{
  "type": "Domain",
  "indicator": "nyames.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/nyames.com",
    "alexa": "http://www.alexa.com/siteinfo/nyames.com",
    "indicator": "nyames.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3810173189,
      "indicator": "nyames.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 9,
      "pulses": [
        {
          "id": "69b2b76c9a490b69b6a085b3",
          "name": "Exodus/cellbrite clone by Q Vashti",
          "description": "",
          "modified": "2026-03-12T12:54:04.160000",
          "created": "2026-03-12T12:54:04.160000",
          "tags": [
            "ssl certificate",
            "network",
            "malware",
            "whois record",
            "contacted",
            "pegasus",
            "resolutions",
            "communicating",
            "sa victim",
            "assaulter",
            "quasar",
            "brian sabey",
            "go.sabey",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls https",
            "samples",
            "united",
            "aaaa",
            "status",
            "susp",
            "search",
            "passive dns",
            "urls",
            "domain",
            "creation date",
            "date",
            "next",
            "show",
            "domain related",
            "feeds ioc",
            "maltiverse",
            "analyze",
            "scan endpoints",
            "all octoseek",
            "url https",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "all search",
            "otx octoseek",
            "hostname",
            "pulse submit",
            "url analysis",
            "files",
            "china unknown",
            "as4134 chinanet",
            "unknown",
            "name servers",
            "showing",
            "namesilo",
            "domain name",
            "dynadot llc",
            "as8075",
            "script urls",
            "netherlands",
            "a domains",
            "capture",
            "asnone united",
            "record value",
            "expiration date",
            "entries",
            "cname",
            "tulach",
            "algorithm",
            "v3 serial",
            "number",
            "key algorithm",
            "key identifier",
            "subject key",
            "identifier",
            "x509v3 key",
            "usage",
            "x509v3 extended",
            "info",
            "first",
            "server",
            "available from",
            "iana id",
            "registrar abuse",
            "registrar url",
            "registrar whois",
            "abuse contact",
            "email",
            "registry domain",
            "code",
            "win32 exe",
            "ufed iphone",
            "cellebrite ufed",
            "setup",
            "tjprojmain",
            "ufed4pc",
            "win32 dll",
            "detections type",
            "name",
            "responder",
            "exodus",
            "android",
            "office open",
            "xml document",
            "cellebrite",
            "type name",
            "pdf cellebrite",
            "ufed release",
            "cellbrite",
            "privilege https",
            "targets sa",
            "survivor",
            "getprocaddress",
            "indicator",
            "prefetch8",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "file",
            "pattern match",
            "observed email",
            "path",
            "factory",
            "hybrid",
            "general",
            "model",
            "comspec",
            "click",
            "title",
            "page",
            "body doctype",
            "quoth",
            "raven",
            "gmt content",
            "type",
            "vary",
            "accept",
            "october",
            "december",
            "copy",
            "execution",
            "awful",
            "referrer",
            "april",
            "kimsuky",
            "malicious",
            "crypto",
            "startpage",
            "hacktool",
            "installer",
            "tofsee",
            "historical ssl",
            "threat roundup",
            "phishing",
            "utc submissions",
            "submitters",
            "csc corporate",
            "domains",
            "twitter",
            "dropbox",
            "incapsula",
            "summary iocs",
            "graph community",
            "registrarsafe",
            "gandi sas",
            "google llc",
            "amazon02",
            "google",
            "akamaias",
            "facebook",
            "service",
            "patch",
            "namecheapnet",
            "cloudflarenet",
            "amazonaes",
            "gmo internet",
            "apple",
            "tsara brashears",
            "keylogger"
          ],
          "references": [
            "https://tulach.cc/",
            "cellebrite.com | https://cellebrite.com/en/federal-government/",
            "https://www.pornhub.com/video/search?search=tsara+brashears",
            "https://twitter.com/PORNO_SEXYBABES",
            "hanmail.net",
            "114.114.114.114",
            "work.a-poster.info",
            "www-stage40.pornhub.com",
            "go.sabey.com",
            "sabey.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Exodus",
              "display_name": "Exodus",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "PWS:Win32/Raven",
              "display_name": "PWS:Win32/Raven",
              "target": "/malware/PWS:Win32/Raven"
            },
            {
              "id": "Kimsuky",
              "display_name": "Kimsuky",
              "target": null
            },
            {
              "id": "VirTool:Win32/Tofsee",
              "display_name": "VirTool:Win32/Tofsee",
              "target": "/malware/VirTool:Win32/Tofsee"
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1588",
              "name": "Obtain Capabilities",
              "display_name": "T1588 - Obtain Capabilities"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6916e098df39114161354b23",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4295,
            "FileHash-MD5": 322,
            "FileHash-SHA1": 296,
            "FileHash-SHA256": 3255,
            "domain": 2911,
            "hostname": 2894,
            "CVE": 2,
            "email": 9,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 13986,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 65,
          "modified_text": "80 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6952febb1dbcf05ee601f050",
          "name": "Pegasus Ongoing l Cellbrite | Exodus | Brian Sabey | HallRender | Tulach (1.29.24)",
          "description": "",
          "modified": "2025-12-29T22:20:43.238000",
          "created": "2025-12-29T22:20:43.238000",
          "tags": [
            "ssl certificate",
            "network",
            "malware",
            "whois record",
            "contacted",
            "pegasus",
            "resolutions",
            "communicating",
            "sa victim",
            "assaulter",
