator_count": 836,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 39,
          "modified_text": "24 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fb1d8245861e48f4ee9ad5",
          "name": "['UAT-8302 and its box full of malware'] clone credit AlienVault",
          "description": "",
          "modified": "2026-05-06T10:57:43.983000",
          "created": "2026-05-06T10:52:50.152000",
          "tags": [
            "fringeporch",
            "netdraft",
            "draculoader",
            "snowrust",
            "snowlight",
            "zingdoor",
            "finaldraft",
            "nosydoor",
            "vshell",
            "deedrat",
            "cloudsorcerer",
            "squiddoor",
            "snappybee"
          ],
          "references": [
            "https://blog.talosintelligence.com/uat-8302/"
          ],
          "public": 1,
          "adversary": "UAT-8302",
          "targeted_countries": [
            "Japan",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "NetDraft",
              "display_name": "NetDraft",
              "target": null
            },
            {
              "id": "FringePorch",
              "display_name": "FringePorch",
              "target": null
            },
            {
              "id": "CloudSorcerer",
              "display_name": "CloudSorcerer",
              "target": null
            },
            {
              "id": "VSHELL",
              "display_name": "VSHELL",
              "target": null
            },
            {
              "id": "SNOWLIGHT",
              "display_name": "SNOWLIGHT",
              "target": null
            },
            {
              "id": "SNOWRUST",
              "display_name": "SNOWRUST",
              "target": null
            },
            {
              "id": "DeedRAT",
              "display_name": "DeedRAT",
              "target": null
            },
            {
              "id": "SNAPPYBEE",
              "display_name": "SNAPPYBEE",
              "target": null
            },
            {
              "id": "ZingDoor",
              "display_name": "ZingDoor",
              "target": null
            },
            {
              "id": "Draculoader",
              "display_name": "Draculoader",
              "target": null
            },
            {
              "id": "FinalDraft",
              "display_name": "FinalDraft",
              "target": null
            },
            {
              "id": "SquidDoor",
              "display_name": "SquidDoor",
              "target": null
            },
            {
              "id": "NosyDoor",
              "display_name": "NosyDoor",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1053.005",
              "name": "Scheduled Task",
              "display_name": "T1053.005 - Scheduled Task"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1087.002",
              "name": "Domain Account",
              "display_name": "T1087.002 - Domain Account"
            },
            {
              "id": "T1087.001",
              "name": "Local Account",
              "display_name": "T1087.001 - Local Account"
            },
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1482",
              "name": "Domain Trust Discovery",
              "display_name": "T1482 - Domain Trust Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1570",
              "name": "Lateral Tool Transfer",
              "display_name": "T1570 - Lateral Tool Transfer"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [
            "Government",
            "Telecommunications",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "69f9f99c0dc1060430bf089e",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 11,
            "CVE": 3,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 20,
            "URL": 4,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 53,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "24 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fabb599b517da83fe7f1d9",
          "name": "UAT-8302 and its box full of malware",
          "description": "",
          "modified": "2026-05-06T03:54:01.190000",
          "created": "2026-05-06T03:54:01.190000",
          "tags": [
            "fringeporch",
            "netdraft",
            "draculoader",
            "snowrust",
            "snowlight",
            "zingdoor",
            "finaldraft",
            "nosydoor",
            "vshell",
            "deedrat",
            "cloudsorcerer",
            "squiddoor",
            "snappybee"
          ],
          "references": [
            "https://blog.talosintelligence.com/uat-8302/"
          ],
          "public": 1,
          "adversary": "UAT-8302",
          "targeted_countries": [
            "Japan",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "NetDraft",
              "display_name": "NetDraft",
              "target": null
            },
            {
              "id": "FringePorch",
              "display_name": "FringePorch",
              "target": null
            },
            {
              "id": "CloudSorcerer",
              "display_name": "CloudSorcerer",
              "target": null
            },
            {
