{
  "type": "Domain",
  "indicator": "mtcserver.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/mtcserver.com",
    "alexa": "http://www.alexa.com/siteinfo/mtcserver.com",
    "indicator": "mtcserver.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2864668406,
      "indicator": "mtcserver.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "69eb0b13472f13e2e8b70a32",
          "name": "osidnahoo",
          "description": "A look at some of the key events in the search for a secure certificate:- or, rather, a complete list of them - that were not found, as they were reported::.",
          "modified": "2026-05-24T06:33:56.814000",
          "created": "2026-04-24T06:17:55.366000",
          "tags": [
            "common name",
            "date",
            "gmt contenttype",
            "statesunited",
            "server",
            "found",
            "moved",
            "ssl certificate",
            "issued",
            "gmt connection",
            "info",
            "encrypt",
            "contact",
            "ovh telecom",
            "francefrance",
            "paris",
            "sitch message",
            "home",
            "softcom gmbh",
            "germanygermany",
            "berlin ssl",
            "certificate",
            "v3 teletech",
            "pte ltd",
            "taiwantaiwan",
            "key type",
            "telefonica de",
            "spainspain",
            "barcelona",
            "time",
            "user port",
            "stor msam",
            "rnto nlst",
            "mkd cdup",
            "comcast ip",
            "derry village",
            "comcast cable",
            "communications",
            "llc united",
            "boston",
            "premium"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 16,
            "URL": 157,
            "domain": 236,
            "hostname": 295,
            "email": 7,
            "FileHash-SHA256": 252,
            "FileHash-MD5": 4
          },
          "indicator_count": 967,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "7 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65a94472aa9ff38469be19b0",
          "name": "trojan.mydoom/memscan | .911porn.org embedded, interacting, Google PlayStore products",
          "description": "Found in a compromised android phone. Redline  Stealer, WebToolbar, SearchSuite. Pseudo Google Chrome. Google PlayStore Wallet won't credit $100's victims Visa & Google Play card .  Unhelpful if any responses, multiple complaints by others with same issue. Why not research. Target/ client complained, unhelpful response from developers, Google Chrome changed to a china based pseudo Chrome.",
          "modified": "2024-02-17T08:04:16.055000",
          "created": "2024-01-18T15:32:02.682000",
          "tags": [
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "samples",
            "ssl certificate",
            "contacted",
            "network",
            "whois record",
            "historical ssl",
            "malware",
            "resolutions",
            "communicating",
            "referrer",
            "domains",
            "registrar",
            "thnic",
            "dynadot inc",
            "final url",
            "urls",
            "whois whois",
            "execution",
            "contacted urls",
            "apple",
            "redline stealer",
            "core",
            "subdomains",
            "first",
            "utc submissions",
            "submitters",
            "ltd dba",
            "com laude",
            "edgecast",
            "gandi sas",
            "csc corporate",
            "summary iocs",
            "facebook",
            "fbnoscript1",
            "as14061",
            "united",
            "whitelisted",
            "as16276",
            "a domains",
            "united kingdom",
            "script urls",
            "name servers",
            "as9009 m247",
            "backdoor",
            "ransom",
            "meta",
            "msil",
            "date",
            "malvertizing",
            "elevated exposure",
            "contextualizing",
            "cve -2023-22518",
            "cve-2017-17215",
            "contains-pe",
            "upx",
            "contains-macho attachment",
            "contains-embedded-js",
            "nsis",
            "pecompact",
            "wear os",
            "android phone",
            "gmail app",
            "smart reply",
            "meet  respond",
            "meet",
            "respond",
            "google",
