{
  "type": "Domain",
  "indicator": "nowplaytoc.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/nowplaytoc.com",
    "alexa": "http://www.alexa.com/siteinfo/nowplaytoc.com",
    "indicator": "nowplaytoc.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4239277045,
      "indicator": "nowplaytoc.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 11,
      "pulses": [
        {
          "id": "69f2a9b03bbc9452cba7ab87",
          "name": "URLert Daily Threat Intel \u2014 2026-04-30",
          "description": "URLert Daily Threat Intel \u2014 2026-04-30\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 40 | Indicators: 81\nConfirmed: 8 | Likely: 31 | Domain intel: 1\nTop threats: Phishing (30), Malware Hosting (4), Dropper (4), Unknown (2)\nDomains: 2mz3me.homes, 3wvftweba.baby, apartment-16896824.com, appbitly.com, beb6.com, beyondclosetstore.com, briansclub.vc, cheetahmall.com, courtlylover.com, due-fineac.com, emailroute.net, filec...\n\n40 unique threats producing 81 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-05-29T21:00:00.267000",
          "created": "2026-04-30T01:00:32.718000",
          "tags": [
            "+18-content",
            "abused-platform",
            "account-takeover",
            "aggressive-prompts",
            "anti-analysis",
            "app-distribution",
            "automated-scan",
            "bitly-impersonation",
            "brand-impersonation",
            "cacau-show",
            "child-exploitation",
            "clickbait",
            "content-spreading",
            "copenhagen-municipality",
            "correos",
            "cracked-software-distribution",
            "credential-harvesting",
            "cryptocurrency",
            "cryptocurrency-fraud",
            "cryptominer",
            "cvv-marketplace",
            "cybercriminal-infrastructure",
            "daily-threat-intel",
            "darknet-market",
            "data-breach",
            "data-collection",
            "dating-scam",
            "deceptive-domain",
            "deceptive-download",
            "deceptive-login",
            "deceptive-practices",
            "deceptive-redirect",
            "deceptive-tactics",
            "domain-classification",
            "domain-impersonation",
            "dpd-impersonation",
            "drugs",
            "evasion-tactic",
            "exit-scam",
            "fake-interface",
            "fake-security-challenge",
            "fake-shop",
            "fake-store",
            "fake-testimonials",
            "file-download",
            "financial-data-theft",
            "financial-information-harvesting",
            "financial-loss",
            "financial-scam",
            "fraud",
            "fraudulent-activity",
            "game-piracy",
            "geometry-dash",
            "government-impersonation",
            "hacking-services",
            "hostinger",
            "identity-theft",
            "ikea",
            "illegal-content",
            "imdb-impersonation",
            "line-impersonation",
            "malicious-extensions",
            "malware-distribution",
            "malware-hosting",
            "malware-reports",
            "media-entertainment",
            "media-impersonation",
            "mobile-app-distribution",
            "modded-apk",
            "nestle-dolce-gusto-impersonation",
            "new-domain",
            "newly-registered-domain",
            "obfuscated-url",
            "orico-impersonation",
            "payload-delivery",
            "payment-scam",
            "pennsylvania",
            "personal-information-collection",
            "personal-information-harvesting",
            "phishing",
            "phishing-site",
            "pirated-software",
            "ponzi-scheme",
            "predatory-lending",
            "pyramid-scheme",
            "random-domain",
            "recent-domain",
            "recruitment-scam",
            "redirect-chain",
            "registration-bonus-scam",
            "scam",
            "social-media-spam",
            "spotahome-impersonation",
            "steam",
            "stolen-financial-data",
            "subdomain-abuse",
            "survey-scam",
            "suspicious-domain",
            "suspicious-pricing",
            "suspicious-subdomain",
            "task-scam",
            "trojan",
            "typosquatting",
            "unauthorized-apk-distribution",
            "untrusted-source",
            "url-shortener",
            "urlert",
            "vortex-market",
            "wallet-drainer",
            "wifi-password-scam",
            "xvideos-impersonation",
            "youtube-lure"
          ],
          "references": [
            "https://urlert.com/domain/2mz3me.homes",
            "https://urlert.com/domain/3wvftweba.baby",
            "https://urlert.com/domain/apartment-16896824.com",
            "https://urlert.com/domain/appbitly.com",
            "https://urlert.com/domain/beb6.com",
            "https://urlert.com/domain/beyondclosetstore.com",
            "https://urlert.com/domain/briansclub.vc",
            "https://urlert.com/domain/cheetahmall.com",
            "https://urlert.com/domain/courtlylover.com",
            "https://urlert.com/domain/due-fineac.com",
            "https://urlert.com/domain/emailroute.net",
            "https://urlert.com/domain/filecr.com",
            "https://urlert.com/domain/flashbot.trade",
            "https://urlert.com/domain/geometrydashvn.org",
            "https://urlert.com/domain/globalbusinespays.com",
            "https://urlert.com/domain/hdid749fp1.com",
            "https://urlert.com/domain/iaoaa.cn",
            "https://urlert.com/domain/is.gd",
            "https://urlert.com/domain/iyvct.xyz",
            "https://urlert.com/domain/moriloti.cfd"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Financial Services",
            "Government",
            "Logistics / Supply Chain",
            "Media / Entertainment",
            "Real Estate",
            "Retail / E-Commerce",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 24,
            "URL": 23,
            "hostname": 11
          },
          "indicator_count": 58,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 30,
          "modified_text": "1 day ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a18e51482e9efa582093669",
          "name": "URLert Daily Threat Intel \u2014 2026-05-29",
          "description": "URLert Daily Threat Intel \u2014 2026-05-29\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 20 | Indicators: 37\nConfirmed: 4 | Likely: 16\nTop threats: Phishing (12), Malware Hosting (5), Dropper (2), Unknown (1)\nDomains: compy.ca, dsvbc.icu, ffddhh.com, fitgirl-repacks.site, getintopc.com, kxcoi.com, ln.run, modbibo.com, nowplaytoc.com, nsknb.com, officence.com, playmogo.com, qingtaishanghao.ink, run.app, ...\n\n20 unique threats producing 37 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-05-29T01:00:04.622000",
          "created": "2026-05-29T01:00:04.622000",
          "tags": [
            "adult-content",
            "automated-scan",
            "brand-impersonation",
            "bypass-security",
            "cracked-software",
            "credential-harvesting",
            "cryptocurrency-scam",
            "daily-threat-intel",
            "data-harvesting",
            "data-theft",
            "deceptive-download",
            "deceptive-landing-page",
            "deceptive-registration",
            "delivery-service-impersonation",
            "download-funnel",
            "drm-bypass",
            "evasion-technique",
            "explicit-content-bait",
            "explicit-lure",
            "financial-services",
            "government-impersonation",
            "illegal-content",
            "malware-distribution",
            "malware-hosting",
            "microsoft",
            "mobile-games",
            "mod-apk",
            "new-domain",
            "newly-registered-domain",
            "offensive-content",
            "personal-information-theft",
            "phishing",
            "phishing-site",
            "pirated-software",
            "redirect-chain",
            "redirect-service",
            "repacked-software",
            "restricted-substances",
            "riskware",
            "scam",
            "scam-platform",
            "security-risk",
            "sensitive-information-theft",
            "seur-impersonation",
            "social-engineering",
            "software-piracy",
            "suspicious-domain",
            "unauthorized-software",
            "untrusted-domain",
            "url-masking",
            "urlert",
            "zendesk"
          ],
          "references": [
            "https://urlert.com/domain/compy.ca",
            "https://urlert.com/domain/dsvbc.icu",
            "https://urlert.com/domain/ffddhh.com",
            "https://urlert.com/domain/fitgirl-repacks.site",
            "https://urlert.com/domain/getintopc.com",
            "https://urlert.com/domain/kxcoi.com",
            "https://urlert.com/domain/ln.run",
            "https://urlert.com/domain/modbibo.com",
            "https://urlert.com/domain/nowplaytoc.com",
            "https://urlert.com/domain/nsknb.com",
            "https://urlert.com/domain/officence.com",
            "https://urlert.com/domain/playmogo.com",
            "https://urlert.com/domain/qingtaishanghao.ink",
            "https://urlert.com/domain/run.app",
            "https://urlert.com/domain/scloud.ws",
            "https://urlert.com/domain/servicos.ru",
            "https://urlert.com/domain/sogorn.com.br",
            "https://urlert.com/domain/us.cc",
            "https://urlert.com/domain/whorez.net"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Financial Services",
            "Government",
            "Logistics / Supply Chain",
            "Retail / E-Commerce",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 16,
            "domain": 10,
            "hostname": 8
          },
          "indicator_count": 34,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 30,
          "modified_text": "2 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69eeb5306d5f58c6044105cc",
          "name": "URLert Daily Threat Intel \u2014 2026-04-27",
          "description": "URLert Daily Threat Intel \u2014 2026-04-27\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 40 | Indicators: 78\nConfirmed: 9 | Likely: 31\nTop threats: Phishing (33), Malware Hosting (3), Dropper (3), Malvertising (1)\nDomains: 355287.com, bunnyband.com, clc.cx, confirm-details.report, cwgobal.net, dipherex.com, dratrans.com, easycash777.com, forms.gle, giveawaybot.cc, hkjhsuies.com.es, hornygiirl.com, localsexap...\n\n40 unique threats producing 78 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-05-26T20:17:24.825000",
          "created": "2026-04-27T01:00:32.645000",
          "tags": [
            "account-takeover",
            "anti-analysis",
            "app-install-malware",
            "auto-generated-domain",
            "automated-scan",
            "betting",
            "bonus-scam",
            "brand-impersonation",
            "budbee-impersonation",
            "click-through-scam",
            "coreweave-impersonation",
            "counterfeit-software",
            "credential-harvesting",
            "daily-threat-intel",
            "dating-scam",
            "deceptive-bait",
            "deceptive-captcha",
            "deceptive-landing-page",
            "deceptive-marketing",
            "deceptive-redirect",
            "deceptive-scam",
            "deceptive-software",
            "dickies",
            "discord-impersonation",
            "disposable-domain",
            "ecommerce",
            "ecuador",
            "explicit-popups",
            "fake-financial-service",
            "fake-giveaway",
            "fake-login",
            "fake-online-store",
            "fake-products",
            "fake-social-proof",
            "fake-testimonials",
            "financial-fraud",
            "financial-scam",
            "financial-service-impersonation",
            "footwear-retail",
            "fraudulent-content",
            "fraudulent-services",
            "free-games-lure",
            "gambling",
            "gambling-scam",
            "gambling-site",
            "gaming-impersonation",
            "google-forms",
            "high-risk-domain",
            "high-risk-tld",
            "identity-service-impersonation",
            "investment-scam",
            "loan-scam",
            "malicious-android-app",
            "malicious-redirect",
            "malvertising",
            "malware-delivery",
            "malware-distribution",
            "malware-risk",
            "new-domain",
            "newly-registered-domain",
            "online-scam",
            "pc-games",
            "personal-information-harvesting",
            "phishing",
            "phishing-infrastructure",
            "phishing-kit",
            "phishing-site",
            "platoboost",
            "redirect-chain",
            "redirection",
            "revanced-project",
            "roblox-impersonation",
            "roblox-users",
            "robux-scam",
            "scam",
            "scams",
            "shopee",
            "social-engineering",
            "social-proof-manipulation",
            "software-piracy",
            "steam",
            "suggestive-imagery",
            "sumup",
            "task-based-scam",
            "task-scam",
            "traffic-redirection",
            "twitter-impersonation",
            "typosquatting",
            "unauthorized-software",
            "unauthorized-streaming",
            "unwanted-programs",
            "unwanted-software",
            "url-obfuscation",
            "url-redirection",
            "urlert",
            "verify-your-connection-scam",
            "victus",
            "warez-site",
            "wixsite-abuse",
            "young-domain",
            "youtube-impersonation"
          ],
          "references": [
            "https://urlert.com/domain/355287.com",
            "https://urlert.com/domain/bunnyband.com",
            "https://urlert.com/domain/clc.cx",
            "https://urlert.com/domain/confirm-details.report",
            "https://urlert.com/domain/cwgobal.net",
            "https://urlert.com/domain/dipherex.com",
            "https://urlert.com/domain/dratrans.com",
            "https://urlert.com/domain/easycash777.com",
            "https://urlert.com/domain/forms.gle",
            "https://urlert.com/domain/giveawaybot.cc",
            "https://urlert.com/domain/hkjhsuies.com.es",
            "https://urlert.com/domain/hornygiirl.com",
            "https://urlert.com/domain/localsexapp.com",
            "https://urlert.com/domain/meusitehostgator.com.br",
            "https://urlert.com/domain/netlify.app",
            "https://urlert.com/domain/netmirror.cc",
            "https://urlert.com/domain/nowplaytoc.com",
            "https://urlert.com/domain/ovagames.com",
            "https://urlert.com/domain/platorelay.com",
            "https://urlert.com/domain/premiumcartoons.cc"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Financial Services",
            "Government",
            "Logistics / Supply Chain",
            "Media / Entertainment",
            "Retail / E-Commerce",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 23,
            "URL": 26,
            "hostname": 8
          },
          "indicator_count": 57,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 31,
          "modified_text": "4 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ec121455951901fef8a045",
          "name": "URLert Daily Threat Intel \u2014 2026-04-25",
          "description": "URLert Daily Threat Intel \u2014 2026-04-25\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 63 | Indicators: 122\nConfirmed: 19 | Likely: 44\nTop threats: Phishing (51), Malware Hosting (4), Unknown (3), Dropper (3), Malvertising (2)\nDomains: 6489.pro, app.link, beacons.ai, bit.ly, bookscloud.net, brohood.my.id, bunnyband.com, ca-paget.sbs, cointerac.org, contaboserver.net, cs2by.com, ct.ws, dexo.click, dkfnvk.cfd, dpdlocafd.sh...\n\n63 unique threats producing 122 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-05-25T00:14:07.625000",
          "created": "2026-04-25T01:00:04.128000",
          "tags": [
            "abused-hosting",
            "account-takeover",
            "adult-content-lure",
            "aggressive-ads",
            "ai-trading-bot",
            "anubis-challenge-service",
            "artificial-urgency",
            "automated-scan",
            "automatic-download",
            "azure-blob-storage",
            "booter",
            "brand-impersonation",
            "broken-site",
            "browser-locker",
            "burberry",
            "car-wrap-scam",
            "cloaking",
            "code-repository-impersonation",
            "command-execution",
            "complex-redirect-chain",