            "quasar",
            "brian sabey",
            "go.sabey",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls https",
            "samples",
            "united",
            "aaaa",
            "status",
            "susp",
            "search",
            "passive dns",
            "urls",
            "domain",
            "creation date",
            "date",
            "next",
            "show",
            "domain related",
            "feeds ioc",
            "maltiverse",
            "analyze",
            "scan endpoints",
            "all octoseek",
            "url https",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "all search",
            "otx octoseek",
            "hostname",
            "pulse submit",
            "url analysis",
            "files",
            "china unknown",
            "as4134 chinanet",
            "unknown",
            "name servers",
            "showing",
            "namesilo",
            "domain name",
            "dynadot llc",
            "as8075",
            "script urls",
            "netherlands",
            "a domains",
            "capture",
            "asnone united",
            "record value",
            "expiration date",
            "entries",
            "cname",
            "tulach",
            "algorithm",
            "v3 serial",
            "number",
            "key algorithm",
            "key identifier",
            "subject key",
            "identifier",
            "x509v3 key",
            "usage",
            "x509v3 extended",
            "info",
            "first",
            "server",
            "available from",
            "iana id",
            "registrar abuse",
            "registrar url",
            "registrar whois",
            "abuse contact",
            "email",
            "registry domain",
            "code",
            "win32 exe",
            "ufed iphone",
            "cellebrite ufed",
            "setup",
            "tjprojmain",
            "ufed4pc",
            "win32 dll",
            "detections type",
            "name",
            "responder",
            "exodus",
            "android",
            "office open",
            "xml document",
            "cellebrite",
            "type name",
            "pdf cellebrite",
            "ufed release",
            "cellbrite",
            "privilege https",
            "targets sa",
            "survivor",
            "getprocaddress",
            "indicator",
            "prefetch8",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "file",
            "pattern match",
            "observed email",
            "path",
            "factory",
            "hybrid",
            "general",
            "model",
            "comspec",
            "click",
            "title",
            "page",
            "body doctype",
            "quoth",
            "raven",
            "gmt content",
            "type",
            "vary",
            "accept",
            "october",
            "december",
            "copy",
            "execution",
            "awful",
            "referrer",
            "april",
            "kimsuky",
            "malicious",
            "crypto",
            "startpage",
            "hacktool",
            "installer",
            "tofsee",
            "historical ssl",
            "threat roundup",
            "phishing",
            "utc submissions",
            "submitters",
            "csc corporate",
            "domains",
            "twitter",
            "dropbox",
            "incapsula",
            "summary iocs",
            "graph community",
            "registrarsafe",
            "gandi sas",
            "google llc",
            "amazon02",
            "google",
            "akamaias",
            "facebook",
            "service",
            "patch",
            "namecheapnet",
            "cloudflarenet",
            "amazonaes",
            "gmo internet",
            "apple",
            "tsara brashears",
            "keylogger"
          ],
          "references": [
            "https://tulach.cc/",
            "cellebrite.com | https://cellebrite.com/en/federal-government/",
            "https://www.pornhub.com/video/search?search=tsara+brashears",
            "https://twitter.com/PORNO_SEXYBABES",
            "hanmail.net",
            "114.114.114.114",
            "work.a-poster.info",
            "www-stage40.pornhub.com",
            "go.sabey.com",
            "sabey.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Exodus",
              "display_name": "Exodus",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "PWS:Win32/Raven",
              "display_name": "PWS:Win32/Raven",
              "target": "/malware/PWS:Win32/Raven"
            },
            {
              "id": "Kimsuky",
              "display_name": "Kimsuky",
              "target": null
            },
            {
              "id": "VirTool:Win32/Tofsee",
              "display_name": "VirTool:Win32/Tofsee",
              "target": "/malware/VirTool:Win32/Tofsee"
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1588",
              "name": "Obtain Capabilities",
              "display_name": "T1588 - Obtain Capabilities"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65b80a20bbcd0eb305a740ec",
          "export_count": 40656,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4101,
            "FileHash-MD5": 322,
            "FileHash-SHA1": 296,
            "FileHash-SHA256": 3155,
            "domain": 2894,
            "hostname": 2847,
            "CVE": 2,
            "email": 9,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 13628,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 145,
          "modified_text": "152 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6916e098df39114161354b23",
          "name": "Exodus l Cellbrite \u2022 Pegasus | Brian Sabey | HallRender | Tulach ",
          "description": "",
          "modified": "2025-12-14T07:05:42.106000",
          "created": "2025-11-14T07:56:08.872000",
          "tags": [
            "ssl certificate",
            "network",
            "malware",
            "whois record",
            "contacted",
            "pegasus",
            "resolutions",
            "communicating",
            "sa victim",
            "assaulter",
            "quasar",
            "brian sabey",
            "go.sabey",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls https",
            "samples",
            "united",
            "aaaa",
            "status",
            "susp",
            "search",
            "passive dns",
            "urls",
            "domain",
            "creation date",
            "date",
            "next",
            "show",
            "domain related",
            "feeds ioc",
            "maltiverse",
            "analyze",
            "scan endpoints",
            "all octoseek",
            "url https",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "all search",
            "otx octoseek",
            "hostname",
            "pulse submit",
            "url analysis",
            "files",
            "china unknown",