              "id": "VSHELL",
              "display_name": "VSHELL",
              "target": null
            },
            {
              "id": "SNOWLIGHT",
              "display_name": "SNOWLIGHT",
              "target": null
            },
            {
              "id": "SNOWRUST",
              "display_name": "SNOWRUST",
              "target": null
            },
            {
              "id": "DeedRAT",
              "display_name": "DeedRAT",
              "target": null
            },
            {
              "id": "SNAPPYBEE",
              "display_name": "SNAPPYBEE",
              "target": null
            },
            {
              "id": "ZingDoor",
              "display_name": "ZingDoor",
              "target": null
            },
            {
              "id": "Draculoader",
              "display_name": "Draculoader",
              "target": null
            },
            {
              "id": "FinalDraft",
              "display_name": "FinalDraft",
              "target": null
            },
            {
              "id": "SquidDoor",
              "display_name": "SquidDoor",
              "target": null
            },
            {
              "id": "NosyDoor",
              "display_name": "NosyDoor",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1053.005",
              "name": "Scheduled Task",
              "display_name": "T1053.005 - Scheduled Task"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1087.002",
              "name": "Domain Account",
              "display_name": "T1087.002 - Domain Account"
            },
            {
              "id": "T1087.001",
              "name": "Local Account",
              "display_name": "T1087.001 - Local Account"
            },
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1482",
              "name": "Domain Trust Discovery",
              "display_name": "T1482 - Domain Trust Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1570",
              "name": "Lateral Tool Transfer",
              "display_name": "T1570 - Lateral Tool Transfer"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [
            "Government",
            "Telecommunications",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "69f9f99c0dc1060430bf089e",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 8,
            "CVE": 3,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 20,
            "URL": 4,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 50,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 278,
          "modified_text": "24 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fabb550dac4e682d0276ed",
          "name": "UAT-8302 and its box full of malware",
          "description": "",
          "modified": "2026-05-06T03:53:57.321000",
          "created": "2026-05-06T03:53:57.321000",
          "tags": [
            "fringeporch",
            "netdraft",
            "draculoader",
            "snowrust",
            "snowlight",
            "zingdoor",
            "finaldraft",
            "nosydoor",
            "vshell",
            "deedrat",
            "cloudsorcerer",
            "squiddoor",
            "snappybee"
          ],
          "references": [
            "https://blog.talosintelligence.com/uat-8302/"
          ],
          "public": 1,
          "adversary": "UAT-8302",
          "targeted_countries": [
            "Japan",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "NetDraft",
              "display_name": "NetDraft",
              "target": null
            },
            {
              "id": "FringePorch",
              "display_name": "FringePorch",
              "target": null
            },
            {
              "id": "CloudSorcerer",
              "display_name": "CloudSorcerer",
              "target": null
            },
            {
              "id": "VSHELL",
              "display_name": "VSHELL",
              "target": null
            },
            {
              "id": "SNOWLIGHT",
              "display_name": "SNOWLIGHT",
              "target": null
            },
            {
              "id": "SNOWRUST",
              "display_name": "SNOWRUST",
              "target": null
            },
            {
              "id": "DeedRAT",
              "display_name": "DeedRAT",
              "target": null
            },
            {
              "id": "SNAPPYBEE",
              "display_name": "SNAPPYBEE",
              "target": null
            },
            {
              "id": "ZingDoor",
              "display_name": "ZingDoor",
              "target": null
            },
            {
              "id": "Draculoader",
              "display_name": "Draculoader",
              "target": null
            },
            {
              "id": "FinalDraft",
              "display_name": "FinalDraft",
              "target": null
            },
            {
              "id": "SquidDoor",
              "display_name": "SquidDoor",
              "target": null
            },
            {
              "id": "NosyDoor",
              "display_name": "NosyDoor",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1053.005",
              "name": "Scheduled Task",