            "compromised-site",
            "contabo",
            "content-locker",
            "content-locker-scam",
            "costco-impersonation",
            "credential-harvesting",
            "crypto-scam",
            "cryptocurrency",
            "cyberattack-facilitation",
            "daily-threat-intel",
            "data-harvesting",
            "ddos-service",
            "deceptive-domain-email",
            "deceptive-marketing",
            "deceptive-practices",
            "deceptive-redirect",
            "deceptive-tactics",
            "deceptive-url",
            "delivery-scam",
            "dpd-impersonation",
            "e-commerce-fraud",
            "e-commerce-scam",
            "email-verification",
            "energy-crisis",
            "evasion-technique",
            "executable-malware",
            "extortion",
            "fake-discounts",
            "fake-download",
            "fake-prize",
            "fake-promotion",
            "fake-urgency",
            "fake-verification",
            "fake-virus-alert",
            "fanatics-impersonation",
            "file-sharing",
            "financial-data-harvesting",
            "financial-fraud",
            "financial-information-harvesting",
            "financial-scam",
            "fraudulent-infrastructure",
            "fraudulent-platform",
            "fraudulent-retail",
            "fraudulent-scheme",
            "fraudulent-sweepstakes",
            "fuel-voucher",
            "gambling-platform",
            "game-related-lure",
            "gaming",
            "gift-card-scam",
            "giveaway-scam",
            "google-cloud-storage-abuse",
            "google-impersonation",
            "government-impersonation",
            "government-targeting",
            "identity-theft",
            "impersonation",
            "infrastructure-misuse",
            "interac",
            "investment-scam",
            "lidl-impersonation",
            "linkvertise",
            "logistics-impersonation",
            "logistics-supply-chain",
            "low-reputation",
            "low-reputation-domain",
            "malicious-download",
            "malicious-file-delivery",
            "malicious-infrastructure",
            "malicious-redirection",
            "malicious-scripts",
            "malvertising",
            "malware-delivery",
            "malware-distribution",
            "mothers-day-scam",
            "multi-provider-phishing",
            "neosurf",
            "new-domain",
            "newly-registered-domain",
            "ontario-government",
            "payload-delivery",
            "payment-voucher-scam",
            "persistent-malware",
            "personal-information-collection",
            "personal-information-harvesting",
            "petrom",
            "phishing",
            "pii-collection",
            "plumeimpactor",
            "potentially-unwanted-software",
            "redirect",
            "roblox",
            "roblox-impersonation",
            "scam",
            "scam-ecommerce",
            "scam-site",
            "servientrega-impersonation",
            "shadow-reporting",
            "shein",
            "social-engineering",
            "software-piracy",
            "software-repository-impersonation",
            "spain",
            "spam-promotion",
            "spotify-impersonation",
            "steam",
            "stress-testing",
            "stresser",
            "survey-scam",
            "suspicious-domain",
            "suspicious-redirect",
            "suspicious-tld",
            "suspicious-url",
            "task-based-scam",
            "task-scam",
            "tech-support-scam",
            "technical-errors",
            "telegram-bot",
            "tracking-parameters",
            "trading-platform",
            "traffic-redirection",
            "transcash",
            "typosquatting",
            "uber-impersonation",
            "unknown-binary",
            "unsecured-site",
            "unverified-health-claims",
            "unwanted-software",
            "url-shortener",
            "urlert",
            "usps",
            "xyz-domain"
          ],
          "references": [
            "https://urlert.com/domain/6489.pro",
            "https://urlert.com/domain/app.link",
            "https://urlert.com/domain/beacons.ai",
            "https://urlert.com/domain/bit.ly",
            "https://urlert.com/domain/bookscloud.net",
            "https://urlert.com/domain/brohood.my.id",
            "https://urlert.com/domain/bunnyband.com",
            "https://urlert.com/domain/ca-paget.sbs",
            "https://urlert.com/domain/cointerac.org",
            "https://urlert.com/domain/contaboserver.net",
            "https://urlert.com/domain/cs2by.com",
            "https://urlert.com/domain/ct.ws",
            "https://urlert.com/domain/dexo.click",
            "https://urlert.com/domain/dkfnvk.cfd",
            "https://urlert.com/domain/dpdlocafd.shop",
            "https://urlert.com/domain/e-entrega.co",
            "https://urlert.com/domain/ethias.be",
            "https://urlert.com/domain/fafda.to",
            "https://urlert.com/domain/futfanaticss.com",
            "https://urlert.com/domain/gamedrive.org"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Energy",
            "Financial Services",
            "Government",
            "Hospitality",
            "Logistics / Supply Chain",
            "Media / Entertainment",
            "Retail / E-Commerce"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 33,
            "URL": 36,
            "hostname": 13
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 30,
          "modified_text": "6 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69e42a619c0c8949c578f81e",
          "name": "URLert Daily Threat Intel \u2014 2026-04-19",
          "description": "URLert Daily Threat Intel \u2014 2026-04-19\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 41 | Indicators: 71\nConfirmed: 14 | Likely: 25 | Domain intel: 2\nTop threats: Phishing (29), Malvertising (3), Dropper (3), Malware Hosting (2), Unknown (2)\nDomains: bitunixg.com, bunnyband.com, casajoys.com, cashboost.live, create-road.my, dahl.su, dahlmessenger.com, digital-solves.com, direct-link.net, earndailly9ja.com.ng, findzu.net, gesowin77.pro,...\n\n41 unique threats producing 71 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-05-18T22:17:43.844000",
          "created": "2026-04-19T01:05:37.600000",
          "tags": [
            "account-verification-scam",
            "adware",
            "android-malware",
            "anti-analysis",
            "app-impersonation",
            "automated-scan",
            "backend-infrastructure",
            "binary-options-scam",
            "brand-impersonation",
            "brazil",
            "browser-locking-scam",
            "cloaking",
            "communication-decryption",
            "communication-eavesdropping",
            "communication-interception",
            "content-gating",
            "costco",
            "counterfeit-apps",
            "counterfeit-cards",
            "counterfeit-money",
            "cpf",
            "credential-harvesting",
            "crypto-scam",
            "cryptocurrency",
            "cryptocurrency-scam",
            "daily-threat-intel",
            "data-exfiltration",
            "data-harvesting",
            "deceptive-content",
            "deceptive-domain",
            "deceptive-practices",
            "deceptive-promotion",
            "deposit-scam",
            "domain-classification",
            "evasive-techniques",
            "extortion",
            "fake-news",
            "fake-parking-ticket",
            "fake-platform",
            "fake-reward",
            "fake-statistics",
            "fake-survey",
            "fake-testimonials",
            "financial-fraud",
            "financial-scam",
            "fiverr",
            "fiverr-impersonation",
            "fraudulent",
            "fraudulent-sales",
            "gambling-scam",
            "get-rich-quick-scheme",
            "giveaway-scam",
            "globe-x",
            "google-docs-hosting",
            "government-impersonation",
            "green-energy-investment",
            "high-risk-tld",
            "high-yield-investment-program",
            "impersonation",
            "imvu",
            "investment-fraud",
            "investment-scam",
            "jurassic-world",
            "legitimate-platform-abuse",
            "linkvertise",
            "login-portal",
            "logistics",
            "malicious-downloads",
            "malicious-infrastructure",
            "malicious-redirect",
            "malicious-redirector",
            "malicious-site",
            "malware-delivery",
            "malware-distribution",
            "man-in-the-middle",
            "manitoba-government",
            "mitm-attacks",
            "new-domain",
            "newly-registered-domain",
            "payment-harvesting",
            "phishing",
            "pig-butchering",
            "pii-collection",
            "potentially-unwanted-software",
            "privacy-risk",
            "privacy-violation",
            "redirect-chain",
            "redirector",
            "rekonise-platform",
            "revanced-impersonation",
            "roblox",
            "roblox-impersonation",
            "scam",
            "scam-site",
            "shufersal-impersonation",
            "social-engineering",
            "social-media-engagement",
            "suspicious-network",
            "suspicious-redirects",
            "task-based-scam",
            "task-scam",
            "telega.me",
            "telegram-traffic",
            "telegram-traffic-interception",
            "third-party-telegram-client",
            "traffic-distribution-system",
            "traffic-interception",
            "twitter-impersonation",
            "typo-squatting",
            "typosquatting",
            "unauthorized-tracking",
            "unrealistic-returns",
            "unwanted-content",
            "unwanted-software",
            "urlert",
            "weakened-encryption",
            "webcam-capture",
            "withdrawal-scam"
          ],
          "references": [
            "https://urlert.com/domain/bitunixg.com",
            "https://urlert.com/domain/bunnyband.com",
            "https://urlert.com/domain/casajoys.com",
            "https://urlert.com/domain/cashboost.live",
            "https://urlert.com/domain/create-road.my",
            "https://urlert.com/domain/dahl.su",
            "https://urlert.com/domain/dahlmessenger.com",
            "https://urlert.com/domain/digital-solves.com",
            "https://urlert.com/domain/direct-link.net",
            "https://urlert.com/domain/earndailly9ja.com.ng",
            "https://urlert.com/domain/findzu.net",
            "https://urlert.com/domain/gesowin77.pro",
            "https://urlert.com/domain/github.io",
            "https://urlert.com/domain/google.com",
            "https://urlert.com/domain/httpps-roblox.co",
            "https://urlert.com/domain/iqkf.com",
            "https://urlert.com/domain/irevenue.co",
            "https://urlert.com/domain/logistica-central.online",
            "https://urlert.com/domain/manitoba-fine-payment.cfd",
            "https://urlert.com/domain/mycostperks.site"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Financial Services",
            "Government",
            "Logistics / Supply Chain",
            "Media / Entertainment",
            "Retail / E-Commerce"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 24,
            "URL": 25,
            "hostname": 4
          },
          "indicator_count": 53,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 30,
          "modified_text": "12 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ed6874491be5ba0e959599",
          "name": "URLert Daily Threat Intel \u2014 2026-04-19",
          "description": "URLert Daily Threat Intel \u2014 2026-04-19\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 41 | Indicators: 71\nConfirmed: 14 | Likely: 25 | Domain intel: 2\nTop threats: Phishing (29), Malvertising (3), Dropper (3), Malware Hosting (2), Unknown (2)\nDomains: bitunixg.com, bunnyband.com, casajoys.com, cashboost.live, create-road.my, dahl.su, dahlmessenger.com, digital-solves.com, direct-link.net, earndailly9ja.com.ng, findzu.net, gesowin77.pro,...\n\n41 unique threats producing 71 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-05-18T22:17:43.844000",
          "created": "2026-04-26T01:20:52.086000",
          "tags": [
            "account-verification-scam",
            "adware",
            "android-malware",
            "anti-analysis",
            "app-impersonation",
            "automated-scan",
            "backend-infrastructure",
            "binary-options-scam",
            "brand-impersonation",
            "brazil",
            "browser-locking-scam",
            "cloaking",
            "communication-decryption",
            "communication-eavesdropping",
            "communication-interception",
            "content-gating",
            "costco",
            "counterfeit-apps",
            "counterfeit-cards",
            "counterfeit-money",
            "cpf",
            "credential-harvesting",
            "crypto-scam",
            "cryptocurrency",
            "cryptocurrency-scam",
            "daily-threat-intel",
            "data-exfiltration",
            "data-harvesting",
            "deceptive-content",
            "deceptive-domain",
            "deceptive-practices",
            "deceptive-promotion",
            "deposit-scam",
            "domain-classification",
            "evasive-techniques",
            "extortion",
            "fake-news",
            "fake-parking-ticket",
            "fake-platform",
            "fake-reward",
            "fake-statistics",
            "fake-survey",
            "fake-testimonials",
            "financial-fraud",
            "financial-scam",
            "fiverr",
            "fiverr-impersonation",
            "fraudulent",
            "fraudulent-sales",
            "gambling-scam",
            "get-rich-quick-scheme",
            "giveaway-scam",
            "globe-x",
            "google-docs-hosting",
            "government-impersonation",
            "green-energy-investment",
            "high-risk-tld",
            "high-yield-investment-program",
            "impersonation",
            "imvu",
            "investment-fraud",
            "investment-scam",
            "jurassic-world",
            "legitimate-platform-abuse",
            "linkvertise",
            "login-portal",
            "logistics",
            "malicious-downloads",
            "malicious-infrastructure",
            "malicious-redirect",
            "malicious-redirector",
            "malicious-site",
            "malware-delivery",
            "malware-distribution",
            "man-in-the-middle",
            "manitoba-government",
            "mitm-attacks",
            "new-domain",
            "newly-registered-domain",
            "payment-harvesting",
            "phishing",
            "pig-butchering",
            "pii-collection",
            "potentially-unwanted-software",
            "privacy-risk",
            "privacy-violation",
            "redirect-chain",
            "redirector",
            "rekonise-platform",
            "revanced-impersonation",
            "roblox",
            "roblox-impersonation",
            "scam",
            "scam-site",
            "shufersal-impersonation",
            "social-engineering",
            "social-media-engagement",
            "suspicious-network",
            "suspicious-redirects",
            "task-based-scam",
            "task-scam",
            "telega.me",
            "telegram-traffic",
            "telegram-traffic-interception",
            "third-party-telegram-client",
            "traffic-distribution-system",
            "traffic-interception",
            "twitter-impersonation",
            "typo-squatting",
            "typosquatting",
            "unauthorized-tracking",
            "unrealistic-returns",
            "unwanted-content",
            "unwanted-software",
            "urlert",
            "weakened-encryption",
            "webcam-capture",
            "withdrawal-scam"
          ],
          "references": [
            "https://urlert.com/domain/bitunixg.com",
            "https://urlert.com/domain/bunnyband.com",
            "https://urlert.com/domain/casajoys.com",
            "https://urlert.com/domain/cashboost.live",
            "https://urlert.com/domain/create-road.my",
            "https://urlert.com/domain/dahl.su",
            "https://urlert.com/domain/dahlmessenger.com",
            "https://urlert.com/domain/digital-solves.com",
            "https://urlert.com/domain/direct-link.net",
            "https://urlert.com/domain/earndailly9ja.com.ng",
            "https://urlert.com/domain/findzu.net",