            "as4134 chinanet",
            "unknown",
            "name servers",
            "showing",
            "namesilo",
            "domain name",
            "dynadot llc",
            "as8075",
            "script urls",
            "netherlands",
            "a domains",
            "capture",
            "asnone united",
            "record value",
            "expiration date",
            "entries",
            "cname",
            "tulach",
            "algorithm",
            "v3 serial",
            "number",
            "key algorithm",
            "key identifier",
            "subject key",
            "identifier",
            "x509v3 key",
            "usage",
            "x509v3 extended",
            "info",
            "first",
            "server",
            "available from",
            "iana id",
            "registrar abuse",
            "registrar url",
            "registrar whois",
            "abuse contact",
            "email",
            "registry domain",
            "code",
            "win32 exe",
            "ufed iphone",
            "cellebrite ufed",
            "setup",
            "tjprojmain",
            "ufed4pc",
            "win32 dll",
            "detections type",
            "name",
            "responder",
            "exodus",
            "android",
            "office open",
            "xml document",
            "cellebrite",
            "type name",
            "pdf cellebrite",
            "ufed release",
            "cellbrite",
            "privilege https",
            "targets sa",
            "survivor",
            "getprocaddress",
            "indicator",
            "prefetch8",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "file",
            "pattern match",
            "observed email",
            "path",
            "factory",
            "hybrid",
            "general",
            "model",
            "comspec",
            "click",
            "title",
            "page",
            "body doctype",
            "quoth",
            "raven",
            "gmt content",
            "type",
            "vary",
            "accept",
            "october",
            "december",
            "copy",
            "execution",
            "awful",
            "referrer",
            "april",
            "kimsuky",
            "malicious",
            "crypto",
            "startpage",
            "hacktool",
            "installer",
            "tofsee",
            "historical ssl",
            "threat roundup",
            "phishing",
            "utc submissions",
            "submitters",
            "csc corporate",
            "domains",
            "twitter",
            "dropbox",
            "incapsula",
            "summary iocs",
            "graph community",
            "registrarsafe",
            "gandi sas",
            "google llc",
            "amazon02",
            "google",
            "akamaias",
            "facebook",
            "service",
            "patch",
            "namecheapnet",
            "cloudflarenet",
            "amazonaes",
            "gmo internet",
            "apple",
            "tsara brashears",
            "keylogger"
          ],
          "references": [
            "https://tulach.cc/",
            "cellebrite.com | https://cellebrite.com/en/federal-government/",
            "https://www.pornhub.com/video/search?search=tsara+brashears",
            "https://twitter.com/PORNO_SEXYBABES",
            "hanmail.net",
            "114.114.114.114",
            "work.a-poster.info",
            "www-stage40.pornhub.com",
            "go.sabey.com",
            "sabey.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Exodus",
              "display_name": "Exodus",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "PWS:Win32/Raven",
              "display_name": "PWS:Win32/Raven",
              "target": "/malware/PWS:Win32/Raven"
            },
            {
              "id": "Kimsuky",
              "display_name": "Kimsuky",
              "target": null
            },
            {
              "id": "VirTool:Win32/Tofsee",
              "display_name": "VirTool:Win32/Tofsee",
              "target": "/malware/VirTool:Win32/Tofsee"
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1588",
              "name": "Obtain Capabilities",
              "display_name": "T1588 - Obtain Capabilities"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65a76c2901b34c79a681596d",
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4295,
            "FileHash-MD5": 322,
            "FileHash-SHA1": 296,
            "FileHash-SHA256": 3255,
            "domain": 2911,
            "hostname": 2894,
            "CVE": 2,
            "email": 9,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 13986,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "168 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65a76c2901b34c79a681596d",
          "name": "Exodus l Cellbrite | Brian Sabey | HallRender | Tulach",
          "description": "Brian Sabey of Hall Render Law firm is incredibly entrenched in spying on a single target. Having made contact,impersonal invitations to meet, filing a lawsuit dismissed by a judge , paying to silence SA victim and spending many years spying, destroying digital profile m libel, malvertizing is concerning. \nConsidering Brashears death threats, following ,  being approached and attempts on her personal safety is unwarranted. Brashears was the confirmed victim of life threatening SA. How does the Federal Government allow this? Found embedded in Brashears link that came from her iPhone.",
          "modified": "2024-02-16T05:03:15.321000",
          "created": "2024-01-17T05:56:57.948000",
          "tags": [
            "ssl certificate",
            "network",
            "malware",
            "whois record",
            "contacted",
            "pegasus",
            "resolutions",
            "communicating",
            "sa victim",
            "assaulter",
            "quasar",
            "brian sabey",
            "go.sabey",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls https",
            "samples",
            "united",
            "aaaa",
            "status",
            "susp",
            "search",
            "passive dns",
            "urls",
            "domain",
            "creation date",
            "date",
            "next",
            "show",
            "domain related",
            "feeds ioc",
            "maltiverse",
            "analyze",
            "scan endpoints",
            "all octoseek",
            "url https",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "all search",
            "otx octoseek",
            "hostname",
            "pulse submit",
            "url analysis",
            "files",
            "china unknown",
            "as4134 chinanet",
            "unknown",
            "name servers",
            "showing",
            "namesilo",
            "domain name",
            "dynadot llc",
            "as8075",
            "script urls",
            "netherlands",
            "a domains",
            "capture",
            "asnone united",