              "display_name": "T1053.005 - Scheduled Task"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1087.002",
              "name": "Domain Account",
              "display_name": "T1087.002 - Domain Account"
            },
            {
              "id": "T1087.001",
              "name": "Local Account",
              "display_name": "T1087.001 - Local Account"
            },
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1482",
              "name": "Domain Trust Discovery",
              "display_name": "T1482 - Domain Trust Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1570",
              "name": "Lateral Tool Transfer",
              "display_name": "T1570 - Lateral Tool Transfer"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [
            "Government",
            "Telecommunications",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "69f9f99c0dc1060430bf089e",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 8,
            "CVE": 3,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 20,
            "URL": 4,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 50,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 278,
          "modified_text": "24 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://blog.talosintelligence.com/uat-8302/",
        "IOCs-May1.csv",
        "https://ltna.com.au/cyber"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "UAT-8302"
          ],
          "malware_families": [
            "Snowrust",
            "Finaldraft",
            "Squiddoor",
            "Deedrat",
            "Snowlight",
            "Nosydoor",
            "Draculoader",
            "Cloudsorcerer",
            "Vshell",
            "Fringeporch",
            "Netdraft",
            "Zingdoor",
            "Snappybee"
          ],
          "industries": [
            "Technology",
            "Government",
            "Telecommunications"
          ]
        },
        "other": {
          "adversary": [
            "Trigona, PowerCod RAT, APT34, PhantomRaven, Hacked sites deliver infostealer, CloudZ RAT",
            "UAT-8302"
          ],
          "malware_families": [
            "Snowrust",
            "Finaldraft",
            "Squiddoor",
            "Deedrat",
            "Snowlight",
            "Nosydoor",
            "Draculoader",
            "Cloudsorcerer",
            "Vshell",
            "Fringeporch",
            "Netdraft",
            "Zingdoor",
            "Snappybee"
          ],
          "industries": [
            "Technology",
            "Government",
            "Telecommunications"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 15,
  "pulses": [
    {
      "id": "69f9f99c0dc1060430bf089e",
      "name": "UAT-8302 and its box full of malware",
      "description": "UAT-8302 is a sophisticated China-nexus advanced persistent threat group targeting government entities in South America since late 2024 and southeastern Europe in 2025. The actor deploys multiple custom-made malware families including NetDraft, a .NET-based backdoor variant of FinalDraft/SquidDoor, and CloudSorcerer version 3. Post-compromise activities involve extensive reconnaissance, credential extraction, information collection from Active Directory, and network proliferation using tools like Impacket. The group establishes persistence through scheduled tasks and deploys additional malware including VSHELL, SNAPPYBEE/DeedRAT, and ZingDoor. UAT-8302 demonstrates connections to several China-nexus threat clusters through shared tooling, including Draculoader and SNOWLIGHT stager. The actor uses legitimate services like MS Graph and OneDrive for command-and-control infrastructure and establishes backdoor access through proxy servers using tools written in Simplified Chinese.",
      "modified": "2026-05-05T15:55:09.079000",
      "created": "2026-05-05T14:07:24.061000",
      "tags": [
        "fringeporch",
        "netdraft",
        "draculoader",
        "snowrust",
        "snowlight",
        "zingdoor",
        "finaldraft",
        "nosydoor",
        "vshell",
        "deedrat",
        "cloudsorcerer",
        "squiddoor",
        "snappybee"
      ],
      "references": [
        "https://blog.talosintelligence.com/uat-8302/"
      ],
      "public": 1,
      "adversary": "UAT-8302",
      "targeted_countries": [
        "Japan",
        "Russian Federation"
      ],
      "malware_families": [
        {
          "id": "NetDraft",
          "display_name": "NetDraft",
          "target": null
        },
        {
          "id": "FringePorch",
          "display_name": "FringePorch",
          "target": null
        },
        {
          "id": "CloudSorcerer",
          "display_name": "CloudSorcerer",
          "target": null
        },
        {
          "id": "VSHELL",
          "display_name": "VSHELL",
          "target": null
        },
        {
          "id": "SNOWLIGHT",
          "display_name": "SNOWLIGHT",
          "target": null
        },
        {
          "id": "SNOWRUST",
          "display_name": "SNOWRUST",
          "target": null
        },
        {
          "id": "DeedRAT",
          "display_name": "DeedRAT",
          "target": null
        },
        {
          "id": "SNAPPYBEE",