            "google chat",
            "gmail",
            "et",
            "playstore",
            "dns",
            "browser events",
            "critical",
            "tsara brashears",
            "unhacker"
          ],
          "references": [
            "http://911porn.org/home.php?mod=space&uid=47570&do=profile&from=space",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "youjazz.911porn.org",
            "gimmebar.com",
            "datafoundry.com",
            "dataconnector.corp.google.com",
            "js.stripe.com [url redirects to]",
            "CVE-2023-22518",
            "https://bi.phncdn.com/www-static/js/lib/generated-lib.js?cache=2017051919",
            "206.189.61.126 [command and control]",
            "https://quantilnetworks.com/ [phishing]",
            "brazzersnetwork.com",
            "brazzers.com",
            "http://missing.hi2.ro/missing.html [malware hosting]",
            "nsscacheserver2.corp.google.com",
            "xred.mooo.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Netherlands",
            "Romania",
            "Russian Federation",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "ALF:Trojan:BAT/EnvVarCharReplacement.Custom",
              "display_name": "ALF:Trojan:BAT/EnvVarCharReplacement.Custom",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win64/PsBanker.MFP!MTB",
              "display_name": "ALF:Trojan:Win64/PsBanker.MFP!MTB",
              "target": null
            },
            {
              "id": "Backdoor:MSIL/AsyncRAT.ZB!MTB",
              "display_name": "Backdoor:MSIL/AsyncRAT.ZB!MTB",
              "target": "/malware/Backdoor:MSIL/AsyncRAT.ZB!MTB"
            },
            {
              "id": "Ransom:Win32/Somhoveran.C",
              "display_name": "Ransom:Win32/Somhoveran.C",
              "target": "/malware/Ransom:Win32/Somhoveran.C"
            },
            {
              "id": "Ransom:Win32/Genasom.AM",
              "display_name": "Ransom:Win32/Genasom.AM",
              "target": "/malware/Ransom:Win32/Genasom.AM"
            },
            {
              "id": "PWS:Win32/PrimaryPass.AD!MTB",
              "display_name": "PWS:Win32/PrimaryPass.AD!MTB",
              "target": "/malware/PWS:Win32/PrimaryPass.AD!MTB"
            },
            {
              "id": "MSIL:GenMalicious-ZC\\ [Trj]",
              "display_name": "MSIL:GenMalicious-ZC\\ [Trj]",
              "target": null
            },
            {
              "id": "Backdoor:Win32/VB.KQ",
              "display_name": "Backdoor:Win32/VB.KQ",
              "target": "/malware/Backdoor:Win32/VB.KQ"
            },
            {
              "id": "Backdoor:Win32/Tofsee.T",
              "display_name": "Backdoor:Win32/Tofsee.T",
              "target": "/malware/Backdoor:Win32/Tofsee.T"
            },
            {
              "id": "Backdoor:MSIL/Bladabindi.AJ",
              "display_name": "Backdoor:MSIL/Bladabindi.AJ",
              "target": "/malware/Backdoor:MSIL/Bladabindi.AJ"
            },
            {
              "id": "trojan.mydoom/memscan",
              "display_name": "trojan.mydoom/memscan",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 566,
            "FileHash-SHA1": 324,
            "FileHash-SHA256": 1828,
            "URL": 3171,
            "domain": 1145,
            "hostname": 1556,
            "CVE": 2,
            "email": 4
          },
          "indicator_count": 8596,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "834 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65aab9b6e5834eef98066f6d",
          "name": "Author avatar trojan.mydoom/memscan | .911porn.org Google embedded  interacting, ",
          "description": "",
          "modified": "2024-02-17T08:04:16.055000",
          "created": "2024-01-19T18:04:38.254000",
          "tags": [
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "samples",
            "ssl certificate",
            "contacted",
            "network",
            "whois record",
            "historical ssl",
            "malware",
            "resolutions",
            "communicating",
            "referrer",
            "domains",
            "registrar",
            "thnic",
            "dynadot inc",
            "final url",
            "urls",
            "whois whois",
            "execution",
            "contacted urls",
            "apple",
            "redline stealer",
            "core",
            "subdomains",
            "first",
            "utc submissions",
            "submitters",
            "ltd dba",
            "com laude",