            "https://urlert.com/domain/gesowin77.pro",
            "https://urlert.com/domain/github.io",
            "https://urlert.com/domain/google.com",
            "https://urlert.com/domain/httpps-roblox.co",
            "https://urlert.com/domain/iqkf.com",
            "https://urlert.com/domain/irevenue.co",
            "https://urlert.com/domain/logistica-central.online",
            "https://urlert.com/domain/manitoba-fine-payment.cfd",
            "https://urlert.com/domain/mycostperks.site"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Financial Services",
            "Government",
            "Logistics / Supply Chain",
            "Media / Entertainment",
            "Retail / E-Commerce"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 24,
            "URL": 25,
            "hostname": 4
          },
          "indicator_count": 53,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 31,
          "modified_text": "12 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69dd91ae78f490fd44e82d33",
          "name": "URLert Daily Threat Intel \u2014 2026-04-14",
          "description": "URLert Daily Threat Intel \u2014 2026-04-14\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 67 | Indicators: 113\nConfirmed: 27 | Likely: 38 | Domain intel: 2\nTop threats: Phishing (49), Malware Hosting (12), Malvertising (3), Dropper (2), Exploit Kit (1)\nDomains: 738833.com, 888-gpifc.vip, 964235.help, 9mod.cloud, ankergames.net, appinjects.com, asusnext.us, binance-ltd.vip, bnz-gov.cam, bucara.my.id, bunnyband.com, challengermode.network, clck.ru,...\n\n67 unique threats producing 113 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-05-14T01:05:16.798000",
          "created": "2026-04-14T01:00:29.601000",
          "tags": [
            ".monster-tld",
            "abused-platform",
            "account-takeover",
            "account-theft",
            "ad-fraud",
            "adult-content-scam",
            "adult-dating-scam",
            "advance-fee-fraud",
            "ai-services",
            "android-malware",
            "anti-analysis",
            "apk-distribution",
            "apk-malware",
            "asset-theft",
            "automated-scan",
            "binance-impersonation",
            "brand-impersonation",
            "brazil",
            "broken-page",
            "carding",
            "city-of-vancouver",
            "click-jacking",
            "cloud-run",
            "combosquatting",
            "community-report",
            "content-locker",
            "counterfeit-domain",
            "credential-harvesting",
            "cryptocurrency",
            "cryptocurrency-scam",
            "daily-threat-intel",
            "data-collection",
            "data-harvesting",
            "deceptive-content",
            "deceptive-domain",
            "deceptive-interface",
            "deceptive-lure",
            "deceptive-page",
            "deceptive-platform",
            "deceptive-practices",
            "deceptive-redirects",
            "deceptive-site",
            "deceptive-url",
            "deceptive-verification",
            "developer-tools-blocking",
            "domain-classification",
            "e-commerce-fraud",
            "earning-scheme",
            "esports-targeting",
            "etsy-impersonation",
            "evasion",
            "evasion-tactics",
            "fake-android-app",
            "fake-app",
            "fake-domain",
            "fake-giveaway",
            "fake-online-store",
            "fake-platform",
            "fake-rewards",
            "fake-verification",
            "file-sharing",
            "file-sharing-impersonation",
            "financial-fraud",
            "financial-harvesting",
            "financial-scam",
            "fiverr",
            "fiverr-impersonation",
            "flhsmv-impersonation",
            "fraudulent-activity",
            "fraudulent-platform",
            "fraudulent-scheme",
            "free-fire",
            "gambling",
            "gambling-promotion",
            "game-cheats",
            "get-paid-to-scheme",
            "google-impersonation",
            "government-impersonation",
            "high-risk-domain",
            "high-risk-tld",
            "information-gathering",
            "information-harvesting",
            "intrusive-ads",
            "investment-management",
            "investment-scam",
            "jadlog-impersonation",
            "low-reputation",
            "malicious-landing-page",
            "malicious-redirect",
            "malicious-redirection",
            "malvertising",
            "malware",
            "malware-distribution",
            "malware-download",
            "malware-hosting",
            "malware-potential",
            "mexc-impersonation",
            "misleading-domain",
            "mobile-spyware",
            "modified-apps",
            "nebula-x",
            "netlify-abuse",
            "new-domain",
            "newly-registered-domain",
            "obfuscation",
            "payment-information-harvesting",
            "payment-scam",
            "personal-data-collection",
            "personal-information-collection",
            "personal-information-harvesting",
            "pet-scam",
            "phishing",
            "phishing-page",
            "phishing-scam",
            "phishing-site",
            "phishing-technique",
            "pirated-software",
            "ponzi-scheme",
            "puppy-scam",
            "recruitment-scam",
            "redirect",
            "redirect-chain",
            "revanced-impersonation",
            "roblox",
            "roblox-impersonation",
            "scam",
            "scam-campaign",
            "scam-lure",
            "scam-site",
            "serviceontario",
            "session-token",
            "shopping-cart-scam",
            "signup-page",
            "signup-scam",
            "social-engineering",
            "spam-promotion",
            "spoofed-domain",
            "spotify",
            "steam",
            "survey-scam",
            "suspicious-retailer",
            "suspicious-service-model",
            "task-based-earning-scam",
            "task-based-scam",
            "task-scam",
            "third-party-download",
            "toll-scam",
            "typosquatting",
            "unofficial-sources",
            "unwanted-software",
            "url-redirection",
            "url-shortener",
            "urlert",
            "usdt-storage",
            "user-manipulation",
            "virtual-tasks",
            "wallet-harvesting",
            "x-twitter",
            "zip-download"
          ],
          "references": [
            "https://urlert.com/domain/738833.com",
            "https://urlert.com/domain/888-gpifc.vip",
            "https://urlert.com/domain/964235.help",
            "https://urlert.com/domain/9mod.cloud",
            "https://urlert.com/domain/ankergames.net",
            "https://urlert.com/domain/appinjects.com",
            "https://urlert.com/domain/asusnext.us",
            "https://urlert.com/domain/binance-ltd.vip",
            "https://urlert.com/domain/bnz-gov.cam",
            "https://urlert.com/domain/bucara.my.id",
            "https://urlert.com/domain/bunnyband.com",
            "https://urlert.com/domain/challengermode.network",
            "https://urlert.com/domain/clck.ru",
            "https://urlert.com/domain/cloudnext.pro",
            "https://urlert.com/domain/dattingrooms.com",
            "https://urlert.com/domain/discord-tracker.com",
            "https://urlert.com/domain/elricat.co.uk",
            "https://urlert.com/domain/f09poypkdea3.com",
            "https://urlert.com/domain/facebook.hk",
            "https://urlert.com/domain/gamenuv.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Financial Services",
            "Government",
            "Logistics / Supply Chain",
            "Media / Entertainment",
            "Retail / E-Commerce",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 35,
            "URL": 40,
            "hostname": 13
          },
          "indicator_count": 88,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 30,
          "modified_text": "17 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69c333aacf8fedcd36832138",
          "name": "URLert Daily Threat Intel \u2014 2026-03-25",
          "description": "URLert Daily Threat Intel \u2014 2026-03-25\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 79 | Indicators: 140\nConfirmed: 27 | Likely: 48 | Domain intel: 4\nTop threats: Phishing (66), Dropper (5), Unknown (4), Malware Hosting (3), C2 Infrastructure (1)\nDomains: 571084.xin, 9990.site, app.link, appwrite.network, arcworld.one, aviatorfine.com, beetrade.me, bit.ly, bonanza-gha.work, casajoys.com, compromisedblog.com, cryptor.plus, daily777ween666.co...\n\n79 unique threats producing 140 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-04-23T20:57:23.519000",
          "created": "2026-03-25T01:00:26.546000",
          "tags": [
            ".cc-tld",
            "abuse-platform",
            "adult-content",
            "adult-scam",
            "affiliate-marketing",
            "aggressive-popups",
            "anti-analysis",
            "ar24-impersonation",
            "automated-scan",
            "blackmail-tool",
            "bonanza-impersonation",
            "brand-impersonation",
            "burn-site",
            "california-dmv",
            "certificate-mismatch",
            "chile",
            "cnn-impersonation",
            "combosquatting",
            "command-and-control",
            "compromised-site",
            "copec",
            "copec-impersonation",
            "credential-harvesting",
            "credit-card-theft",
            "crypto-investment-scam",
            "crypto-scam",
            "cryptocurrency",
            "cryptocurrency-fraud",
            "cryptocurrency-scam",
            "daily-threat-intel",
            "data-collection",
            "data-exfiltration",
            "data-harvesting",
            "data-theft",
            "deceptive-claims",
            "deceptive-content",
            "deceptive-landing-page",
            "deceptive-marketing",
            "deceptive-practices",
            "deceptive-reward-site",
            "deceptive-rewards",
            "deceptive-site",
            "deceptive-social-viewer",
            "deceptive-tactics",
            "digital-currency-theft",
            "dmv-impersonation",
            "document-sharing-impersonation",
            "domain-classification",
            "domain-rotation",
            "drive-by-download",
            "e-commerce-scam",
            "email-phishing",
            "evasion",
            "exit-scam",
            "facebook-messenger",
            "fake-login",
            "fake-login-portal",
            "fake-offer",
            "fake-phone-number",
            "fake-retail",
            "fake-toll-charge",
            "fake-verification",
            "financial-data-harvesting",
            "financial-fraud",
            "financial-scam",
            "financial-services-impersonation",
            "forced-download",
            "forepaas",
            "forepaas-impersonation",
            "fraudulent-deposits",
            "fraudulent-investment",
            "fraudulent-store",
            "fraudulent-website",
            "gambling-promotion",
            "gambling-scam",
            "gambling-site",
            "game-resource-generator",
            "gibberish-domain",
            "gmail-impersonation",
            "government-impersonation",
            "high-risk-gambling",
            "high-risk-tld",
            "high-traffic",
            "impersonation",
            "instagram-impersonation",
            "investment-scam",
            "kyc-fraud",
            "lead-generation",
            "litellm-malware",
            "login-page",
            "low-reputation-domain",
            "malicious-download",
            "malicious-redirect",
            "malicious-redirection",
            "malicious-redirects",
            "malicious-site",
            "malicious-url",
            "malware-distribution",
            "malware-download",
            "malware-dropper",
            "mfa-harvesting",
            "microsoft",
            "microsoft-defender-flagged",
            "myprotein",
            "nebula-x",
            "new-domain",
            "newly-registered-domain",
            "no-customer-support",
            "obscure-site",
            "online-casino-scam",
            "package-delivery-scam",
            "payment-information-theft",
            "payment-scam",
            "personal-information-theft",
            "phishing",
            "phishing-campaign",
            "phishing-gateway",
            "phishing-site",
            "phone-number-harvesting",
            "pii-collection",
            "pirated-games",
            "pop-mart-impersonation",
            "price-scam",
            "privacy-risk",
            "privacy-violation",
            "quickbooks",
            "redirect",
            "redirect-chain",
            "redirect-cloaking",
            "redirect-service",
            "redirection",
            "redirector",
            "redirects",
            "reverb-impersonation",
            "risky-url",
            "rug-pull",
            "sars-impersonation",
            "scam",
            "social-engineering",
            "social-media-abuse",
            "social-media-campaign",
            "social-media-scam",
            "social-media-scams",
            "south-africa",
            "spam-distribution",
            "spotify-impersonation",
            "streaming-service-scam",
            "subscription-scam",
            "supply-chain-attack",
            "support-scam",
            "surveillance",
            "suspicious-domain",
            "taplink-abuse",
            "task-scam",
            "tencent-hosting",
            "third-party-data-sharing",
            "throwaway-domain",
            "tracking",
            "tracking-url",
            "typosquatting",
            "unaccountable-infrastructure",
            "unauthorized-software",
            "undelivered-goods",
            "unlicensed-gambling",
            "unrealistic-pricing",
            "unreleased-products",
            "unsecured-file-sharing",
            "unwanted-software",
            "url-cloaking",
            "url-shortener",
            "urlert",
            "usdt",
            "usdt-scam",
            "user-manipulation",
            "vpn-impersonation",
            "webcam-capture",
            "webcam-tracking",
            "weebly-abuse",
            "xvideos-impersonation",
            "zero-day-registration"
          ],
          "references": [
            "https://urlert.com/domain/571084.xin",
            "https://urlert.com/domain/9990.site",
            "https://urlert.com/domain/app.link",
            "https://urlert.com/domain/appwrite.network",
            "https://urlert.com/domain/arcworld.one",
            "https://urlert.com/domain/aviatorfine.com",
            "https://urlert.com/domain/beetrade.me",
            "https://urlert.com/domain/bit.ly",
            "https://urlert.com/domain/bonanza-gha.work",
            "https://urlert.com/domain/casajoys.com",
            "https://urlert.com/domain/compromisedblog.com",
            "https://urlert.com/domain/cryptor.plus",
            "https://urlert.com/domain/daily777ween666.com",
            "https://urlert.com/domain/dpoiq.life",
            "https://urlert.com/domain/e.vg",
            "https://urlert.com/domain/effectivegatecpm.com",
            "https://urlert.com/domain/explodely.com",
            "https://urlert.com/domain/extravagant-streaming.life",
            "https://urlert.com/domain/fedexredeliveryform.com",
            "https://urlert.com/domain/fgl.cc"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Energy",
            "Financial Services",
            "Government",
            "Logistics / Supply Chain",
            "Media / Entertainment",
            "Retail / E-Commerce",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 37,
            "hostname": 15,
            "URL": 36
          },
          "indicator_count": 88,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 31,
          "modified_text": "37 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ae1bb0bd34b3f694765e2b",
          "name": "URLert Daily Threat Intel \u2014 2026-03-09",
          "description": "URLert Daily Threat Intel \u2014 2026-03-09\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 42 | Indicators: 73\nConfirmed: 13 | Likely: 26 | Domain intel: 2 | Manual: 1\nTop threats: Phishing (33), Unknown (3), Malvertising (2), Dropper (2), Exploit Kit (1)\nDomains: allegrolokalnie.pl, cloudstoragex.shop, codecarteinstant.com, donutstake.com, effectivegatecpm.com, feua.cn, firebaseapp.com, ftghnbjkolswedfrcvbnhgfdswazxcvbnmjkolmpqwasderftgbnvcza.net, ...\n\n42 unique threats producing 73 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-04-07T22:19:15.041000",