          "display_name": "SNAPPYBEE",
          "target": null
        },
        {
          "id": "ZingDoor",
          "display_name": "ZingDoor",
          "target": null
        },
        {
          "id": "Draculoader",
          "display_name": "Draculoader",
          "target": null
        },
        {
          "id": "FinalDraft",
          "display_name": "FinalDraft",
          "target": null
        },
        {
          "id": "SquidDoor",
          "display_name": "SquidDoor",
          "target": null
        },
        {
          "id": "NosyDoor",
          "display_name": "NosyDoor",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1053.005",
          "name": "Scheduled Task",
          "display_name": "T1053.005 - Scheduled Task"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1087.002",
          "name": "Domain Account",
          "display_name": "T1087.002 - Domain Account"
        },
        {
          "id": "T1087.001",
          "name": "Local Account",
          "display_name": "T1087.001 - Local Account"
        },
        {
          "id": "T1135",
          "name": "Network Share Discovery",
          "display_name": "T1135 - Network Share Discovery"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1482",
          "name": "Domain Trust Discovery",
          "display_name": "T1482 - Domain Trust Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1570",
          "name": "Lateral Tool Transfer",
          "display_name": "T1570 - Lateral Tool Transfer"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [
        "Government",
        "Telecommunications",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 8,
        "CVE": 3,
        "FileHash-MD5": 6,
        "FileHash-SHA1": 6,
        "FileHash-SHA256": 20,
        "URL": 4,
        "domain": 2,
        "hostname": 1
      },
      "indicator_count": 50,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386452,
      "modified_text": "25 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "5fa1852d337eca8e99c2ec32",
      "name": "Malware - Malware Domain Feed V2 - November 03 2020",
      "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
      "modified": "2026-05-30T03:19:46.084000",
      "created": "2020-11-03T16:28:29.011000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 552123,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 3,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "otxrobottwo",
        "id": "78495",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_78495/resized/80/avatar_ba5a8acdbd.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 49967,
        "domain": 75353
      },
      "indicator_count": 125320,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1727,
      "modified_text": "18 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a05d87e1a72136955395ca3",
      "name": "Botnet_C2 | May 15, 2026",
      "description": "Botnet_C2 indicators. Date: May 15, 2026. Total: 1254 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-14T14:13:18.368000",
      "created": "2026-05-14T14:13:18.368000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "domain": 114,
        "hostname": 159,
        "URL": 111
      },
      "indicator_count": 389,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "16 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a04873aa32e956eec586c77",
      "name": "Botnet_C2 | May 14, 2026",
      "description": "Botnet_C2 indicators. Date: May 14, 2026. Total: 1170 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-13T14:14:18.218000",
      "created": "2026-05-13T14:14:18.218000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "hostname": 161,
        "URL": 112,
        "domain": 134
      },
      "indicator_count": 412,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "17 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a0335a9ce1b312bb85367f7",
      "name": "Botnet_C2 | May 13, 2026",
      "description": "Botnet_C2 indicators. Date: May 13, 2026. Total: 1052 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-12T14:14:01.762000",
      "created": "2026-05-12T14:14:01.762000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "URL": 102,
        "domain": 140,
        "hostname": 165
      },
      "indicator_count": 412,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 91,
      "modified_text": "18 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a02a0b3dd97f4bd74ca7622",
      "name": "IOC - UAT-8302 and its box full of malware",
      "description": "",
      "modified": "2026-05-12T03:38:27.036000",
      "created": "2026-05-12T03:38:27.036000",
      "tags": [
        "fringeporch",
        "netdraft",
        "draculoader",
        "snowrust",
        "snowlight",
        "zingdoor",
        "finaldraft",
        "nosydoor",
        "vshell",
        "deedrat",
        "cloudsorcerer",
        "squiddoor",
        "snappybee"
      ],
      "references": [
        "https://blog.talosintelligence.com/uat-8302/"
      ],
      "public": 1,
      "adversary": "UAT-8302",
      "targeted_countries": [
        "Japan",
        "Russian Federation"
      ],
      "malware_families": [
        {
          "id": "NetDraft",
          "display_name": "NetDraft",