            "edgecast",
            "gandi sas",
            "csc corporate",
            "summary iocs",
            "facebook",
            "fbnoscript1",
            "as14061",
            "united",
            "whitelisted",
            "as16276",
            "a domains",
            "united kingdom",
            "script urls",
            "name servers",
            "as9009 m247",
            "backdoor",
            "ransom",
            "meta",
            "msil",
            "date",
            "malvertizing",
            "elevated exposure",
            "contextualizing",
            "cve -2023-22518",
            "cve-2017-17215",
            "contains-pe",
            "upx",
            "contains-macho attachment",
            "contains-embedded-js",
            "nsis",
            "pecompact",
            "wear os",
            "android phone",
            "gmail app",
            "smart reply",
            "meet  respond",
            "meet",
            "respond",
            "google",
            "google chat",
            "gmail",
            "et",
            "playstore",
            "dns",
            "browser events",
            "critical",
            "tsara brashears",
            "unhacker"
          ],
          "references": [
            "http://911porn.org/home.php?mod=space&uid=47570&do=profile&from=space",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "youjazz.911porn.org",
            "gimmebar.com",
            "datafoundry.com",
            "dataconnector.corp.google.com",
            "js.stripe.com [url redirects to]",
            "CVE-2023-22518",
            "https://bi.phncdn.com/www-static/js/lib/generated-lib.js?cache=2017051919",
            "206.189.61.126 [command and control]",
            "https://quantilnetworks.com/ [phishing]",
            "brazzersnetwork.com",
            "brazzers.com",
            "http://missing.hi2.ro/missing.html [malware hosting]",
            "nsscacheserver2.corp.google.com",
            "xred.mooo.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Netherlands",
            "Romania",
            "Russian Federation",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "ALF:Trojan:BAT/EnvVarCharReplacement.Custom",
              "display_name": "ALF:Trojan:BAT/EnvVarCharReplacement.Custom",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win64/PsBanker.MFP!MTB",
              "display_name": "ALF:Trojan:Win64/PsBanker.MFP!MTB",
              "target": null
            },
            {
              "id": "Backdoor:MSIL/AsyncRAT.ZB!MTB",
              "display_name": "Backdoor:MSIL/AsyncRAT.ZB!MTB",
              "target": "/malware/Backdoor:MSIL/AsyncRAT.ZB!MTB"
            },
            {
              "id": "Ransom:Win32/Somhoveran.C",
              "display_name": "Ransom:Win32/Somhoveran.C",
              "target": "/malware/Ransom:Win32/Somhoveran.C"
            },
            {
              "id": "Ransom:Win32/Genasom.AM",
              "display_name": "Ransom:Win32/Genasom.AM",
              "target": "/malware/Ransom:Win32/Genasom.AM"
            },
            {
              "id": "PWS:Win32/PrimaryPass.AD!MTB",
              "display_name": "PWS:Win32/PrimaryPass.AD!MTB",
              "target": "/malware/PWS:Win32/PrimaryPass.AD!MTB"
            },
            {
              "id": "MSIL:GenMalicious-ZC\\ [Trj]",
              "display_name": "MSIL:GenMalicious-ZC\\ [Trj]",
              "target": null
            },
            {
              "id": "Backdoor:Win32/VB.KQ",
              "display_name": "Backdoor:Win32/VB.KQ",
              "target": "/malware/Backdoor:Win32/VB.KQ"
            },
            {
              "id": "Backdoor:Win32/Tofsee.T",
              "display_name": "Backdoor:Win32/Tofsee.T",
              "target": "/malware/Backdoor:Win32/Tofsee.T"
            },
            {
              "id": "Backdoor:MSIL/Bladabindi.AJ",
              "display_name": "Backdoor:MSIL/Bladabindi.AJ",
              "target": "/malware/Backdoor:MSIL/Bladabindi.AJ"
            },
            {
              "id": "trojan.mydoom/memscan",
              "display_name": "trojan.mydoom/memscan",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65a94472aa9ff38469be19b0",
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 566,
            "FileHash-SHA1": 324,
            "FileHash-SHA256": 1828,
            "URL": 3171,
            "domain": 1145,
            "hostname": 1556,
            "CVE": 2,
            "email": 4
          },