          "created": "2026-03-09T01:00:32.570000",
          "tags": [
            "adult-content-lure",
            "adult-dating-scam",
            "aggressive-advertising",
            "atacadao-impersonation",
            "automated-scan",
            "booking-com-impersonation",
            "brand-impersonation",
            "browser-manipulation",
            "bulletproof-hosting",
            "cacau-show",
            "cloaking",
            "combosquatting",
            "compromised-site",
            "concealed-threat",
            "content-piracy",
            "credential-harvesting",
            "credit-card-harvesting",
            "cryptocurrency-scam",
            "daily-threat-intel",
            "dating-scam",
            "debugger-evasion",
            "deceptive-access",
            "deceptive-buttons",
            "deceptive-content",
            "deceptive-landing-page",
            "deceptive-practices",
            "deceptive-redirects",
            "deceptive-site",
            "discount-lure",
            "domain-classification",
            "domain-squatting",
            "ebay-impersonation",
            "ecommerce-targeting",
            "evasive-maneuvers",
            "exploit-kit-landing-page",
            "fake-download",
            "fake-giveaway",
            "fake-payment-portal",
            "fake-prize-scam",
            "fake-product",
            "fake-shopping",
            "fake-verification",
            "financial-exploitation",
            "financial-fraud",
            "financial-scam",
            "financial-sector",
            "fraudulent-scheme",
            "fraudulent-store",
            "giveaway-scam",
            "google-impersonation",
            "greece",
            "high-risk-tld",
            "investment-scam",
            "liquidity-pool-scam",
            "malicious-app-distribution",
            "malicious-redirect",
            "malvertising",
            "malware-delivery",
            "manomano-impersonation",
            "manual-entry",
            "minecraft-community",
            "new-domain",
            "newly-registered-domain",
            "onlyfans-impersonation",
            "otp-harvesting",
            "phishing",
            "phishing-kit",
            "phishing-site",
            "pig-butchering-scam",
            "pii-harvesting",
            "predatory-content",
            "predatory-monetization",
            "prize-scam",
            "redirect-activity",
            "redirect-cloaking",
            "retail-e-commerce",
            "retail-scam",
            "roblox",
            "scam",
            "scam-site",
            "social-media-impersonation",
            "social-proof-scam",
            "subscription-scam",
            "survey-scam",
            "suspicious-traffic",
            "tambo-plus-impersonation",
            "telcel-impersonation",
            "traffic-redirection",
            "transaction-fraud",
            "typosquatting",
            "unofficial-domain",
            "unregulated-gambling",
            "unwanted-software",
            "url-shortener",
            "urlert",
            "usdt-scam",
            "wallet-scam"
          ],
          "references": [
            "https://urlert.com/domain/allegrolokalnie.pl",
            "https://urlert.com/domain/cloudstoragex.shop",
            "https://urlert.com/domain/codecarteinstant.com",
            "https://urlert.com/domain/donutstake.com",
            "https://urlert.com/domain/effectivegatecpm.com",
            "https://urlert.com/domain/feua.cn",
            "https://urlert.com/domain/firebaseapp.com",
            "https://urlert.com/domain/flirtcaster.com",
            "https://urlert.com/domain/ftghnbjkolswedfrcvbnhgfdswazxcvbnmjkolmpqwasderftgbnvcza.net",
            "https://urlert.com/domain/fyo.cc",
            "https://urlert.com/domain/harafbangroup.com.ng",
            "https://urlert.com/domain/homelyero.com",
            "https://urlert.com/domain/ieuj.cn",
            "https://urlert.com/domain/is.gd",
            "https://urlert.com/domain/j82k.site",
            "https://urlert.com/domain/kec.az",
            "https://urlert.com/domain/lawlovepqr.click",
            "https://urlert.com/domain/lfi9d.vip",
            "https://urlert.com/domain/me-ebay.com",
            "https://urlert.com/domain/minertech.co"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Financial Services",
            "Government",
            "Hospitality",
            "Media / Entertainment",
            "Retail / E-Commerce",
            "Technology",
            "Telecommunications"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 28,
            "URL": 26,
            "hostname": 4
          },
          "indicator_count": 58,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 30,
          "modified_text": "53 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69a8dd2e875873023f69baaf",
          "name": "URLert Daily Threat Intel \u2014 2026-03-05",
          "description": "URLert Daily Threat Intel \u2014 2026-03-05\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 71 | Indicators: 136\nConfirmed: 13 | Likely: 45 | Under review: 4 | Domain intel: 7 | Manual: 2\nTop threats: Phishing (52), Unknown (11), Malware Hosting (2), Dropper (2), Malvertising (2)\nDomains: 4download.net, 87870.cyou, africa.com, amourconnects.com, appspot.com, artbbs.al, benson-gmbh.top, blox.gifts, bluetickon-adslive.online, bridgestonemerchandise.com, budal05.xyz, crusaders...\n\n71 unique threats producing 136 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-04-03T19:50:47.596000",
          "created": "2026-03-05T01:32:25.962000",
          "tags": [
            "adult-content",
            "adult-content-lure",
            "adult-dating",
            "adult-forum",
            "adult-scam",
            "ai-generated-pornography",
            "ai-jailbreaking",
            "allstate",
            "apple-care",
            "auto-download",
            "automated-scan",
            "belgian-government",
            "blogspot",
            "brand-impersonation",
            "bridgestone-impersonation",
            "broken-links",
            "browser-extension-malware",
            "business-email-phishing",
            "cisco-impersonation",
            "combosquatting",
            "content-generation",
            "cracks-keygens",
            "credential-harvesting",
            "crypto-scam",
            "cryptocurrency",
            "cryptocurrency-scam",
            "csam",
            "daily-threat-intel",
            "dangerous-url",
            "data-collection",
            "data-harvesting-risk",
            "deceptive-buttons",
            "deceptive-consent",
            "deceptive-content",
            "deceptive-download",
            "deceptive-lure",
            "deceptive-page",
            "deceptive-practices",
            "deceptive-scheme",
            "deceptive-service",
            "deepfake-content",
            "device-information-collection",
            "domain-classification",
            "domain-rotation",
            "e-commerce-scam",
            "ecommerce-scam",
            "email-service-abuse",
            "extremist-content",
            "fake-giveaway",
            "fake-login",
            "fake-prize-scam",
            "fake-questionnaire",
            "fake-survey",
            "file-sharing",
            "financial-fraud",
            "financial-scam",
            "flipkart-impersonation",
            "fraud",
            "fraudulent-ecommerce",
            "fraudulent-service",
            "free-hosting",
            "gibberish-domain",
            "gore-content",
            "government-services",
            "graphic-content",
            "graphic-media",
            "hate-speech",
            "high-risk-tld",
            "illegal-activation",
            "illegal-content",
            "impersonation",
            "indicator",
            "indonesia",
            "information-harvesting",
            "insurance-phishing",
            "insurance-sector",
            "investigation-promoted",
            "investment-scam",
            "ip-access-scam",
            "italian-users",
            "jailbait",
            "leak-content-lure",
            "lidl-impersonation",
            "link-in-bio",
            "live-streaming-platform",
            "logistics",
            "logistics-phishing",
            "low-reputation",
            "malicious-domain",
            "malicious-redirect",
            "malvertising",
            "malware-bundling",
            "malware-distribution",
            "malware-hosting",
            "manipulative-lure",
            "manual-entry",
            "mastro-credit-union",
            "mateus-supermercados",
            "microsoft-365",
            "microsoft-sharepoint-impersonation",
            "mpesa",
            "nebula-x",
            "netflix",
            "new-domain",
            "newly-registered-domain",
            "nsfw-generation",
            "online-scam",
            "onlyfans-impersonation",
            "payload-delivery",
            "payment-harvesting",
            "payment-scam",
            "personal-information-collection",
            "personal-information-harvesting",
            "phishing",
            "phishing-attempt",
            "phishing-example",
            "phishing-kit",
            "phishing-page",
            "phishing-scam",
            "phishing-site",
            "pig-butchering-scam",
            "pii-harvesting",
            "pingo-doce",
            "pirate-streaming",
            "pirated-software",
            "pizza-hut-impersonation",
            "postal-service-impersonation",
            "potentially-malicious",
            "prize-scam",
            "public-platform-abuse",
            "random-domain",
            "recently-registered",
            "recently-registered-domain",
            "redirection",
            "redirector",
            "retail-sector",
            "retail-targeting",
            "roblox",
            "roblox-impersonation",
            "scam",
            "scam-related",
            "scam-site",
            "scanlations",
            "scareware",
            "seur",
            "sexually-suggestive-content",
            "shock-content",
            "social-engineering",
            "spam-distribution",
            "staples-impersonation",
            "subscription-scam",
            "supermetrics-impersonation",
            "survey-scam",
            "suspicious-domain",
            "suspicious-url",
            "suspicious-verification",
            "tech-support-scam",
            "teen-content",
            "telegram-redirection",
            "threat-scan",
            "threat-scan-evidence",
            "threat-scan-indicator",
            "traffic-redirection",
            "typo-squat",
            "typosquatting-domain",
            "uncensored-ai",
            "unclassified-threat",
            "unscanned-files",
            "unwanted-redirects",
            "unwanted-subscription",
            "unwanted-subscriptions",
            "url-redirection",
            "urlert",
            "user-reported",
            "watch-to-earn-scam",
            "webmail-phishing",
            "whatsapp-scam",
            "white-supremacist",
            "zoho-impersonation"
          ],
          "references": [
            "https://urlert.com/domain/4download.net",
            "https://urlert.com/domain/87870.cyou",
            "https://urlert.com/domain/africa.com",
            "https://urlert.com/domain/amourconnects.com",
            "https://urlert.com/domain/appspot.com",
            "https://urlert.com/domain/artbbs.al",
            "https://urlert.com/domain/benson-gmbh.top",
            "https://urlert.com/domain/blox.gifts",
            "https://urlert.com/domain/bluetickon-adslive.online",
            "https://urlert.com/domain/bridgestonemerchandise.com",
            "https://urlert.com/domain/budal05.xyz",
            "https://urlert.com/domain/campsite.bio",
            "https://urlert.com/domain/crusaders.gg",
            "https://urlert.com/domain/cudasvc.com",
            "https://urlert.com/domain/dftrx.web.id",
            "https://urlert.com/domain/eej.at",
            "https://urlert.com/domain/eibmw.com",
            "https://urlert.com/domain/facebook.com",
            "https://urlert.com/domain/fgl.cc",
            "https://urlert.com/domain/flipxu.cyou"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Automotive",
            "Financial Services",
            "Government",
            "Insurance",
            "Logistics / Supply Chain",
            "Media / Entertainment",
            "Retail / E-Commerce",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 49,
            "URL": 43,
            "hostname": 15
          },
          "indicator_count": 107,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 29,
          "modified_text": "57 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69a7aafc64d45f543f042857",
          "name": "URLert Daily Threat Intel \u2014 2026-03-04",
          "description": "URLert Daily Threat Intel \u2014 2026-03-04\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 16 | Indicators: 32\nConfirmed: 1 | Likely: 12 | Under review: 1 | Domain intel: 2\nTop threats: Phishing (12), Unknown (2), Malvertising (1), Malware Hosting (1)\nDomains: covenantsisters.org, delta-executor.com, freemining.shop, google.com, grandsealsolutions.com, hbcm.jp, jecua.cn, koirm.cn, link-hub.net, myfirsthome.org.uk, negtl.cn, nowplaytoc.com, ojuel...\n\n16 unique threats producing 32 actionable indicators. Generated by URLert automated threat intelligence.",
          "modified": "2026-03-04T03:45:59.483000",
          "created": "2026-03-04T03:45:59.483000",
          "tags": [
            "advertising",
            "automated-scan",
            "blockfi",
            "booking-com",
            "brand-impersonation",
            "brazil",
            "browser-extension",
            "credential-harvesting",
            "daily-threat-intel",
            "dangerous-domain",
            "data-harvesting",
            "deception",
            "deceptive-advertising",
            "deceptive-tactics",
            "domain-classification",
            "financial-fraud",
            "financial-sector",
            "giveaway-scam",
            "google-docs-abuse",
            "impersonation",
            "indonesian",
            "investigation-promoted",
            "kroll-administration",
            "magicbid-ai",
            "malware",
            "mateus-supermercados",
            "mining-scam",
            "new-domain",
            "newly-registered-domain",
            "non-profit-impersonation",
            "olx",
            "online-gambling",
            "phishing",
            "phishing-page",
            "phpmyadmin-impersonation",
            "prize-scam",
            "redirect-cloaking",
            "scam",
            "scam-domain",
            "tienda-mass",
            "tienda-mass-impersonation",
            "unknown",
            "unwanted-software",
            "urlert",
            "xyz-tld"
          ],
          "references": [
            "https://urlert.com/domain/covenantsisters.org",
            "https://urlert.com/domain/delta-executor.com",
            "https://urlert.com/domain/freemining.shop",
            "https://urlert.com/domain/google.com",
            "https://urlert.com/domain/grandsealsolutions.com",
            "https://urlert.com/domain/hbcm.jp",
            "https://urlert.com/domain/jecua.cn",
            "https://urlert.com/domain/koirm.cn",
            "https://urlert.com/domain/link-hub.net",
            "https://urlert.com/domain/myfirsthome.org.uk",
            "https://urlert.com/domain/negtl.cn",
            "https://urlert.com/domain/nowplaytoc.com",
            "https://urlert.com/domain/ojuelosdejalisco.gob.mx",
            "https://urlert.com/domain/ondofintrd.xyz",
            "https://urlert.com/domain/pl-3qs7q.cfd",
            "https://urlert.com/domain/smore.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Financial Services"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "urlert_intel",
            "id": "386175",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 13,
            "URL": 14,
            "hostname": 5
          },
          "indicator_count": 32,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 28,
          "modified_text": "88 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://urlert.com/domain/netlify.app",
        "https://urlert.com/domain/nowplaytoc.com",
        "https://urlert.com/domain/dkfnvk.cfd",
        "https://urlert.com/domain/logistica-central.online",
        "https://urlert.com/domain/jecua.cn",
        "https://urlert.com/domain/contaboserver.net",
        "https://urlert.com/domain/extravagant-streaming.life",
        "https://urlert.com/domain/hdid749fp1.com",
        "https://urlert.com/domain/budal05.xyz",
        "https://urlert.com/domain/allegrolokalnie.pl",
        "https://urlert.com/domain/confirm-details.report",