          "target": null
        },
        {
          "id": "FringePorch",
          "display_name": "FringePorch",
          "target": null
        },
        {
          "id": "CloudSorcerer",
          "display_name": "CloudSorcerer",
          "target": null
        },
        {
          "id": "VSHELL",
          "display_name": "VSHELL",
          "target": null
        },
        {
          "id": "SNOWLIGHT",
          "display_name": "SNOWLIGHT",
          "target": null
        },
        {
          "id": "SNOWRUST",
          "display_name": "SNOWRUST",
          "target": null
        },
        {
          "id": "DeedRAT",
          "display_name": "DeedRAT",
          "target": null
        },
        {
          "id": "SNAPPYBEE",
          "display_name": "SNAPPYBEE",
          "target": null
        },
        {
          "id": "ZingDoor",
          "display_name": "ZingDoor",
          "target": null
        },
        {
          "id": "Draculoader",
          "display_name": "Draculoader",
          "target": null
        },
        {
          "id": "FinalDraft",
          "display_name": "FinalDraft",
          "target": null
        },
        {
          "id": "SquidDoor",
          "display_name": "SquidDoor",
          "target": null
        },
        {
          "id": "NosyDoor",
          "display_name": "NosyDoor",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1053.005",
          "name": "Scheduled Task",
          "display_name": "T1053.005 - Scheduled Task"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1087.002",
          "name": "Domain Account",
          "display_name": "T1087.002 - Domain Account"
        },
        {
          "id": "T1087.001",
          "name": "Local Account",
          "display_name": "T1087.001 - Local Account"
        },
        {
          "id": "T1135",
          "name": "Network Share Discovery",
          "display_name": "T1135 - Network Share Discovery"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1482",
          "name": "Domain Trust Discovery",
          "display_name": "T1482 - Domain Trust Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1570",
          "name": "Lateral Tool Transfer",
          "display_name": "T1570 - Lateral Tool Transfer"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [
        "Government",
        "Telecommunications",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": "69f9f99c0dc1060430bf089e",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "celestre",
        "id": "295357",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 8,
        "CVE": 3,
        "FileHash-MD5": 6,
        "FileHash-SHA1": 6,
        "FileHash-SHA256": 20,
        "URL": 4,
        "domain": 2,
        "hostname": 1
      },
      "indicator_count": 50,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 139,
      "modified_text": "18 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a01e4064798f56d423e2d96",
      "name": "Botnet_C2 | May 12, 2026",
      "description": "Botnet_C2 indicators. Date: May 12, 2026. Total: 945 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-11T14:13:26.060000",
      "created": "2026-05-11T14:13:26.060000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "hostname": 96,
        "domain": 145,
        "URL": 124
      },
      "indicator_count": 370,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "19 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a00928de04e9ba4cac1d6eb",
      "name": "Botnet_C2 | May 11, 2026",
      "description": "Botnet_C2 indicators. Date: May 11, 2026. Total: 861 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-10T14:13:33.465000",
      "created": "2026-05-10T14:13:33.465000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "URL": 133,
        "hostname": 112,
        "domain": 125
      },
      "indicator_count": 375,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 94,
      "modified_text": "20 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69ff40f444f57576283e05ff",
      "name": "Botnet_C2 | May 10, 2026",
      "description": "Botnet_C2 indicators. Date: May 10, 2026. Total: 850 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-09T14:13:08.467000",
      "created": "2026-05-09T14:13:08.467000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "URL": 130,
        "hostname": 126,
        "domain": 107
      },
      "indicator_count": 368,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 91,
      "modified_text": "21 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69fdef814e48bf9214326ebd",
      "name": "Botnet_C2 | May 9, 2026",
      "description": "Botnet_C2 indicators. Date: May 9, 2026. Total: 890 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-08T14:13:21.488000",
      "created": "2026-05-08T14:13:21.488000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "hostname": 138,
        "URL": 133,
        "domain": 103
      },
      "indicator_count": 379,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "22 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "msiidentity.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "msiidentity.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780176078.531692
}