          "indicator_count": 8596,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "834 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "datafoundry.com",
        "brazzersnetwork.com",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "CVE-2023-22518",
        "brazzers.com",
        "http://911porn.org/home.php?mod=space&uid=47570&do=profile&from=space",
        "dataconnector.corp.google.com",
        "js.stripe.com [url redirects to]",
        "206.189.61.126 [command and control]",
        "https://quantilnetworks.com/ [phishing]",
        "http://missing.hi2.ro/missing.html [malware hosting]",
        "youjazz.911porn.org",
        "gimmebar.com",
        "https://bi.phncdn.com/www-static/js/lib/generated-lib.js?cache=2017051919",
        "nsscacheserver2.corp.google.com",
        "xred.mooo.com"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Backdoor:msil/bladabindi.aj",
            "Backdoor:win32/tofsee.t",
            "Ransom:win32/somhoveran.c",
            "Ransom:win32/genasom.am",
            "Pws:win32/primarypass.ad!mtb",
            "Alf:trojan:win64/psbanker.mfp!mtb",
            "Backdoor:msil/asyncrat.zb!mtb",
            "Msil:genmalicious-zc\\ [trj]",
            "Redline stealer",
            "Backdoor:win32/vb.kq",
            "Trojan.mydoom/memscan",
            "Alf:trojan:bat/envvarcharreplacement.custom",
            "Nsis"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "69eb0b13472f13e2e8b70a32",
      "name": "osidnahoo",
      "description": "A look at some of the key events in the search for a secure certificate:- or, rather, a complete list of them - that were not found, as they were reported::.",
      "modified": "2026-05-24T06:33:56.814000",
      "created": "2026-04-24T06:17:55.366000",
      "tags": [
        "common name",
        "date",
        "gmt contenttype",
        "statesunited",
        "server",
        "found",
        "moved",
        "ssl certificate",
        "issued",
        "gmt connection",
        "info",
        "encrypt",
        "contact",
        "ovh telecom",
        "francefrance",
        "paris",
        "sitch message",
        "home",
        "softcom gmbh",
        "germanygermany",
        "berlin ssl",
        "certificate",
        "v3 teletech",
        "pte ltd",
        "taiwantaiwan",
        "key type",
        "telefonica de",
        "spainspain",
        "barcelona",
        "time",
        "user port",
        "stor msam",
        "rnto nlst",
        "mkd cdup",
        "comcast ip",
        "derry village",
        "comcast cable",
        "communications",
        "llc united",
        "boston",
        "premium"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 16,
        "URL": 157,
        "domain": 236,
        "hostname": 295,
        "email": 7,
        "FileHash-SHA256": 252,
        "FileHash-MD5": 4
      },
      "indicator_count": 967,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "7 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65a94472aa9ff38469be19b0",
      "name": "trojan.mydoom/memscan | .911porn.org embedded, interacting, Google PlayStore products",
      "description": "Found in a compromised android phone. Redline  Stealer, WebToolbar, SearchSuite. Pseudo Google Chrome. Google PlayStore Wallet won't credit $100's victims Visa & Google Play card .  Unhelpful if any responses, multiple complaints by others with same issue. Why not research. Target/ client complained, unhelpful response from developers, Google Chrome changed to a china based pseudo Chrome.",
      "modified": "2024-02-17T08:04:16.055000",
      "created": "2024-01-18T15:32:02.682000",
      "tags": [
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "samples",
        "ssl certificate",
        "contacted",
        "network",
        "whois record",
        "historical ssl",
        "malware",
        "resolutions",
        "communicating",
        "referrer",
        "domains",
        "registrar",
        "thnic",
        "dynadot inc",
        "final url",
        "urls",
        "whois whois",
        "execution",
        "contacted urls",
        "apple",
        "redline stealer",
        "core",
        "subdomains",
        "first",
        "utc submissions",
        "submitters",
        "ltd dba",
        "com laude",
        "edgecast",
        "gandi sas",
        "csc corporate",
        "summary iocs",
        "facebook",
        "fbnoscript1",
        "as14061",
        "united",
        "whitelisted",
        "as16276",
        "a domains",
        "united kingdom",
        "script urls",
        "name servers",
        "as9009 m247",