        "https://urlert.com/domain/brohood.my.id",
        "https://urlert.com/domain/blox.gifts",
        "https://urlert.com/domain/iyvct.xyz",
        "https://urlert.com/domain/earndailly9ja.com.ng",
        "https://urlert.com/domain/bit.ly",
        "https://urlert.com/domain/campsite.bio",
        "https://urlert.com/domain/kec.az",
        "https://urlert.com/domain/lawlovepqr.click",
        "https://urlert.com/domain/covenantsisters.org",
        "https://urlert.com/domain/myfirsthome.org.uk",
        "https://urlert.com/domain/netmirror.cc",
        "https://urlert.com/domain/facebook.hk",
        "https://urlert.com/domain/sogorn.com.br",
        "https://urlert.com/domain/3wvftweba.baby",
        "https://urlert.com/domain/ln.run",
        "https://urlert.com/domain/fyo.cc",
        "https://urlert.com/domain/modbibo.com",
        "https://urlert.com/domain/create-road.my",
        "https://urlert.com/domain/cryptor.plus",
        "https://urlert.com/domain/run.app",
        "https://urlert.com/domain/fedexredeliveryform.com",
        "https://urlert.com/domain/github.io",
        "https://urlert.com/domain/africa.com",
        "https://urlert.com/domain/cwgobal.net",
        "https://urlert.com/domain/dahl.su",
        "https://urlert.com/domain/9mod.cloud",
        "https://urlert.com/domain/964235.help",
        "https://urlert.com/domain/cheetahmall.com",
        "https://urlert.com/domain/futfanaticss.com",
        "https://urlert.com/domain/clck.ru",
        "https://urlert.com/domain/ondofintrd.xyz",
        "https://urlert.com/domain/j82k.site",
        "https://urlert.com/domain/daily777ween666.com",
        "https://urlert.com/domain/ethias.be",
        "https://urlert.com/domain/bonanza-gha.work",
        "https://urlert.com/domain/clc.cx",
        "https://urlert.com/domain/cloudstoragex.shop",
        "https://urlert.com/domain/ca-paget.sbs",
        "https://urlert.com/domain/beyondclosetstore.com",
        "https://urlert.com/domain/discord-tracker.com",
        "https://urlert.com/domain/app.link",
        "https://urlert.com/domain/elricat.co.uk",
        "https://urlert.com/domain/kxcoi.com",
        "https://urlert.com/domain/easycash777.com",
        "https://urlert.com/domain/explodely.com",
        "https://urlert.com/domain/koirm.cn",
        "https://urlert.com/domain/888-gpifc.vip",
        "https://urlert.com/domain/bnz-gov.cam",
        "https://urlert.com/domain/minertech.co",
        "https://urlert.com/domain/moriloti.cfd",
        "https://urlert.com/domain/e.vg",
        "https://urlert.com/domain/arcworld.one",
        "https://urlert.com/domain/donutstake.com",
        "https://urlert.com/domain/ftghnbjkolswedfrcvbnhgfdswazxcvbnmjkolmpqwasderftgbnvcza.net",
        "https://urlert.com/domain/eibmw.com",
        "https://urlert.com/domain/forms.gle",
        "https://urlert.com/domain/effectivegatecpm.com",
        "https://urlert.com/domain/grandsealsolutions.com",
        "https://urlert.com/domain/servicos.ru",
        "https://urlert.com/domain/6489.pro",
        "https://urlert.com/domain/findzu.net",
        "https://urlert.com/domain/giveawaybot.cc",
        "https://urlert.com/domain/manitoba-fine-payment.cfd",
        "https://urlert.com/domain/87870.cyou",
        "https://urlert.com/domain/cudasvc.com",
        "https://urlert.com/domain/apartment-16896824.com",
        "https://urlert.com/domain/ffddhh.com",
        "https://urlert.com/domain/briansclub.vc",
        "https://urlert.com/domain/cloudnext.pro",
        "https://urlert.com/domain/httpps-roblox.co",
        "https://urlert.com/domain/fgl.cc",
        "https://urlert.com/domain/appspot.com",
        "https://urlert.com/domain/crusaders.gg",
        "https://urlert.com/domain/355287.com",
        "https://urlert.com/domain/e-entrega.co",
        "https://urlert.com/domain/hbcm.jp",
        "https://urlert.com/domain/meusitehostgator.com.br",
        "https://urlert.com/domain/feua.cn",
        "https://urlert.com/domain/bitunixg.com",
        "https://urlert.com/domain/artbbs.al",
        "https://urlert.com/domain/cashboost.live",
        "https://urlert.com/domain/beacons.ai",
        "https://urlert.com/domain/cointerac.org",
        "https://urlert.com/domain/harafbangroup.com.ng",
        "https://urlert.com/domain/us.cc",
        "https://urlert.com/domain/platorelay.com",
        "https://urlert.com/domain/dipherex.com",
        "https://urlert.com/domain/beetrade.me",
        "https://urlert.com/domain/beb6.com",
        "https://urlert.com/domain/hornygiirl.com",
        "https://urlert.com/domain/gamedrive.org",
        "https://urlert.com/domain/lfi9d.vip",
        "https://urlert.com/domain/asusnext.us",
        "https://urlert.com/domain/gesowin77.pro",
        "https://urlert.com/domain/is.gd",
        "https://urlert.com/domain/mycostperks.site",
        "https://urlert.com/domain/compromisedblog.com",
        "https://urlert.com/domain/benson-gmbh.top",
        "https://urlert.com/domain/ovagames.com",
        "https://urlert.com/domain/ieuj.cn",
        "https://urlert.com/domain/ojuelosdejalisco.gob.mx",
        "https://urlert.com/domain/dattingrooms.com",
        "https://urlert.com/domain/571084.xin",
        "https://urlert.com/domain/whorez.net",
        "https://urlert.com/domain/fafda.to",
        "https://urlert.com/domain/dsvbc.icu",
        "https://urlert.com/domain/courtlylover.com",
        "https://urlert.com/domain/playmogo.com",
        "https://urlert.com/domain/qingtaishanghao.ink",
        "https://urlert.com/domain/geometrydashvn.org",
        "https://urlert.com/domain/f09poypkdea3.com",
        "https://urlert.com/domain/9990.site",
        "https://urlert.com/domain/filecr.com",
        "https://urlert.com/domain/localsexapp.com",
        "https://urlert.com/domain/738833.com",
        "https://urlert.com/domain/due-fineac.com",
        "https://urlert.com/domain/ankergames.net",
        "https://urlert.com/domain/appbitly.com",
        "https://urlert.com/domain/dratrans.com",
        "https://urlert.com/domain/freemining.shop",
        "https://urlert.com/domain/globalbusinespays.com",
        "https://urlert.com/domain/firebaseapp.com",
        "https://urlert.com/domain/ct.ws",
        "https://urlert.com/domain/dexo.click",
        "https://urlert.com/domain/compy.ca",
        "https://urlert.com/domain/direct-link.net",
        "https://urlert.com/domain/pl-3qs7q.cfd",
        "https://urlert.com/domain/dpoiq.life",
        "https://urlert.com/domain/iqkf.com",
        "https://urlert.com/domain/dahlmessenger.com",
        "https://urlert.com/domain/officence.com",
        "https://urlert.com/domain/emailroute.net",
        "https://urlert.com/domain/4download.net",
        "https://urlert.com/domain/dpdlocafd.shop",
        "https://urlert.com/domain/fitgirl-repacks.site",
        "https://urlert.com/domain/eej.at",
        "https://urlert.com/domain/hkjhsuies.com.es",
        "https://urlert.com/domain/delta-executor.com",
        "https://urlert.com/domain/amourconnects.com",
        "https://urlert.com/domain/bridgestonemerchandise.com",
        "https://urlert.com/domain/aviatorfine.com",
        "https://urlert.com/domain/iaoaa.cn",
        "https://urlert.com/domain/google.com",
        "https://urlert.com/domain/cs2by.com",
        "https://urlert.com/domain/gamenuv.com",
        "https://urlert.com/domain/bucara.my.id",
        "https://urlert.com/domain/nsknb.com",
        "https://urlert.com/domain/challengermode.network",
        "https://urlert.com/domain/digital-solves.com",
        "https://urlert.com/domain/appinjects.com",
        "https://urlert.com/domain/getintopc.com",
        "https://urlert.com/domain/bunnyband.com",
        "https://urlert.com/domain/me-ebay.com",
        "https://urlert.com/domain/dftrx.web.id",
        "https://urlert.com/domain/homelyero.com",
        "https://urlert.com/domain/premiumcartoons.cc",
        "https://urlert.com/domain/smore.com",
        "https://urlert.com/domain/casajoys.com",
        "https://urlert.com/domain/2mz3me.homes",
        "https://urlert.com/domain/negtl.cn",
        "https://urlert.com/domain/bookscloud.net",
        "https://urlert.com/domain/irevenue.co",
        "https://urlert.com/domain/binance-ltd.vip",
        "https://urlert.com/domain/flashbot.trade",
        "https://urlert.com/domain/flipxu.cyou",
        "https://urlert.com/domain/codecarteinstant.com",
        "https://urlert.com/domain/flirtcaster.com",
        "https://urlert.com/domain/facebook.com",
        "https://urlert.com/domain/bluetickon-adslive.online",
        "https://urlert.com/domain/link-hub.net",
        "https://urlert.com/domain/scloud.ws",
        "https://urlert.com/domain/appwrite.network"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [
            "Government",
            "Insurance",
            "Media / entertainment",
            "Retail / e-commerce",
            "Technology",
            "Hospitality",
            "Logistics / supply chain",
            "Automotive",
            "Telecommunications",
            "Financial services",
            "Energy",
            "Real estate"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 11,
  "pulses": [
    {
      "id": "69f2a9b03bbc9452cba7ab87",
      "name": "URLert Daily Threat Intel \u2014 2026-04-30",
      "description": "URLert Daily Threat Intel \u2014 2026-04-30\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 40 | Indicators: 81\nConfirmed: 8 | Likely: 31 | Domain intel: 1\nTop threats: Phishing (30), Malware Hosting (4), Dropper (4), Unknown (2)\nDomains: 2mz3me.homes, 3wvftweba.baby, apartment-16896824.com, appbitly.com, beb6.com, beyondclosetstore.com, briansclub.vc, cheetahmall.com, courtlylover.com, due-fineac.com, emailroute.net, filec...\n\n40 unique threats producing 81 actionable indicators. Generated by URLert automated threat intelligence.",
      "modified": "2026-05-29T21:00:00.267000",
      "created": "2026-04-30T01:00:32.718000",
      "tags": [
        "+18-content",
        "abused-platform",
        "account-takeover",
        "aggressive-prompts",
        "anti-analysis",
        "app-distribution",
        "automated-scan",
        "bitly-impersonation",
        "brand-impersonation",
        "cacau-show",
        "child-exploitation",
        "clickbait",
        "content-spreading",
        "copenhagen-municipality",
        "correos",
        "cracked-software-distribution",
        "credential-harvesting",
        "cryptocurrency",
        "cryptocurrency-fraud",
        "cryptominer",
        "cvv-marketplace",
        "cybercriminal-infrastructure",
        "daily-threat-intel",
        "darknet-market",
        "data-breach",
        "data-collection",
        "dating-scam",
        "deceptive-domain",
        "deceptive-download",
        "deceptive-login",
        "deceptive-practices",
        "deceptive-redirect",
        "deceptive-tactics",
        "domain-classification",
        "domain-impersonation",
        "dpd-impersonation",
        "drugs",
        "evasion-tactic",
        "exit-scam",
        "fake-interface",
        "fake-security-challenge",
        "fake-shop",
        "fake-store",
        "fake-testimonials",
        "file-download",
        "financial-data-theft",
        "financial-information-harvesting",
        "financial-loss",
        "financial-scam",
        "fraud",
        "fraudulent-activity",
        "game-piracy",
        "geometry-dash",
        "government-impersonation",
        "hacking-services",
        "hostinger",
        "identity-theft",
        "ikea",
        "illegal-content",
        "imdb-impersonation",
        "line-impersonation",
        "malicious-extensions",
        "malware-distribution",
        "malware-hosting",
        "malware-reports",
        "media-entertainment",
        "media-impersonation",
        "mobile-app-distribution",
        "modded-apk",
        "nestle-dolce-gusto-impersonation",
        "new-domain",
        "newly-registered-domain",
        "obfuscated-url",
        "orico-impersonation",
        "payload-delivery",
        "payment-scam",
        "pennsylvania",
        "personal-information-collection",
        "personal-information-harvesting",
        "phishing",
        "phishing-site",
        "pirated-software",
        "ponzi-scheme",
        "predatory-lending",
        "pyramid-scheme",
        "random-domain",
        "recent-domain",
        "recruitment-scam",
        "redirect-chain",
        "registration-bonus-scam",
        "scam",
        "social-media-spam",
        "spotahome-impersonation",
        "steam",
        "stolen-financial-data",
        "subdomain-abuse",
        "survey-scam",
        "suspicious-domain",
        "suspicious-pricing",
        "suspicious-subdomain",
        "task-scam",
        "trojan",
        "typosquatting",
        "unauthorized-apk-distribution",
        "untrusted-source",
        "url-shortener",
        "urlert",
        "vortex-market",
        "wallet-drainer",
        "wifi-password-scam",
        "xvideos-impersonation",
        "youtube-lure"
      ],
      "references": [
        "https://urlert.com/domain/2mz3me.homes",
        "https://urlert.com/domain/3wvftweba.baby",
        "https://urlert.com/domain/apartment-16896824.com",
        "https://urlert.com/domain/appbitly.com",
        "https://urlert.com/domain/beb6.com",
        "https://urlert.com/domain/beyondclosetstore.com",
        "https://urlert.com/domain/briansclub.vc",
        "https://urlert.com/domain/cheetahmall.com",
        "https://urlert.com/domain/courtlylover.com",
        "https://urlert.com/domain/due-fineac.com",
        "https://urlert.com/domain/emailroute.net",
        "https://urlert.com/domain/filecr.com",
        "https://urlert.com/domain/flashbot.trade",
        "https://urlert.com/domain/geometrydashvn.org",
        "https://urlert.com/domain/globalbusinespays.com",
        "https://urlert.com/domain/hdid749fp1.com",
        "https://urlert.com/domain/iaoaa.cn",
        "https://urlert.com/domain/is.gd",
        "https://urlert.com/domain/iyvct.xyz",
        "https://urlert.com/domain/moriloti.cfd"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Financial Services",
        "Government",
        "Logistics / Supply Chain",
        "Media / Entertainment",
        "Real Estate",
        "Retail / E-Commerce",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "urlert_intel",
        "id": "386175",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 24,
        "URL": 23,
        "hostname": 11
      },
      "indicator_count": 58,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 30,
      "modified_text": "1 day ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a18e51482e9efa582093669",
      "name": "URLert Daily Threat Intel \u2014 2026-05-29",
      "description": "URLert Daily Threat Intel \u2014 2026-05-29\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 20 | Indicators: 37\nConfirmed: 4 | Likely: 16\nTop threats: Phishing (12), Malware Hosting (5), Dropper (2), Unknown (1)\nDomains: compy.ca, dsvbc.icu, ffddhh.com, fitgirl-repacks.site, getintopc.com, kxcoi.com, ln.run, modbibo.com, nowplaytoc.com, nsknb.com, officence.com, playmogo.com, qingtaishanghao.ink, run.app, ...\n\n20 unique threats producing 37 actionable indicators. Generated by URLert automated threat intelligence.",
      "modified": "2026-05-29T01:00:04.622000",
      "created": "2026-05-29T01:00:04.622000",
      "tags": [
        "adult-content",
        "automated-scan",
        "brand-impersonation",
        "bypass-security",
        "cracked-software",
        "credential-harvesting",
        "cryptocurrency-scam",
        "daily-threat-intel",
        "data-harvesting",
        "data-theft",
        "deceptive-download",
        "deceptive-landing-page",
        "deceptive-registration",
        "delivery-service-impersonation",
        "download-funnel",
        "drm-bypass",
        "evasion-technique",
        "explicit-content-bait",
        "explicit-lure",
        "financial-services",
        "government-impersonation",
        "illegal-content",
        "malware-distribution",
        "malware-hosting",
        "microsoft",
        "mobile-games",
        "mod-apk",
        "new-domain",
        "newly-registered-domain",
        "offensive-content",
        "personal-information-theft",
        "phishing",
        "phishing-site",
        "pirated-software",
        "redirect-chain",
        "redirect-service",
        "repacked-software",
        "restricted-substances",
        "riskware",
        "scam",
        "scam-platform",
        "security-risk",
        "sensitive-information-theft",
        "seur-impersonation",
        "social-engineering",
        "software-piracy",
        "suspicious-domain",
        "unauthorized-software",
        "untrusted-domain",
        "url-masking",
        "urlert",
        "zendesk"
      ],
      "references": [
        "https://urlert.com/domain/compy.ca",
        "https://urlert.com/domain/dsvbc.icu",
        "https://urlert.com/domain/ffddhh.com",