            "record value",
            "expiration date",
            "entries",
            "cname",
            "tulach",
            "algorithm",
            "v3 serial",
            "number",
            "key algorithm",
            "key identifier",
            "subject key",
            "identifier",
            "x509v3 key",
            "usage",
            "x509v3 extended",
            "info",
            "first",
            "server",
            "available from",
            "iana id",
            "registrar abuse",
            "registrar url",
            "registrar whois",
            "abuse contact",
            "email",
            "registry domain",
            "code",
            "win32 exe",
            "ufed iphone",
            "cellebrite ufed",
            "setup",
            "tjprojmain",
            "ufed4pc",
            "win32 dll",
            "detections type",
            "name",
            "responder",
            "exodus",
            "android",
            "office open",
            "xml document",
            "cellebrite",
            "type name",
            "pdf cellebrite",
            "ufed release",
            "cellbrite",
            "privilege https",
            "targets sa",
            "survivor",
            "getprocaddress",
            "indicator",
            "prefetch8",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "file",
            "pattern match",
            "observed email",
            "path",
            "factory",
            "hybrid",
            "general",
            "model",
            "comspec",
            "click",
            "title",
            "page",
            "body doctype",
            "quoth",
            "raven",
            "gmt content",
            "type",
            "vary",
            "accept",
            "october",
            "december",
            "copy",
            "execution",
            "awful",
            "referrer",
            "april",
            "kimsuky",
            "malicious",
            "crypto",
            "startpage",
            "hacktool",
            "installer",
            "tofsee",
            "historical ssl",
            "threat roundup",
            "phishing",
            "utc submissions",
            "submitters",
            "csc corporate",
            "domains",
            "twitter",
            "dropbox",
            "incapsula",
            "summary iocs",
            "graph community",
            "registrarsafe",
            "gandi sas",
            "google llc",
            "amazon02",
            "google",
            "akamaias",
            "facebook",
            "service",
            "patch",
            "namecheapnet",
            "cloudflarenet",
            "amazonaes",
            "gmo internet",
            "apple",
            "tsara brashears",
            "keylogger"
          ],
          "references": [
            "https://tulach.cc/",
            "cellebrite.com | https://cellebrite.com/en/federal-government/",
            "https://www.pornhub.com/video/search?search=tsara+brashears",
            "https://twitter.com/PORNO_SEXYBABES",
            "hanmail.net",
            "114.114.114.114",
            "work.a-poster.info",
            "www-stage40.pornhub.com",
            "go.sabey.com",
            "sabey.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Exodus",
              "display_name": "Exodus",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "PWS:Win32/Raven",
              "display_name": "PWS:Win32/Raven",
              "target": "/malware/PWS:Win32/Raven"
            },
            {
              "id": "Kimsuky",
              "display_name": "Kimsuky",
              "target": null
            },
            {
              "id": "VirTool:Win32/Tofsee",
              "display_name": "VirTool:Win32/Tofsee",
              "target": "/malware/VirTool:Win32/Tofsee"
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1588",
              "name": "Obtain Capabilities",
              "display_name": "T1588 - Obtain Capabilities"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4101,
            "FileHash-MD5": 322,
            "FileHash-SHA1": 296,
            "FileHash-SHA256": 3155,
            "domain": 2894,
            "hostname": 2847,
            "CVE": 2,
            "email": 9,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 13628,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "835 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65a77c6a22a236495c4548d6",
          "name": "PEGASUS | Exodus l Cellbrite | Brian Sabey | HallRender | Tulach",
          "description": "I'm unclear if the legitimatecy of use of Cellbrite considering Brashears was the attacked. Brashears has spoken with every authority on her own terms. Law enforcement 'you're not that important. You're not a suspect .' FBI -' Brashears victim of Identity theft case that lasted months. Alleged false reports removed.'  PI's - 'someone is abusing privilege' Was a SA advocate Non Profit. Awareness Saves & social media deleted by hackers",
          "modified": "2024-02-16T05:03:15.321000",
          "created": "2024-01-17T07:06:18.453000",
          "tags": [
            "ssl certificate",
            "network",
            "malware",
            "whois record",
            "contacted",
            "pegasus",
            "resolutions",
            "communicating",
            "sa victim",
            "assaulter",
            "quasar",
            "brian sabey",
            "go.sabey",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls https",
            "samples",
            "united",
            "aaaa",
            "status",
            "susp",
            "search",
            "passive dns",
            "urls",
            "domain",
            "creation date",
            "date",
            "next",
            "show",
            "domain related",
            "feeds ioc",
            "maltiverse",
            "analyze",
            "scan endpoints",
            "all octoseek",
            "url https",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "all search",
            "otx octoseek",
            "hostname",
            "pulse submit",
            "url analysis",
            "files",
            "china unknown",
            "as4134 chinanet",
            "unknown",
            "name servers",
            "showing",
            "namesilo",
            "domain name",
            "dynadot llc",
            "as8075",
            "script urls",
            "netherlands",
            "a domains",
            "capture",
            "asnone united",
            "record value",
            "expiration date",
            "entries",
            "cname",
            "tulach",
            "algorithm",
            "v3 serial",
            "number",
            "key algorithm",
            "key identifier",
            "subject key",
            "identifier",
            "x509v3 key",
            "usage",
            "x509v3 extended",
            "info",
            "first",
            "server",
            "available from",
            "iana id",
            "registrar abuse",
            "registrar url",