        "backdoor",
        "ransom",
        "meta",
        "msil",
        "date",
        "malvertizing",
        "elevated exposure",
        "contextualizing",
        "cve -2023-22518",
        "cve-2017-17215",
        "contains-pe",
        "upx",
        "contains-macho attachment",
        "contains-embedded-js",
        "nsis",
        "pecompact",
        "wear os",
        "android phone",
        "gmail app",
        "smart reply",
        "meet  respond",
        "meet",
        "respond",
        "google",
        "google chat",
        "gmail",
        "et",
        "playstore",
        "dns",
        "browser events",
        "critical",
        "tsara brashears",
        "unhacker"
      ],
      "references": [
        "http://911porn.org/home.php?mod=space&uid=47570&do=profile&from=space",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "youjazz.911porn.org",
        "gimmebar.com",
        "datafoundry.com",
        "dataconnector.corp.google.com",
        "js.stripe.com [url redirects to]",
        "CVE-2023-22518",
        "https://bi.phncdn.com/www-static/js/lib/generated-lib.js?cache=2017051919",
        "206.189.61.126 [command and control]",
        "https://quantilnetworks.com/ [phishing]",
        "brazzersnetwork.com",
        "brazzers.com",
        "http://missing.hi2.ro/missing.html [malware hosting]",
        "nsscacheserver2.corp.google.com",
        "xred.mooo.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Netherlands",
        "Romania",
        "Russian Federation",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "ALF:Trojan:BAT/EnvVarCharReplacement.Custom",
          "display_name": "ALF:Trojan:BAT/EnvVarCharReplacement.Custom",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win64/PsBanker.MFP!MTB",
          "display_name": "ALF:Trojan:Win64/PsBanker.MFP!MTB",
          "target": null
        },
        {
          "id": "Backdoor:MSIL/AsyncRAT.ZB!MTB",
          "display_name": "Backdoor:MSIL/AsyncRAT.ZB!MTB",
          "target": "/malware/Backdoor:MSIL/AsyncRAT.ZB!MTB"
        },
        {
          "id": "Ransom:Win32/Somhoveran.C",
          "display_name": "Ransom:Win32/Somhoveran.C",
          "target": "/malware/Ransom:Win32/Somhoveran.C"
        },
        {
          "id": "Ransom:Win32/Genasom.AM",
          "display_name": "Ransom:Win32/Genasom.AM",
          "target": "/malware/Ransom:Win32/Genasom.AM"
        },
        {
          "id": "PWS:Win32/PrimaryPass.AD!MTB",
          "display_name": "PWS:Win32/PrimaryPass.AD!MTB",
          "target": "/malware/PWS:Win32/PrimaryPass.AD!MTB"
        },
        {
          "id": "MSIL:GenMalicious-ZC\\ [Trj]",
          "display_name": "MSIL:GenMalicious-ZC\\ [Trj]",
          "target": null
        },
        {
          "id": "Backdoor:Win32/VB.KQ",
          "display_name": "Backdoor:Win32/VB.KQ",
          "target": "/malware/Backdoor:Win32/VB.KQ"
        },
        {
          "id": "Backdoor:Win32/Tofsee.T",
          "display_name": "Backdoor:Win32/Tofsee.T",
          "target": "/malware/Backdoor:Win32/Tofsee.T"
        },
        {
          "id": "Backdoor:MSIL/Bladabindi.AJ",
          "display_name": "Backdoor:MSIL/Bladabindi.AJ",
          "target": "/malware/Backdoor:MSIL/Bladabindi.AJ"
        },
        {
          "id": "trojan.mydoom/memscan",
          "display_name": "trojan.mydoom/memscan",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "NSIS",
          "display_name": "NSIS",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 566,
        "FileHash-SHA1": 324,
        "FileHash-SHA256": 1828,
        "URL": 3171,
        "domain": 1145,
        "hostname": 1556,
        "CVE": 2,
        "email": 4
      },
      "indicator_count": 8596,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "834 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65aab9b6e5834eef98066f6d",
      "name": "Author avatar trojan.mydoom/memscan | .911porn.org Google embedded  interacting, ",
      "description": "",
      "modified": "2024-02-17T08:04:16.055000",
      "created": "2024-01-19T18:04:38.254000",
      "tags": [
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "samples",
        "ssl certificate",
        "contacted",
        "network",
        "whois record",
        "historical ssl",
        "malware",
        "resolutions",
        "communicating",
        "referrer",
        "domains",
        "registrar",
        "thnic",
        "dynadot inc",
        "final url",
        "urls",
        "whois whois",
        "execution",
        "contacted urls",
        "apple",