        "https://urlert.com/domain/fitgirl-repacks.site",
        "https://urlert.com/domain/getintopc.com",
        "https://urlert.com/domain/kxcoi.com",
        "https://urlert.com/domain/ln.run",
        "https://urlert.com/domain/modbibo.com",
        "https://urlert.com/domain/nowplaytoc.com",
        "https://urlert.com/domain/nsknb.com",
        "https://urlert.com/domain/officence.com",
        "https://urlert.com/domain/playmogo.com",
        "https://urlert.com/domain/qingtaishanghao.ink",
        "https://urlert.com/domain/run.app",
        "https://urlert.com/domain/scloud.ws",
        "https://urlert.com/domain/servicos.ru",
        "https://urlert.com/domain/sogorn.com.br",
        "https://urlert.com/domain/us.cc",
        "https://urlert.com/domain/whorez.net"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Financial Services",
        "Government",
        "Logistics / Supply Chain",
        "Retail / E-Commerce",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "urlert_intel",
        "id": "386175",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 16,
        "domain": 10,
        "hostname": 8
      },
      "indicator_count": 34,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 30,
      "modified_text": "2 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69eeb5306d5f58c6044105cc",
      "name": "URLert Daily Threat Intel \u2014 2026-04-27",
      "description": "URLert Daily Threat Intel \u2014 2026-04-27\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 40 | Indicators: 78\nConfirmed: 9 | Likely: 31\nTop threats: Phishing (33), Malware Hosting (3), Dropper (3), Malvertising (1)\nDomains: 355287.com, bunnyband.com, clc.cx, confirm-details.report, cwgobal.net, dipherex.com, dratrans.com, easycash777.com, forms.gle, giveawaybot.cc, hkjhsuies.com.es, hornygiirl.com, localsexap...\n\n40 unique threats producing 78 actionable indicators. Generated by URLert automated threat intelligence.",
      "modified": "2026-05-26T20:17:24.825000",
      "created": "2026-04-27T01:00:32.645000",
      "tags": [
        "account-takeover",
        "anti-analysis",
        "app-install-malware",
        "auto-generated-domain",
        "automated-scan",
        "betting",
        "bonus-scam",
        "brand-impersonation",
        "budbee-impersonation",
        "click-through-scam",
        "coreweave-impersonation",
        "counterfeit-software",
        "credential-harvesting",
        "daily-threat-intel",
        "dating-scam",
        "deceptive-bait",
        "deceptive-captcha",
        "deceptive-landing-page",
        "deceptive-marketing",
        "deceptive-redirect",
        "deceptive-scam",
        "deceptive-software",
        "dickies",
        "discord-impersonation",
        "disposable-domain",
        "ecommerce",
        "ecuador",
        "explicit-popups",
        "fake-financial-service",
        "fake-giveaway",
        "fake-login",
        "fake-online-store",
        "fake-products",
        "fake-social-proof",
        "fake-testimonials",
        "financial-fraud",
        "financial-scam",
        "financial-service-impersonation",
        "footwear-retail",
        "fraudulent-content",
        "fraudulent-services",
        "free-games-lure",
        "gambling",
        "gambling-scam",
        "gambling-site",
        "gaming-impersonation",
        "google-forms",
        "high-risk-domain",
        "high-risk-tld",
        "identity-service-impersonation",
        "investment-scam",
        "loan-scam",
        "malicious-android-app",
        "malicious-redirect",
        "malvertising",
        "malware-delivery",
        "malware-distribution",
        "malware-risk",
        "new-domain",
        "newly-registered-domain",
        "online-scam",
        "pc-games",
        "personal-information-harvesting",
        "phishing",
        "phishing-infrastructure",
        "phishing-kit",
        "phishing-site",
        "platoboost",
        "redirect-chain",
        "redirection",
        "revanced-project",
        "roblox-impersonation",
        "roblox-users",
        "robux-scam",
        "scam",
        "scams",
        "shopee",
        "social-engineering",
        "social-proof-manipulation",
        "software-piracy",
        "steam",
        "suggestive-imagery",
        "sumup",
        "task-based-scam",
        "task-scam",
        "traffic-redirection",
        "twitter-impersonation",
        "typosquatting",
        "unauthorized-software",
        "unauthorized-streaming",
        "unwanted-programs",
        "unwanted-software",
        "url-obfuscation",
        "url-redirection",
        "urlert",
        "verify-your-connection-scam",
        "victus",
        "warez-site",
        "wixsite-abuse",
        "young-domain",
        "youtube-impersonation"
      ],
      "references": [
        "https://urlert.com/domain/355287.com",
        "https://urlert.com/domain/bunnyband.com",
        "https://urlert.com/domain/clc.cx",
        "https://urlert.com/domain/confirm-details.report",
        "https://urlert.com/domain/cwgobal.net",
        "https://urlert.com/domain/dipherex.com",
        "https://urlert.com/domain/dratrans.com",
        "https://urlert.com/domain/easycash777.com",
        "https://urlert.com/domain/forms.gle",
        "https://urlert.com/domain/giveawaybot.cc",
        "https://urlert.com/domain/hkjhsuies.com.es",
        "https://urlert.com/domain/hornygiirl.com",
        "https://urlert.com/domain/localsexapp.com",
        "https://urlert.com/domain/meusitehostgator.com.br",
        "https://urlert.com/domain/netlify.app",
        "https://urlert.com/domain/netmirror.cc",
        "https://urlert.com/domain/nowplaytoc.com",
        "https://urlert.com/domain/ovagames.com",
        "https://urlert.com/domain/platorelay.com",
        "https://urlert.com/domain/premiumcartoons.cc"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Financial Services",
        "Government",
        "Logistics / Supply Chain",
        "Media / Entertainment",
        "Retail / E-Commerce",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "urlert_intel",
        "id": "386175",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 23,
        "URL": 26,
        "hostname": 8
      },
      "indicator_count": 57,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 31,
      "modified_text": "4 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69ec121455951901fef8a045",
      "name": "URLert Daily Threat Intel \u2014 2026-04-25",
      "description": "URLert Daily Threat Intel \u2014 2026-04-25\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 63 | Indicators: 122\nConfirmed: 19 | Likely: 44\nTop threats: Phishing (51), Malware Hosting (4), Unknown (3), Dropper (3), Malvertising (2)\nDomains: 6489.pro, app.link, beacons.ai, bit.ly, bookscloud.net, brohood.my.id, bunnyband.com, ca-paget.sbs, cointerac.org, contaboserver.net, cs2by.com, ct.ws, dexo.click, dkfnvk.cfd, dpdlocafd.sh...\n\n63 unique threats producing 122 actionable indicators. Generated by URLert automated threat intelligence.",
      "modified": "2026-05-25T00:14:07.625000",
      "created": "2026-04-25T01:00:04.128000",
      "tags": [
        "abused-hosting",
        "account-takeover",
        "adult-content-lure",
        "aggressive-ads",
        "ai-trading-bot",
        "anubis-challenge-service",
        "artificial-urgency",
        "automated-scan",
        "automatic-download",
        "azure-blob-storage",
        "booter",
        "brand-impersonation",
        "broken-site",
        "browser-locker",
        "burberry",
        "car-wrap-scam",
        "cloaking",
        "code-repository-impersonation",
        "command-execution",
        "complex-redirect-chain",
        "compromised-site",
        "contabo",
        "content-locker",
        "content-locker-scam",
        "costco-impersonation",
        "credential-harvesting",
        "crypto-scam",
        "cryptocurrency",
        "cyberattack-facilitation",
        "daily-threat-intel",
        "data-harvesting",
        "ddos-service",
        "deceptive-domain-email",
        "deceptive-marketing",
        "deceptive-practices",
        "deceptive-redirect",
        "deceptive-tactics",
        "deceptive-url",
        "delivery-scam",
        "dpd-impersonation",
        "e-commerce-fraud",
        "e-commerce-scam",
        "email-verification",
        "energy-crisis",
        "evasion-technique",
        "executable-malware",
        "extortion",
        "fake-discounts",
        "fake-download",
        "fake-prize",
        "fake-promotion",
        "fake-urgency",
        "fake-verification",
        "fake-virus-alert",
        "fanatics-impersonation",
        "file-sharing",
        "financial-data-harvesting",
        "financial-fraud",
        "financial-information-harvesting",
        "financial-scam",
        "fraudulent-infrastructure",
        "fraudulent-platform",
        "fraudulent-retail",
        "fraudulent-scheme",
        "fraudulent-sweepstakes",
        "fuel-voucher",
        "gambling-platform",
        "game-related-lure",
        "gaming",
        "gift-card-scam",
        "giveaway-scam",
        "google-cloud-storage-abuse",
        "google-impersonation",
        "government-impersonation",
        "government-targeting",
        "identity-theft",
        "impersonation",
        "infrastructure-misuse",
        "interac",
        "investment-scam",
        "lidl-impersonation",
        "linkvertise",
        "logistics-impersonation",
        "logistics-supply-chain",
        "low-reputation",
        "low-reputation-domain",
        "malicious-download",
        "malicious-file-delivery",
        "malicious-infrastructure",
        "malicious-redirection",
        "malicious-scripts",
        "malvertising",
        "malware-delivery",
        "malware-distribution",
        "mothers-day-scam",
        "multi-provider-phishing",
        "neosurf",
        "new-domain",
        "newly-registered-domain",
        "ontario-government",
        "payload-delivery",
        "payment-voucher-scam",
        "persistent-malware",
        "personal-information-collection",
        "personal-information-harvesting",
        "petrom",
        "phishing",
        "pii-collection",
        "plumeimpactor",
        "potentially-unwanted-software",
        "redirect",
        "roblox",
        "roblox-impersonation",
        "scam",
        "scam-ecommerce",
        "scam-site",
        "servientrega-impersonation",
        "shadow-reporting",
        "shein",
        "social-engineering",
        "software-piracy",
        "software-repository-impersonation",
        "spain",
        "spam-promotion",
        "spotify-impersonation",
        "steam",
        "stress-testing",
        "stresser",
        "survey-scam",
        "suspicious-domain",
        "suspicious-redirect",
        "suspicious-tld",
        "suspicious-url",
        "task-based-scam",
        "task-scam",
        "tech-support-scam",
        "technical-errors",
        "telegram-bot",
        "tracking-parameters",
        "trading-platform",
        "traffic-redirection",
        "transcash",
        "typosquatting",
        "uber-impersonation",
        "unknown-binary",
        "unsecured-site",
        "unverified-health-claims",
        "unwanted-software",
        "url-shortener",
        "urlert",
        "usps",
        "xyz-domain"
      ],
      "references": [
        "https://urlert.com/domain/6489.pro",
        "https://urlert.com/domain/app.link",
        "https://urlert.com/domain/beacons.ai",
        "https://urlert.com/domain/bit.ly",
        "https://urlert.com/domain/bookscloud.net",
        "https://urlert.com/domain/brohood.my.id",
        "https://urlert.com/domain/bunnyband.com",
        "https://urlert.com/domain/ca-paget.sbs",
        "https://urlert.com/domain/cointerac.org",
        "https://urlert.com/domain/contaboserver.net",
        "https://urlert.com/domain/cs2by.com",
        "https://urlert.com/domain/ct.ws",
        "https://urlert.com/domain/dexo.click",
        "https://urlert.com/domain/dkfnvk.cfd",
        "https://urlert.com/domain/dpdlocafd.shop",
        "https://urlert.com/domain/e-entrega.co",
        "https://urlert.com/domain/ethias.be",
        "https://urlert.com/domain/fafda.to",
        "https://urlert.com/domain/futfanaticss.com",
        "https://urlert.com/domain/gamedrive.org"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Energy",
        "Financial Services",
        "Government",
        "Hospitality",
        "Logistics / Supply Chain",
        "Media / Entertainment",
        "Retail / E-Commerce"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "urlert_intel",
        "id": "386175",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 33,
        "URL": 36,
        "hostname": 13
      },
      "indicator_count": 82,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 30,
      "modified_text": "6 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69e42a619c0c8949c578f81e",
      "name": "URLert Daily Threat Intel \u2014 2026-04-19",
      "description": "URLert Daily Threat Intel \u2014 2026-04-19\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 41 | Indicators: 71\nConfirmed: 14 | Likely: 25 | Domain intel: 2\nTop threats: Phishing (29), Malvertising (3), Dropper (3), Malware Hosting (2), Unknown (2)\nDomains: bitunixg.com, bunnyband.com, casajoys.com, cashboost.live, create-road.my, dahl.su, dahlmessenger.com, digital-solves.com, direct-link.net, earndailly9ja.com.ng, findzu.net, gesowin77.pro,...\n\n41 unique threats producing 71 actionable indicators. Generated by URLert automated threat intelligence.",
      "modified": "2026-05-18T22:17:43.844000",
      "created": "2026-04-19T01:05:37.600000",
      "tags": [
        "account-verification-scam",
        "adware",
        "android-malware",
        "anti-analysis",
        "app-impersonation",
        "automated-scan",
        "backend-infrastructure",
        "binary-options-scam",
        "brand-impersonation",
        "brazil",
        "browser-locking-scam",
        "cloaking",
        "communication-decryption",
        "communication-eavesdropping",
        "communication-interception",
        "content-gating",
        "costco",
        "counterfeit-apps",
        "counterfeit-cards",
        "counterfeit-money",
        "cpf",
        "credential-harvesting",
        "crypto-scam",
        "cryptocurrency",
        "cryptocurrency-scam",
        "daily-threat-intel",
        "data-exfiltration",
        "data-harvesting",
        "deceptive-content",
        "deceptive-domain",
        "deceptive-practices",
        "deceptive-promotion",
        "deposit-scam",
        "domain-classification",
        "evasive-techniques",
        "extortion",
        "fake-news",
        "fake-parking-ticket",
        "fake-platform",
        "fake-reward",
        "fake-statistics",
        "fake-survey",
        "fake-testimonials",
        "financial-fraud",
        "financial-scam",
        "fiverr",
        "fiverr-impersonation",
        "fraudulent",
        "fraudulent-sales",
        "gambling-scam",
        "get-rich-quick-scheme",
        "giveaway-scam",
        "globe-x",
        "google-docs-hosting",
        "government-impersonation",
        "green-energy-investment",
        "high-risk-tld",
        "high-yield-investment-program",
        "impersonation",
        "imvu",
        "investment-fraud",
        "investment-scam",
        "jurassic-world",
        "legitimate-platform-abuse",
        "linkvertise",
        "login-portal",
        "logistics",
        "malicious-downloads",
        "malicious-infrastructure",
        "malicious-redirect",
        "malicious-redirector",
        "malicious-site",
        "malware-delivery",
        "malware-distribution",
        "man-in-the-middle",
        "manitoba-government",
        "mitm-attacks",
        "new-domain",
        "newly-registered-domain",
        "payment-harvesting",
        "phishing",
        "pig-butchering",
        "pii-collection",
        "potentially-unwanted-software",
        "privacy-risk",
        "privacy-violation",
        "redirect-chain",
        "redirector",
        "rekonise-platform",
        "revanced-impersonation",
        "roblox",
        "roblox-impersonation",
        "scam",
        "scam-site",
        "shufersal-impersonation",
        "social-engineering",
        "social-media-engagement",
        "suspicious-network",
        "suspicious-redirects",
        "task-based-scam",
        "task-scam",
        "telega.me",
        "telegram-traffic",
        "telegram-traffic-interception",
        "third-party-telegram-client",
        "traffic-distribution-system",
        "traffic-interception",
        "twitter-impersonation",
        "typo-squatting",
        "typosquatting",
        "unauthorized-tracking",
        "unrealistic-returns",
        "unwanted-content",
        "unwanted-software",
        "urlert",
        "weakened-encryption",
        "webcam-capture",
        "withdrawal-scam"
      ],
      "references": [