            "registrar whois",
            "abuse contact",
            "email",
            "registry domain",
            "code",
            "win32 exe",
            "ufed iphone",
            "cellebrite ufed",
            "setup",
            "tjprojmain",
            "ufed4pc",
            "win32 dll",
            "detections type",
            "name",
            "responder",
            "exodus",
            "android",
            "office open",
            "xml document",
            "cellebrite",
            "type name",
            "pdf cellebrite",
            "ufed release",
            "cellbrite",
            "privilege https",
            "targets sa",
            "survivor",
            "getprocaddress",
            "indicator",
            "prefetch8",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "file",
            "pattern match",
            "observed email",
            "path",
            "factory",
            "hybrid",
            "general",
            "model",
            "comspec",
            "click",
            "title",
            "page",
            "body doctype",
            "quoth",
            "raven",
            "gmt content",
            "type",
            "vary",
            "accept",
            "october",
            "december",
            "copy",
            "execution",
            "awful",
            "referrer",
            "april",
            "kimsuky",
            "malicious",
            "crypto",
            "startpage",
            "hacktool",
            "installer",
            "tofsee",
            "historical ssl",
            "threat roundup",
            "phishing",
            "utc submissions",
            "submitters",
            "csc corporate",
            "domains",
            "twitter",
            "dropbox",
            "incapsula",
            "summary iocs",
            "graph community",
            "registrarsafe",
            "gandi sas",
            "google llc",
            "amazon02",
            "google",
            "akamaias",
            "facebook",
            "service",
            "patch",
            "namecheapnet",
            "cloudflarenet",
            "amazonaes",
            "gmo internet",
            "remote",
            "malvertizing",
            "spying",
            "cyber stalking"
          ],
          "references": [
            "https://tulach.cc/",
            "go.sabey.com",
            "sabey.com",
            "cellebrite.com",
            "https://cellebrite.com/en/federal-government/  [Pegasus ck privilege collection]",
            "https://www.pornhub.com/video/search?search=tsara+brashears",
            "remote.aciscomputers.com",
            "https://track.toccha.com/978eb025-0a62-46fa-827c-d71aa0524818?zoneid=5939372&ua=high&subzone_id=3038557&set=social&country=SY&region=49&isp=syriatelmobiletelecom&useragent=Mozilla/5.0",
            "114.114.114.114 [Tulach]",
            "nr-data.net [Apple Private Data Collection]",
            "defenselawyernj.com",
            "attorney-marketing-specialists.com ?",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/image-recognition-and-searcher/id1450230225",
            "http://www.apple.com/appleca/AppleIncRootCertificate.cer",
            "http://flexlucky.com/isurvey/en/?devicemodel=iPhone&carrier=\u00aeion=Tbilisi&brand=Apple&browser=GoogleApp&prize=cur&u=track.bawiwia.com&isp=JSCGlobalErty&ts=29900ce7-726c-4c9f-b0c3-21ff2f859648&country=GE&click_id=wuo4jm6db011lufu2f8h138c&partner=5658402&skip=yes&frame={frame}&cost=0.010100&lang=en",
            "https://t.me/hermitspyware/24",
            "hyundai-smg.com | http://hyundai-smg.com/index.php?route=information/contact | http://hyundai-smg.com/index.php?route=information/contact",
            "https://imazing.com/guides/detect-pegasus-and-other-spyware-on-iphone",
            "http://watchhers.net/index.php [remote attackers | malware spreader]",
            "api-stage.pornhub.com",
            "newbrazzers.com [y8.com]",
            "www.videolan.org [info solutions]",
            "www2.blackbagtech.com [hidden users included]",
            "http://subtitles.rest7.com/subs/The.Expanse.S03E11.720p.HDTV.x264-KILLERS[eztv].mkv",
            "http://pegasus.diskel.co.uk/ [phishing]",
            "wapwon.live/category/tsara-brashears-assaulted-by-jeffrey-reimerAccept-Language",
            "fds.cellebrite.com",
            "http://www1.mychartahn.org/?tm=1&subid4=1671014887.0191400000&kw=Patient+Portal&KW1=Patient+Access+Network&KW2=Patient+Self+Check+In+System&KW3=Electronic+Health+Record+EHR+System&KW4=Patient+Appointment+Scheduling+System&KW5=Medical+Billing+System+Software&KW6=Patient+Financial+Assistance&searchbox=0&domainname=0&backfill=0",
            "healthcare.greatcall.com [fake call centers | PHI & PII info stealers]",
            "http://download.virtualbox.org/virtualbox/debian",
            "match.pegasus.isi.edu",
            "asp.net",
            "http://dropbox.com/ [ intrusions/ dropbox stealer]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Exodus",
              "display_name": "Exodus",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Sabey",
              "display_name": "Sabey",
              "target": null
            },
            {
              "id": "VirTool:Win32/Tofsee",
              "display_name": "VirTool:Win32/Tofsee",
              "target": "/malware/VirTool:Win32/Tofsee"
            },
            {
              "id": "Kimsuky",
              "display_name": "Kimsuky",
              "target": null
            },
            {
              "id": "PWS:Win32/Raven",
              "display_name": "PWS:Win32/Raven",
              "target": "/malware/PWS:Win32/Raven"
            },
            {
              "id": "Trojan:Win32/Comspec",
              "display_name": "Trojan:Win32/Comspec",
              "target": "/malware/Trojan:Win32/Comspec"
            },
            {
              "id": "HallRender",
              "display_name": "HallRender",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1588",
              "name": "Obtain Capabilities",
              "display_name": "T1588 - Obtain Capabilities"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1588.004",
              "name": "Digital Certificates",
              "display_name": "T1588.004 - Digital Certificates"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1546.015",
              "name": "Component Object Model Hijacking",
              "display_name": "T1546.015 - Component Object Model Hijacking"
            },
            {
              "id": "T1071.003",
              "name": "Mail Protocols",
              "display_name": "T1071.003 - Mail Protocols"
            }
          ],
          "industries": [
            "Individual",
            "Patient",
            "Healthcare",
            "Survivor"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4101,
            "FileHash-MD5": 322,
            "FileHash-SHA1": 296,
            "FileHash-SHA256": 3157,
            "domain": 2903,
            "hostname": 2847,
            "CVE": 2,