        "redline stealer",
        "core",
        "subdomains",
        "first",
        "utc submissions",
        "submitters",
        "ltd dba",
        "com laude",
        "edgecast",
        "gandi sas",
        "csc corporate",
        "summary iocs",
        "facebook",
        "fbnoscript1",
        "as14061",
        "united",
        "whitelisted",
        "as16276",
        "a domains",
        "united kingdom",
        "script urls",
        "name servers",
        "as9009 m247",
        "backdoor",
        "ransom",
        "meta",
        "msil",
        "date",
        "malvertizing",
        "elevated exposure",
        "contextualizing",
        "cve -2023-22518",
        "cve-2017-17215",
        "contains-pe",
        "upx",
        "contains-macho attachment",
        "contains-embedded-js",
        "nsis",
        "pecompact",
        "wear os",
        "android phone",
        "gmail app",
        "smart reply",
        "meet  respond",
        "meet",
        "respond",
        "google",
        "google chat",
        "gmail",
        "et",
        "playstore",
        "dns",
        "browser events",
        "critical",
        "tsara brashears",
        "unhacker"
      ],
      "references": [
        "http://911porn.org/home.php?mod=space&uid=47570&do=profile&from=space",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "youjazz.911porn.org",
        "gimmebar.com",
        "datafoundry.com",
        "dataconnector.corp.google.com",
        "js.stripe.com [url redirects to]",
        "CVE-2023-22518",
        "https://bi.phncdn.com/www-static/js/lib/generated-lib.js?cache=2017051919",
        "206.189.61.126 [command and control]",
        "https://quantilnetworks.com/ [phishing]",
        "brazzersnetwork.com",
        "brazzers.com",
        "http://missing.hi2.ro/missing.html [malware hosting]",
        "nsscacheserver2.corp.google.com",
        "xred.mooo.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Netherlands",
        "Romania",
        "Russian Federation",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "ALF:Trojan:BAT/EnvVarCharReplacement.Custom",
          "display_name": "ALF:Trojan:BAT/EnvVarCharReplacement.Custom",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win64/PsBanker.MFP!MTB",
          "display_name": "ALF:Trojan:Win64/PsBanker.MFP!MTB",
          "target": null
        },
        {
          "id": "Backdoor:MSIL/AsyncRAT.ZB!MTB",
          "display_name": "Backdoor:MSIL/AsyncRAT.ZB!MTB",
          "target": "/malware/Backdoor:MSIL/AsyncRAT.ZB!MTB"
        },
        {
          "id": "Ransom:Win32/Somhoveran.C",
          "display_name": "Ransom:Win32/Somhoveran.C",
          "target": "/malware/Ransom:Win32/Somhoveran.C"
        },
        {
          "id": "Ransom:Win32/Genasom.AM",
          "display_name": "Ransom:Win32/Genasom.AM",
          "target": "/malware/Ransom:Win32/Genasom.AM"
        },
        {
          "id": "PWS:Win32/PrimaryPass.AD!MTB",
          "display_name": "PWS:Win32/PrimaryPass.AD!MTB",
          "target": "/malware/PWS:Win32/PrimaryPass.AD!MTB"
        },
        {
          "id": "MSIL:GenMalicious-ZC\\ [Trj]",
          "display_name": "MSIL:GenMalicious-ZC\\ [Trj]",
          "target": null
        },
        {
          "id": "Backdoor:Win32/VB.KQ",
          "display_name": "Backdoor:Win32/VB.KQ",
          "target": "/malware/Backdoor:Win32/VB.KQ"
        },
        {
          "id": "Backdoor:Win32/Tofsee.T",
          "display_name": "Backdoor:Win32/Tofsee.T",
          "target": "/malware/Backdoor:Win32/Tofsee.T"
        },
        {
          "id": "Backdoor:MSIL/Bladabindi.AJ",
          "display_name": "Backdoor:MSIL/Bladabindi.AJ",
          "target": "/malware/Backdoor:MSIL/Bladabindi.AJ"
        },
        {
          "id": "trojan.mydoom/memscan",
          "display_name": "trojan.mydoom/memscan",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "NSIS",
          "display_name": "NSIS",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65a94472aa9ff38469be19b0",
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 566,
        "FileHash-SHA1": 324,
        "FileHash-SHA256": 1828,
        "URL": 3171,
        "domain": 1145,
        "hostname": 1556,
        "CVE": 2,
        "email": 4
      },
      "indicator_count": 8596,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "834 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "mtcserver.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "mtcserver.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780215311.7194576
}