        "https://urlert.com/domain/bitunixg.com",
        "https://urlert.com/domain/bunnyband.com",
        "https://urlert.com/domain/casajoys.com",
        "https://urlert.com/domain/cashboost.live",
        "https://urlert.com/domain/create-road.my",
        "https://urlert.com/domain/dahl.su",
        "https://urlert.com/domain/dahlmessenger.com",
        "https://urlert.com/domain/digital-solves.com",
        "https://urlert.com/domain/direct-link.net",
        "https://urlert.com/domain/earndailly9ja.com.ng",
        "https://urlert.com/domain/findzu.net",
        "https://urlert.com/domain/gesowin77.pro",
        "https://urlert.com/domain/github.io",
        "https://urlert.com/domain/google.com",
        "https://urlert.com/domain/httpps-roblox.co",
        "https://urlert.com/domain/iqkf.com",
        "https://urlert.com/domain/irevenue.co",
        "https://urlert.com/domain/logistica-central.online",
        "https://urlert.com/domain/manitoba-fine-payment.cfd",
        "https://urlert.com/domain/mycostperks.site"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Financial Services",
        "Government",
        "Logistics / Supply Chain",
        "Media / Entertainment",
        "Retail / E-Commerce"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "urlert_intel",
        "id": "386175",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 24,
        "URL": 25,
        "hostname": 4
      },
      "indicator_count": 53,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 30,
      "modified_text": "12 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69ed6874491be5ba0e959599",
      "name": "URLert Daily Threat Intel \u2014 2026-04-19",
      "description": "URLert Daily Threat Intel \u2014 2026-04-19\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 41 | Indicators: 71\nConfirmed: 14 | Likely: 25 | Domain intel: 2\nTop threats: Phishing (29), Malvertising (3), Dropper (3), Malware Hosting (2), Unknown (2)\nDomains: bitunixg.com, bunnyband.com, casajoys.com, cashboost.live, create-road.my, dahl.su, dahlmessenger.com, digital-solves.com, direct-link.net, earndailly9ja.com.ng, findzu.net, gesowin77.pro,...\n\n41 unique threats producing 71 actionable indicators. Generated by URLert automated threat intelligence.",
      "modified": "2026-05-18T22:17:43.844000",
      "created": "2026-04-26T01:20:52.086000",
      "tags": [
        "account-verification-scam",
        "adware",
        "android-malware",
        "anti-analysis",
        "app-impersonation",
        "automated-scan",
        "backend-infrastructure",
        "binary-options-scam",
        "brand-impersonation",
        "brazil",
        "browser-locking-scam",
        "cloaking",
        "communication-decryption",
        "communication-eavesdropping",
        "communication-interception",
        "content-gating",
        "costco",
        "counterfeit-apps",
        "counterfeit-cards",
        "counterfeit-money",
        "cpf",
        "credential-harvesting",
        "crypto-scam",
        "cryptocurrency",
        "cryptocurrency-scam",
        "daily-threat-intel",
        "data-exfiltration",
        "data-harvesting",
        "deceptive-content",
        "deceptive-domain",
        "deceptive-practices",
        "deceptive-promotion",
        "deposit-scam",
        "domain-classification",
        "evasive-techniques",
        "extortion",
        "fake-news",
        "fake-parking-ticket",
        "fake-platform",
        "fake-reward",
        "fake-statistics",
        "fake-survey",
        "fake-testimonials",
        "financial-fraud",
        "financial-scam",
        "fiverr",
        "fiverr-impersonation",
        "fraudulent",
        "fraudulent-sales",
        "gambling-scam",
        "get-rich-quick-scheme",
        "giveaway-scam",
        "globe-x",
        "google-docs-hosting",
        "government-impersonation",
        "green-energy-investment",
        "high-risk-tld",
        "high-yield-investment-program",
        "impersonation",
        "imvu",
        "investment-fraud",
        "investment-scam",
        "jurassic-world",
        "legitimate-platform-abuse",
        "linkvertise",
        "login-portal",
        "logistics",
        "malicious-downloads",
        "malicious-infrastructure",
        "malicious-redirect",
        "malicious-redirector",
        "malicious-site",
        "malware-delivery",
        "malware-distribution",
        "man-in-the-middle",
        "manitoba-government",
        "mitm-attacks",
        "new-domain",
        "newly-registered-domain",
        "payment-harvesting",
        "phishing",
        "pig-butchering",
        "pii-collection",
        "potentially-unwanted-software",
        "privacy-risk",
        "privacy-violation",
        "redirect-chain",
        "redirector",
        "rekonise-platform",
        "revanced-impersonation",
        "roblox",
        "roblox-impersonation",
        "scam",
        "scam-site",
        "shufersal-impersonation",
        "social-engineering",
        "social-media-engagement",
        "suspicious-network",
        "suspicious-redirects",
        "task-based-scam",
        "task-scam",
        "telega.me",
        "telegram-traffic",
        "telegram-traffic-interception",
        "third-party-telegram-client",
        "traffic-distribution-system",
        "traffic-interception",
        "twitter-impersonation",
        "typo-squatting",
        "typosquatting",
        "unauthorized-tracking",
        "unrealistic-returns",
        "unwanted-content",
        "unwanted-software",
        "urlert",
        "weakened-encryption",
        "webcam-capture",
        "withdrawal-scam"
      ],
      "references": [
        "https://urlert.com/domain/bitunixg.com",
        "https://urlert.com/domain/bunnyband.com",
        "https://urlert.com/domain/casajoys.com",
        "https://urlert.com/domain/cashboost.live",
        "https://urlert.com/domain/create-road.my",
        "https://urlert.com/domain/dahl.su",
        "https://urlert.com/domain/dahlmessenger.com",
        "https://urlert.com/domain/digital-solves.com",
        "https://urlert.com/domain/direct-link.net",
        "https://urlert.com/domain/earndailly9ja.com.ng",
        "https://urlert.com/domain/findzu.net",
        "https://urlert.com/domain/gesowin77.pro",
        "https://urlert.com/domain/github.io",
        "https://urlert.com/domain/google.com",
        "https://urlert.com/domain/httpps-roblox.co",
        "https://urlert.com/domain/iqkf.com",
        "https://urlert.com/domain/irevenue.co",
        "https://urlert.com/domain/logistica-central.online",
        "https://urlert.com/domain/manitoba-fine-payment.cfd",
        "https://urlert.com/domain/mycostperks.site"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Financial Services",
        "Government",
        "Logistics / Supply Chain",
        "Media / Entertainment",
        "Retail / E-Commerce"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "urlert_intel",
        "id": "386175",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 24,
        "URL": 25,
        "hostname": 4
      },
      "indicator_count": 53,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 31,
      "modified_text": "12 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69dd91ae78f490fd44e82d33",
      "name": "URLert Daily Threat Intel \u2014 2026-04-14",
      "description": "URLert Daily Threat Intel \u2014 2026-04-14\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 67 | Indicators: 113\nConfirmed: 27 | Likely: 38 | Domain intel: 2\nTop threats: Phishing (49), Malware Hosting (12), Malvertising (3), Dropper (2), Exploit Kit (1)\nDomains: 738833.com, 888-gpifc.vip, 964235.help, 9mod.cloud, ankergames.net, appinjects.com, asusnext.us, binance-ltd.vip, bnz-gov.cam, bucara.my.id, bunnyband.com, challengermode.network, clck.ru,...\n\n67 unique threats producing 113 actionable indicators. Generated by URLert automated threat intelligence.",
      "modified": "2026-05-14T01:05:16.798000",
      "created": "2026-04-14T01:00:29.601000",
      "tags": [
        ".monster-tld",
        "abused-platform",
        "account-takeover",
        "account-theft",
        "ad-fraud",
        "adult-content-scam",
        "adult-dating-scam",
        "advance-fee-fraud",
        "ai-services",
        "android-malware",
        "anti-analysis",
        "apk-distribution",
        "apk-malware",
        "asset-theft",
        "automated-scan",
        "binance-impersonation",
        "brand-impersonation",
        "brazil",
        "broken-page",
        "carding",
        "city-of-vancouver",
        "click-jacking",
        "cloud-run",
        "combosquatting",
        "community-report",
        "content-locker",
        "counterfeit-domain",
        "credential-harvesting",
        "cryptocurrency",
        "cryptocurrency-scam",
        "daily-threat-intel",
        "data-collection",
        "data-harvesting",
        "deceptive-content",
        "deceptive-domain",
        "deceptive-interface",
        "deceptive-lure",
        "deceptive-page",
        "deceptive-platform",
        "deceptive-practices",
        "deceptive-redirects",
        "deceptive-site",
        "deceptive-url",
        "deceptive-verification",
        "developer-tools-blocking",
        "domain-classification",
        "e-commerce-fraud",
        "earning-scheme",
        "esports-targeting",
        "etsy-impersonation",
        "evasion",
        "evasion-tactics",
        "fake-android-app",
        "fake-app",
        "fake-domain",
        "fake-giveaway",
        "fake-online-store",
        "fake-platform",
        "fake-rewards",
        "fake-verification",
        "file-sharing",
        "file-sharing-impersonation",
        "financial-fraud",
        "financial-harvesting",
        "financial-scam",
        "fiverr",
        "fiverr-impersonation",
        "flhsmv-impersonation",
        "fraudulent-activity",
        "fraudulent-platform",
        "fraudulent-scheme",
        "free-fire",
        "gambling",
        "gambling-promotion",
        "game-cheats",
        "get-paid-to-scheme",
        "google-impersonation",
        "government-impersonation",
        "high-risk-domain",
        "high-risk-tld",
        "information-gathering",
        "information-harvesting",
        "intrusive-ads",
        "investment-management",
        "investment-scam",
        "jadlog-impersonation",
        "low-reputation",
        "malicious-landing-page",
        "malicious-redirect",
        "malicious-redirection",
        "malvertising",
        "malware",
        "malware-distribution",
        "malware-download",
        "malware-hosting",
        "malware-potential",
        "mexc-impersonation",
        "misleading-domain",
        "mobile-spyware",
        "modified-apps",
        "nebula-x",
        "netlify-abuse",
        "new-domain",
        "newly-registered-domain",
        "obfuscation",
        "payment-information-harvesting",
        "payment-scam",
        "personal-data-collection",
        "personal-information-collection",
        "personal-information-harvesting",
        "pet-scam",
        "phishing",
        "phishing-page",
        "phishing-scam",
        "phishing-site",
        "phishing-technique",
        "pirated-software",
        "ponzi-scheme",
        "puppy-scam",
        "recruitment-scam",
        "redirect",
        "redirect-chain",
        "revanced-impersonation",
        "roblox",
        "roblox-impersonation",
        "scam",
        "scam-campaign",
        "scam-lure",
        "scam-site",
        "serviceontario",
        "session-token",
        "shopping-cart-scam",
        "signup-page",
        "signup-scam",
        "social-engineering",
        "spam-promotion",
        "spoofed-domain",
        "spotify",
        "steam",
        "survey-scam",
        "suspicious-retailer",
        "suspicious-service-model",
        "task-based-earning-scam",
        "task-based-scam",
        "task-scam",
        "third-party-download",
        "toll-scam",
        "typosquatting",
        "unofficial-sources",
        "unwanted-software",
        "url-redirection",
        "url-shortener",
        "urlert",
        "usdt-storage",
        "user-manipulation",
        "virtual-tasks",
        "wallet-harvesting",
        "x-twitter",
        "zip-download"
      ],
      "references": [
        "https://urlert.com/domain/738833.com",
        "https://urlert.com/domain/888-gpifc.vip",
        "https://urlert.com/domain/964235.help",
        "https://urlert.com/domain/9mod.cloud",
        "https://urlert.com/domain/ankergames.net",
        "https://urlert.com/domain/appinjects.com",
        "https://urlert.com/domain/asusnext.us",
        "https://urlert.com/domain/binance-ltd.vip",
        "https://urlert.com/domain/bnz-gov.cam",
        "https://urlert.com/domain/bucara.my.id",
        "https://urlert.com/domain/bunnyband.com",
        "https://urlert.com/domain/challengermode.network",
        "https://urlert.com/domain/clck.ru",
        "https://urlert.com/domain/cloudnext.pro",
        "https://urlert.com/domain/dattingrooms.com",
        "https://urlert.com/domain/discord-tracker.com",
        "https://urlert.com/domain/elricat.co.uk",
        "https://urlert.com/domain/f09poypkdea3.com",
        "https://urlert.com/domain/facebook.hk",
        "https://urlert.com/domain/gamenuv.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Financial Services",
        "Government",
        "Logistics / Supply Chain",
        "Media / Entertainment",
        "Retail / E-Commerce",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "urlert_intel",
        "id": "386175",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 35,
        "URL": 40,
        "hostname": 13
      },
      "indicator_count": 88,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 30,
      "modified_text": "17 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69c333aacf8fedcd36832138",
      "name": "URLert Daily Threat Intel \u2014 2026-03-25",
      "description": "URLert Daily Threat Intel \u2014 2026-03-25\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 79 | Indicators: 140\nConfirmed: 27 | Likely: 48 | Domain intel: 4\nTop threats: Phishing (66), Dropper (5), Unknown (4), Malware Hosting (3), C2 Infrastructure (1)\nDomains: 571084.xin, 9990.site, app.link, appwrite.network, arcworld.one, aviatorfine.com, beetrade.me, bit.ly, bonanza-gha.work, casajoys.com, compromisedblog.com, cryptor.plus, daily777ween666.co...\n\n79 unique threats producing 140 actionable indicators. Generated by URLert automated threat intelligence.",
      "modified": "2026-04-23T20:57:23.519000",
      "created": "2026-03-25T01:00:26.546000",
      "tags": [
        ".cc-tld",
        "abuse-platform",
        "adult-content",
        "adult-scam",
        "affiliate-marketing",
        "aggressive-popups",
        "anti-analysis",
        "ar24-impersonation",
        "automated-scan",
        "blackmail-tool",
        "bonanza-impersonation",
        "brand-impersonation",
        "burn-site",
        "california-dmv",
        "certificate-mismatch",
        "chile",
        "cnn-impersonation",
        "combosquatting",
        "command-and-control",
        "compromised-site",
        "copec",
        "copec-impersonation",
        "credential-harvesting",
        "credit-card-theft",
        "crypto-investment-scam",
        "crypto-scam",
        "cryptocurrency",
        "cryptocurrency-fraud",
        "cryptocurrency-scam",
        "daily-threat-intel",
        "data-collection",
        "data-exfiltration",
        "data-harvesting",
        "data-theft",
        "deceptive-claims",
        "deceptive-content",
        "deceptive-landing-page",
        "deceptive-marketing",
        "deceptive-practices",
        "deceptive-reward-site",
        "deceptive-rewards",
        "deceptive-site",
        "deceptive-social-viewer",
        "deceptive-tactics",
        "digital-currency-theft",
        "dmv-impersonation",
        "document-sharing-impersonation",
        "domain-classification",
        "domain-rotation",
        "drive-by-download",
        "e-commerce-scam",
        "email-phishing",
        "evasion",
        "exit-scam",
        "facebook-messenger",
        "fake-login",
        "fake-login-portal",
        "fake-offer",
        "fake-phone-number",
        "fake-retail",
        "fake-toll-charge",
        "fake-verification",
        "financial-data-harvesting",
        "financial-fraud",
        "financial-scam",
        "financial-services-impersonation",
        "forced-download",
        "forepaas",
        "forepaas-impersonation",
        "fraudulent-deposits",
        "fraudulent-investment",
        "fraudulent-store",
        "fraudulent-website",
        "gambling-promotion",
        "gambling-scam",
        "gambling-site",
        "game-resource-generator",
        "gibberish-domain",
        "gmail-impersonation",
        "government-impersonation",
        "high-risk-gambling",
        "high-risk-tld",
        "high-traffic",