            "email": 9,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 13639,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "835 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65b80a20bbcd0eb305a740ec",
          "name": "Exodus l Cellbrite | Brian Sabey | HallRender | Tulach",
          "description": "",
          "modified": "2024-02-16T05:03:15.321000",
          "created": "2024-01-29T20:27:12.899000",
          "tags": [
            "ssl certificate",
            "network",
            "malware",
            "whois record",
            "contacted",
            "pegasus",
            "resolutions",
            "communicating",
            "sa victim",
            "assaulter",
            "quasar",
            "brian sabey",
            "go.sabey",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls https",
            "samples",
            "united",
            "aaaa",
            "status",
            "susp",
            "search",
            "passive dns",
            "urls",
            "domain",
            "creation date",
            "date",
            "next",
            "show",
            "domain related",
            "feeds ioc",
            "maltiverse",
            "analyze",
            "scan endpoints",
            "all octoseek",
            "url https",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "all search",
            "otx octoseek",
            "hostname",
            "pulse submit",
            "url analysis",
            "files",
            "china unknown",
            "as4134 chinanet",
            "unknown",
            "name servers",
            "showing",
            "namesilo",
            "domain name",
            "dynadot llc",
            "as8075",
            "script urls",
            "netherlands",
            "a domains",
            "capture",
            "asnone united",
            "record value",
            "expiration date",
            "entries",
            "cname",
            "tulach",
            "algorithm",
            "v3 serial",
            "number",
            "key algorithm",
            "key identifier",
            "subject key",
            "identifier",
            "x509v3 key",
            "usage",
            "x509v3 extended",
            "info",
            "first",
            "server",
            "available from",
            "iana id",
            "registrar abuse",
            "registrar url",
            "registrar whois",
            "abuse contact",
            "email",
            "registry domain",
            "code",
            "win32 exe",
            "ufed iphone",
            "cellebrite ufed",
            "setup",
            "tjprojmain",
            "ufed4pc",
            "win32 dll",
            "detections type",
            "name",
            "responder",
            "exodus",
            "android",
            "office open",
            "xml document",
            "cellebrite",
            "type name",
            "pdf cellebrite",
            "ufed release",
            "cellbrite",
            "privilege https",
            "targets sa",
            "survivor",
            "getprocaddress",
            "indicator",
            "prefetch8",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "file",
            "pattern match",
            "observed email",
            "path",
            "factory",
            "hybrid",
            "general",
            "model",
            "comspec",
            "click",
            "title",
            "page",
            "body doctype",
            "quoth",
            "raven",
            "gmt content",
            "type",
            "vary",
            "accept",
            "october",
            "december",
            "copy",
            "execution",
            "awful",
            "referrer",
            "april",
            "kimsuky",
            "malicious",
            "crypto",
            "startpage",
            "hacktool",
            "installer",
            "tofsee",
            "historical ssl",
            "threat roundup",
            "phishing",
            "utc submissions",
            "submitters",
            "csc corporate",
            "domains",
            "twitter",
            "dropbox",
            "incapsula",
            "summary iocs",
            "graph community",
            "registrarsafe",
            "gandi sas",
            "google llc",
            "amazon02",
            "google",
            "akamaias",
            "facebook",
            "service",
            "patch",
            "namecheapnet",
            "cloudflarenet",
            "amazonaes",
            "gmo internet",
            "apple",
            "tsara brashears",
            "keylogger"
          ],
          "references": [
            "https://tulach.cc/",
            "cellebrite.com | https://cellebrite.com/en/federal-government/",
            "https://www.pornhub.com/video/search?search=tsara+brashears",
            "https://twitter.com/PORNO_SEXYBABES",
            "hanmail.net",
            "114.114.114.114",
            "work.a-poster.info",
            "www-stage40.pornhub.com",
            "go.sabey.com",
            "sabey.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Exodus",
              "display_name": "Exodus",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "PWS:Win32/Raven",
              "display_name": "PWS:Win32/Raven",
              "target": "/malware/PWS:Win32/Raven"
            },
            {
              "id": "Kimsuky",
              "display_name": "Kimsuky",
              "target": null
            },
            {
              "id": "VirTool:Win32/Tofsee",
              "display_name": "VirTool:Win32/Tofsee",
              "target": "/malware/VirTool:Win32/Tofsee"
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1588",
              "name": "Obtain Capabilities",
              "display_name": "T1588 - Obtain Capabilities"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65a76c2901b34c79a681596d",
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4101,
            "FileHash-MD5": 322,
            "FileHash-SHA1": 296,
            "FileHash-SHA256": 3155,
            "domain": 2894,
            "hostname": 2847,
            "CVE": 2,
            "email": 9,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 13628,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "835 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6583e3a2d1432cbf9054d26d",
          "name": "Qkbot | Reddit",
          "description": "Qbot URL:  https://seedbeej.pk/tin/index.php?QBOT.zip found in Reddit Honeypot link: https://www.reddit.com/user\nbackdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork  with many capabilities, attack methods and demands.  An unsuspecting victim  always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware, malvertizing, fraud services, full control of badly compromised digital profiles which have been discovered.",
          "modified": "2024-01-20T02:02:19.559000",
          "created": "2023-12-21T07:05:06.936000",
          "tags": [
            "ssl certificate",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "threat",
            "paste",
            "blacklist https",
            "qakbot",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "ascii text",
            "pattern match",
            "file",
            "windows nt",
            "appdata",
            "indicator",
            "crlf line",
            "unicode text",
            "jpeg image",
            "mitre att",
            "hybrid",
            "general",
            "local",
            "error",
            "click",
            "strings",
            "microsoft",
            "threat analyzer",
            "urls https",
            "no data",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "heur",
            "malware site",
            "malicious site",
            "safe site",
            "malware",
            "html",
            "phishing site",
            "site top",
            "riskware",
            "unsafe",
            "artemis",
            "quasar rat",
            "downldr",
            "agent",
            "presenoker",
            "applicunwnt",
            "crack",
            "cve201711882",
            "win64",
            "iframe",
            "quasar",
            "trojanspy",
            "exit",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "traffic",
            "anonymizer",
            "brasil",
            "phishing three",
            "united",
            "phishing bank",
            "virustotal",
            "tech",
            "bank",
            "maltiverse",
            "hidelink",
            "samples",
            "spyware",
            "injector",
            "mon jan",
            "tld count",
            "wed dec",
            "download",
            "first",
            "team",
            "simda",
            "bambernek",
            "simda simda",
            "infy",
            "alexa",
            "gregory",
            "cyber threat",
            "phishing",
            "engineering",
            "covid19",
            "telefonica co",
            "malicious",
            "zbot",
            "zeus",
            "betabot",
            "suppobox",
            "citadel",
            "pony",
            "kraken",
            "redline stealer",
            "ransomware",
            "vawtrak",
            "athena",
            "neutrino",
            "alina",
            "andromeda",
            "dexter",
            "unknown",
            "keylogger",
            "hawkeye",
            "phase",
            "jackpos",
            "plasma",
            "spyeye",
            "spitmo",
            "slingshot",
            "ramnit",
            "emotet",
            "pykspa",
            "virut",
            "installcore",
            "dorkbot",
            "bondat",
            "union",
            "vskimmer",
            "xtrat",
            "solar",
            "grandcrab",
            "nymaim",
            "matsnu",
            "cutwail",
            "cobalt strike",
            "hydra",
            "tinba",
            "nsis",
            "memscan",
            "deepscan",
            "runescape",
            "backdoor",
            "reddit",
            "tulach"
          ],
          "references": [
            "https://seedbeej.pk/tin/index.php?QBOT.zip",
            "https://tulach.cc/ [phishing, exploits, malware spreader]",
            "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
            "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
            "198.54.115.46            [exploit_source]",
            "gadyniw.com          [command_and_control]",
            "gahyqah.com          [command_and_control]",
            "galyqaz.com            [command_and_control]",
            "lyvyxor.com             [command_and_control]",
            "puzylyp.com           [command_and_control]",
            "malicious.high.ml   [dropper]",
            "https://www.reddit.com/user"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Quasar",
              "display_name": "Quasar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Gregory",
              "display_name": "Gregory",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Matsnu",
              "display_name": "Matsnu",
              "target": null
            },
            {
              "id": "Vawtrak",
              "display_name": "Vawtrak",
              "target": null
            },
            {
              "id": "XRat",
              "display_name": "XRat",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "vSkimmer",
              "display_name": "vSkimmer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "SpyEye",
              "display_name": "SpyEye",
              "target": null
            },
            {
              "id": "Spitmo",
              "display_name": "Spitmo",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "DorkBot",
              "display_name": "DorkBot",
              "target": null
            },
            {
              "id": "Slingshot",
              "display_name": "Slingshot",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Plasma RAT",
              "display_name": "Plasma RAT",
              "target": null
            },
            {
              "id": "Neutrino",
              "display_name": "Neutrino",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "GrandCrab",
              "display_name": "GrandCrab",
              "target": null
            },
            {
              "id": "Andromeda",
              "display_name": "Andromeda",
              "target": null
            },
            {
              "id": "Alinaos",
              "display_name": "Alinaos",
              "target": null
            },
            {
              "id": "HawkEye",
              "display_name": "HawkEye",
              "target": null
            },
            {
              "id": "Kraken",
              "display_name": "Kraken",
              "target": null
            },
            {
              "id": "Infy",
              "display_name": "Infy",
              "target": null
            },
            {
              "id": "Dexter",
              "display_name": "Dexter",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "ASCII",
              "display_name": "ASCII",
              "target": null
            },
            {
              "id": "Athena",
              "display_name": "Athena",
              "target": null
            },
            {
              "id": "Bambernek",
              "display_name": "Bambernek",
              "target": null
            },
            {
              "id": "BetaBot",
              "display_name": "BetaBot",
              "target": null
            },
            {
              "id": "COVID19",
              "display_name": "COVID19",
              "target": null
            },
            {
              "id": "Citadel",
              "display_name": "Citadel",
              "target": null
            },
            {
              "id": "Bondat",
              "display_name": "Bondat",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Hydra",
              "display_name": "Hydra",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 98,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8343,
            "FileHash-MD5": 953,
            "FileHash-SHA1": 489,