        "impersonation",
        "instagram-impersonation",
        "investment-scam",
        "kyc-fraud",
        "lead-generation",
        "litellm-malware",
        "login-page",
        "low-reputation-domain",
        "malicious-download",
        "malicious-redirect",
        "malicious-redirection",
        "malicious-redirects",
        "malicious-site",
        "malicious-url",
        "malware-distribution",
        "malware-download",
        "malware-dropper",
        "mfa-harvesting",
        "microsoft",
        "microsoft-defender-flagged",
        "myprotein",
        "nebula-x",
        "new-domain",
        "newly-registered-domain",
        "no-customer-support",
        "obscure-site",
        "online-casino-scam",
        "package-delivery-scam",
        "payment-information-theft",
        "payment-scam",
        "personal-information-theft",
        "phishing",
        "phishing-campaign",
        "phishing-gateway",
        "phishing-site",
        "phone-number-harvesting",
        "pii-collection",
        "pirated-games",
        "pop-mart-impersonation",
        "price-scam",
        "privacy-risk",
        "privacy-violation",
        "quickbooks",
        "redirect",
        "redirect-chain",
        "redirect-cloaking",
        "redirect-service",
        "redirection",
        "redirector",
        "redirects",
        "reverb-impersonation",
        "risky-url",
        "rug-pull",
        "sars-impersonation",
        "scam",
        "social-engineering",
        "social-media-abuse",
        "social-media-campaign",
        "social-media-scam",
        "social-media-scams",
        "south-africa",
        "spam-distribution",
        "spotify-impersonation",
        "streaming-service-scam",
        "subscription-scam",
        "supply-chain-attack",
        "support-scam",
        "surveillance",
        "suspicious-domain",
        "taplink-abuse",
        "task-scam",
        "tencent-hosting",
        "third-party-data-sharing",
        "throwaway-domain",
        "tracking",
        "tracking-url",
        "typosquatting",
        "unaccountable-infrastructure",
        "unauthorized-software",
        "undelivered-goods",
        "unlicensed-gambling",
        "unrealistic-pricing",
        "unreleased-products",
        "unsecured-file-sharing",
        "unwanted-software",
        "url-cloaking",
        "url-shortener",
        "urlert",
        "usdt",
        "usdt-scam",
        "user-manipulation",
        "vpn-impersonation",
        "webcam-capture",
        "webcam-tracking",
        "weebly-abuse",
        "xvideos-impersonation",
        "zero-day-registration"
      ],
      "references": [
        "https://urlert.com/domain/571084.xin",
        "https://urlert.com/domain/9990.site",
        "https://urlert.com/domain/app.link",
        "https://urlert.com/domain/appwrite.network",
        "https://urlert.com/domain/arcworld.one",
        "https://urlert.com/domain/aviatorfine.com",
        "https://urlert.com/domain/beetrade.me",
        "https://urlert.com/domain/bit.ly",
        "https://urlert.com/domain/bonanza-gha.work",
        "https://urlert.com/domain/casajoys.com",
        "https://urlert.com/domain/compromisedblog.com",
        "https://urlert.com/domain/cryptor.plus",
        "https://urlert.com/domain/daily777ween666.com",
        "https://urlert.com/domain/dpoiq.life",
        "https://urlert.com/domain/e.vg",
        "https://urlert.com/domain/effectivegatecpm.com",
        "https://urlert.com/domain/explodely.com",
        "https://urlert.com/domain/extravagant-streaming.life",
        "https://urlert.com/domain/fedexredeliveryform.com",
        "https://urlert.com/domain/fgl.cc"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Energy",
        "Financial Services",
        "Government",
        "Logistics / Supply Chain",
        "Media / Entertainment",
        "Retail / E-Commerce",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "urlert_intel",
        "id": "386175",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 37,
        "hostname": 15,
        "URL": 36
      },
      "indicator_count": 88,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 31,
      "modified_text": "37 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69ae1bb0bd34b3f694765e2b",
      "name": "URLert Daily Threat Intel \u2014 2026-03-09",
      "description": "URLert Daily Threat Intel \u2014 2026-03-09\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 42 | Indicators: 73\nConfirmed: 13 | Likely: 26 | Domain intel: 2 | Manual: 1\nTop threats: Phishing (33), Unknown (3), Malvertising (2), Dropper (2), Exploit Kit (1)\nDomains: allegrolokalnie.pl, cloudstoragex.shop, codecarteinstant.com, donutstake.com, effectivegatecpm.com, feua.cn, firebaseapp.com, ftghnbjkolswedfrcvbnhgfdswazxcvbnmjkolmpqwasderftgbnvcza.net, ...\n\n42 unique threats producing 73 actionable indicators. Generated by URLert automated threat intelligence.",
      "modified": "2026-04-07T22:19:15.041000",
      "created": "2026-03-09T01:00:32.570000",
      "tags": [
        "adult-content-lure",
        "adult-dating-scam",
        "aggressive-advertising",
        "atacadao-impersonation",
        "automated-scan",
        "booking-com-impersonation",
        "brand-impersonation",
        "browser-manipulation",
        "bulletproof-hosting",
        "cacau-show",
        "cloaking",
        "combosquatting",
        "compromised-site",
        "concealed-threat",
        "content-piracy",
        "credential-harvesting",
        "credit-card-harvesting",
        "cryptocurrency-scam",
        "daily-threat-intel",
        "dating-scam",
        "debugger-evasion",
        "deceptive-access",
        "deceptive-buttons",
        "deceptive-content",
        "deceptive-landing-page",
        "deceptive-practices",
        "deceptive-redirects",
        "deceptive-site",
        "discount-lure",
        "domain-classification",
        "domain-squatting",
        "ebay-impersonation",
        "ecommerce-targeting",
        "evasive-maneuvers",
        "exploit-kit-landing-page",
        "fake-download",
        "fake-giveaway",
        "fake-payment-portal",
        "fake-prize-scam",
        "fake-product",
        "fake-shopping",
        "fake-verification",
        "financial-exploitation",
        "financial-fraud",
        "financial-scam",
        "financial-sector",
        "fraudulent-scheme",
        "fraudulent-store",
        "giveaway-scam",
        "google-impersonation",
        "greece",
        "high-risk-tld",
        "investment-scam",
        "liquidity-pool-scam",
        "malicious-app-distribution",
        "malicious-redirect",
        "malvertising",
        "malware-delivery",
        "manomano-impersonation",
        "manual-entry",
        "minecraft-community",
        "new-domain",
        "newly-registered-domain",
        "onlyfans-impersonation",
        "otp-harvesting",
        "phishing",
        "phishing-kit",
        "phishing-site",
        "pig-butchering-scam",
        "pii-harvesting",
        "predatory-content",
        "predatory-monetization",
        "prize-scam",
        "redirect-activity",
        "redirect-cloaking",
        "retail-e-commerce",
        "retail-scam",
        "roblox",
        "scam",
        "scam-site",
        "social-media-impersonation",
        "social-proof-scam",
        "subscription-scam",
        "survey-scam",
        "suspicious-traffic",
        "tambo-plus-impersonation",
        "telcel-impersonation",
        "traffic-redirection",
        "transaction-fraud",
        "typosquatting",
        "unofficial-domain",
        "unregulated-gambling",
        "unwanted-software",
        "url-shortener",
        "urlert",
        "usdt-scam",
        "wallet-scam"
      ],
      "references": [
        "https://urlert.com/domain/allegrolokalnie.pl",
        "https://urlert.com/domain/cloudstoragex.shop",
        "https://urlert.com/domain/codecarteinstant.com",
        "https://urlert.com/domain/donutstake.com",
        "https://urlert.com/domain/effectivegatecpm.com",
        "https://urlert.com/domain/feua.cn",
        "https://urlert.com/domain/firebaseapp.com",
        "https://urlert.com/domain/flirtcaster.com",
        "https://urlert.com/domain/ftghnbjkolswedfrcvbnhgfdswazxcvbnmjkolmpqwasderftgbnvcza.net",
        "https://urlert.com/domain/fyo.cc",
        "https://urlert.com/domain/harafbangroup.com.ng",
        "https://urlert.com/domain/homelyero.com",
        "https://urlert.com/domain/ieuj.cn",
        "https://urlert.com/domain/is.gd",
        "https://urlert.com/domain/j82k.site",
        "https://urlert.com/domain/kec.az",
        "https://urlert.com/domain/lawlovepqr.click",
        "https://urlert.com/domain/lfi9d.vip",
        "https://urlert.com/domain/me-ebay.com",
        "https://urlert.com/domain/minertech.co"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Financial Services",
        "Government",
        "Hospitality",
        "Media / Entertainment",
        "Retail / E-Commerce",
        "Technology",
        "Telecommunications"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "urlert_intel",
        "id": "386175",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 28,
        "URL": 26,
        "hostname": 4
      },
      "indicator_count": 58,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 30,
      "modified_text": "53 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69a8dd2e875873023f69baaf",
      "name": "URLert Daily Threat Intel \u2014 2026-03-05",
      "description": "URLert Daily Threat Intel \u2014 2026-03-05\n\nAutomated threat intelligence from URLert (https://urlert.com) \u2014 AI-powered URL and domain analysis.\n\nThreats: 71 | Indicators: 136\nConfirmed: 13 | Likely: 45 | Under review: 4 | Domain intel: 7 | Manual: 2\nTop threats: Phishing (52), Unknown (11), Malware Hosting (2), Dropper (2), Malvertising (2)\nDomains: 4download.net, 87870.cyou, africa.com, amourconnects.com, appspot.com, artbbs.al, benson-gmbh.top, blox.gifts, bluetickon-adslive.online, bridgestonemerchandise.com, budal05.xyz, crusaders...\n\n71 unique threats producing 136 actionable indicators. Generated by URLert automated threat intelligence.",
      "modified": "2026-04-03T19:50:47.596000",
      "created": "2026-03-05T01:32:25.962000",
      "tags": [
        "adult-content",
        "adult-content-lure",
        "adult-dating",
        "adult-forum",
        "adult-scam",
        "ai-generated-pornography",
        "ai-jailbreaking",
        "allstate",
        "apple-care",
        "auto-download",
        "automated-scan",
        "belgian-government",
        "blogspot",
        "brand-impersonation",
        "bridgestone-impersonation",
        "broken-links",
        "browser-extension-malware",
        "business-email-phishing",
        "cisco-impersonation",
        "combosquatting",
        "content-generation",
        "cracks-keygens",
        "credential-harvesting",
        "crypto-scam",
        "cryptocurrency",
        "cryptocurrency-scam",
        "csam",
        "daily-threat-intel",
        "dangerous-url",
        "data-collection",
        "data-harvesting-risk",
        "deceptive-buttons",
        "deceptive-consent",
        "deceptive-content",
        "deceptive-download",
        "deceptive-lure",
        "deceptive-page",
        "deceptive-practices",
        "deceptive-scheme",
        "deceptive-service",
        "deepfake-content",
        "device-information-collection",
        "domain-classification",
        "domain-rotation",
        "e-commerce-scam",
        "ecommerce-scam",
        "email-service-abuse",
        "extremist-content",
        "fake-giveaway",
        "fake-login",
        "fake-prize-scam",
        "fake-questionnaire",
        "fake-survey",
        "file-sharing",
        "financial-fraud",
        "financial-scam",
        "flipkart-impersonation",
        "fraud",
        "fraudulent-ecommerce",
        "fraudulent-service",
        "free-hosting",
        "gibberish-domain",
        "gore-content",
        "government-services",
        "graphic-content",
        "graphic-media",
        "hate-speech",
        "high-risk-tld",
        "illegal-activation",
        "illegal-content",
        "impersonation",
        "indicator",
        "indonesia",
        "information-harvesting",
        "insurance-phishing",
        "insurance-sector",
        "investigation-promoted",
        "investment-scam",
        "ip-access-scam",
        "italian-users",
        "jailbait",
        "leak-content-lure",
        "lidl-impersonation",
        "link-in-bio",
        "live-streaming-platform",
        "logistics",
        "logistics-phishing",
        "low-reputation",
        "malicious-domain",
        "malicious-redirect",
        "malvertising",
        "malware-bundling",
        "malware-distribution",
        "malware-hosting",
        "manipulative-lure",
        "manual-entry",
        "mastro-credit-union",
        "mateus-supermercados",
        "microsoft-365",
        "microsoft-sharepoint-impersonation",
        "mpesa",
        "nebula-x",
        "netflix",
        "new-domain",
        "newly-registered-domain",
        "nsfw-generation",
        "online-scam",
        "onlyfans-impersonation",
        "payload-delivery",
        "payment-harvesting",
        "payment-scam",
        "personal-information-collection",
        "personal-information-harvesting",
        "phishing",
        "phishing-attempt",
        "phishing-example",
        "phishing-kit",
        "phishing-page",
        "phishing-scam",
        "phishing-site",
        "pig-butchering-scam",
        "pii-harvesting",
        "pingo-doce",
        "pirate-streaming",
        "pirated-software",
        "pizza-hut-impersonation",
        "postal-service-impersonation",
        "potentially-malicious",
        "prize-scam",
        "public-platform-abuse",
        "random-domain",
        "recently-registered",
        "recently-registered-domain",
        "redirection",
        "redirector",
        "retail-sector",
        "retail-targeting",
        "roblox",
        "roblox-impersonation",
        "scam",
        "scam-related",
        "scam-site",
        "scanlations",
        "scareware",
        "seur",
        "sexually-suggestive-content",
        "shock-content",
        "social-engineering",
        "spam-distribution",
        "staples-impersonation",
        "subscription-scam",
        "supermetrics-impersonation",
        "survey-scam",
        "suspicious-domain",
        "suspicious-url",
        "suspicious-verification",
        "tech-support-scam",
        "teen-content",
        "telegram-redirection",
        "threat-scan",
        "threat-scan-evidence",
        "threat-scan-indicator",
        "traffic-redirection",
        "typo-squat",
        "typosquatting-domain",
        "uncensored-ai",
        "unclassified-threat",
        "unscanned-files",
        "unwanted-redirects",
        "unwanted-subscription",
        "unwanted-subscriptions",
        "url-redirection",
        "urlert",
        "user-reported",
        "watch-to-earn-scam",
        "webmail-phishing",
        "whatsapp-scam",
        "white-supremacist",
        "zoho-impersonation"
      ],
      "references": [
        "https://urlert.com/domain/4download.net",
        "https://urlert.com/domain/87870.cyou",
        "https://urlert.com/domain/africa.com",
        "https://urlert.com/domain/amourconnects.com",
        "https://urlert.com/domain/appspot.com",
        "https://urlert.com/domain/artbbs.al",
        "https://urlert.com/domain/benson-gmbh.top",
        "https://urlert.com/domain/blox.gifts",
        "https://urlert.com/domain/bluetickon-adslive.online",
        "https://urlert.com/domain/bridgestonemerchandise.com",
        "https://urlert.com/domain/budal05.xyz",
        "https://urlert.com/domain/campsite.bio",
        "https://urlert.com/domain/crusaders.gg",
        "https://urlert.com/domain/cudasvc.com",
        "https://urlert.com/domain/dftrx.web.id",
        "https://urlert.com/domain/eej.at",
        "https://urlert.com/domain/eibmw.com",
        "https://urlert.com/domain/facebook.com",
        "https://urlert.com/domain/fgl.cc",
        "https://urlert.com/domain/flipxu.cyou"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Automotive",
        "Financial Services",
        "Government",
        "Insurance",
        "Logistics / Supply Chain",
        "Media / Entertainment",
        "Retail / E-Commerce",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "urlert_intel",
        "id": "386175",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_386175/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 49,
        "URL": 43,
        "hostname": 15
      },
      "indicator_count": 107,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 29,
      "modified_text": "57 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "nowplaytoc.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "nowplaytoc.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780235686.7373085
}