            "FileHash-SHA256": 3565,
            "domain": 1494,
            "hostname": 2218,
            "CVE": 6
          },
          "indicator_count": 17068,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "862 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6583e3acc7f464d48a3503d1",
          "name": "Qkbot | Reddit",
          "description": "Qbot URL:  https://seedbeej.pk/tin/index.php?QBOT.zip found in Reddit Honeypot link: https://www.reddit.com/user\nbackdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork  with many capabilities, attack methods and demands.  An unsuspecting victim  always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware, malvertizing, fraud services, full control of badly compromised digital profiles which have been discovered.",
          "modified": "2024-01-20T02:02:19.559000",
          "created": "2023-12-21T07:05:16.695000",
          "tags": [
            "ssl certificate",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "threat",
            "paste",
            "blacklist https",
            "qakbot",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "ascii text",
            "pattern match",
            "file",
            "windows nt",
            "appdata",
            "indicator",
            "crlf line",
            "unicode text",
            "jpeg image",
            "mitre att",
            "hybrid",
            "general",
            "local",
            "error",
            "click",
            "strings",
            "microsoft",
            "threat analyzer",
            "urls https",
            "no data",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "heur",
            "malware site",
            "malicious site",
            "safe site",
            "malware",
            "html",
            "phishing site",
            "site top",
            "riskware",
            "unsafe",
            "artemis",
            "quasar rat",
            "downldr",
            "agent",
            "presenoker",
            "applicunwnt",
            "crack",
            "cve201711882",
            "win64",
            "iframe",
            "quasar",
            "trojanspy",
            "exit",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "traffic",
            "anonymizer",
            "brasil",
            "phishing three",
            "united",
            "phishing bank",
            "virustotal",
            "tech",
            "bank",
            "maltiverse",
            "hidelink",
            "samples",
            "spyware",
            "injector",
            "mon jan",
            "tld count",
            "wed dec",
            "download",
            "first",
            "team",
            "simda",
            "bambernek",
            "simda simda",
            "infy",
            "alexa",
            "gregory",
            "cyber threat",
            "phishing",
            "engineering",
            "covid19",
            "telefonica co",
            "malicious",
            "zbot",
            "zeus",
            "betabot",
            "suppobox",
            "citadel",
            "pony",
            "kraken",
            "redline stealer",
            "ransomware",
            "vawtrak",
            "athena",
            "neutrino",
            "alina",
            "andromeda",
            "dexter",
            "unknown",
            "keylogger",
            "hawkeye",
            "phase",
            "jackpos",
            "plasma",
            "spyeye",
            "spitmo",
            "slingshot",
            "ramnit",
            "emotet",
            "pykspa",
            "virut",
            "installcore",
            "dorkbot",
            "bondat",
            "union",
            "vskimmer",
            "xtrat",
            "solar",
            "grandcrab",
            "nymaim",
            "matsnu",
            "cutwail",
            "cobalt strike",
            "hydra",
            "tinba",
            "nsis",
            "memscan",
            "deepscan",
            "runescape",
            "backdoor",
            "reddit",
            "tulach"
          ],
          "references": [
            "https://seedbeej.pk/tin/index.php?QBOT.zip",
            "https://tulach.cc/ [phishing, exploits, malware spreader]",
            "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
            "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
            "198.54.115.46            [exploit_source]",
            "gadyniw.com          [command_and_control]",
            "gahyqah.com          [command_and_control]",
            "galyqaz.com            [command_and_control]",
            "lyvyxor.com             [command_and_control]",
            "puzylyp.com           [command_and_control]",
            "malicious.high.ml   [dropper]",
            "https://www.reddit.com/user"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Quasar",
              "display_name": "Quasar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Gregory",
              "display_name": "Gregory",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Matsnu",
              "display_name": "Matsnu",
              "target": null
            },
            {
              "id": "Vawtrak",
              "display_name": "Vawtrak",
              "target": null
            },
            {
              "id": "XRat",
              "display_name": "XRat",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "vSkimmer",
              "display_name": "vSkimmer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "SpyEye",
              "display_name": "SpyEye",
              "target": null
            },
            {
              "id": "Spitmo",
              "display_name": "Spitmo",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "DorkBot",
              "display_name": "DorkBot",
              "target": null
            },
            {
              "id": "Slingshot",
              "display_name": "Slingshot",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Plasma RAT",
              "display_name": "Plasma RAT",
              "target": null
            },
            {
              "id": "Neutrino",
              "display_name": "Neutrino",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "GrandCrab",
              "display_name": "GrandCrab",
              "target": null
            },
            {
              "id": "Andromeda",
              "display_name": "Andromeda",
              "target": null
            },
            {
              "id": "Alinaos",
              "display_name": "Alinaos",
              "target": null
            },
            {
              "id": "HawkEye",
              "display_name": "HawkEye",
              "target": null
            },
            {
              "id": "Kraken",
              "display_name": "Kraken",
              "target": null
            },
            {
              "id": "Infy",
              "display_name": "Infy",
              "target": null
            },
            {
              "id": "Dexter",
              "display_name": "Dexter",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "ASCII",
              "display_name": "ASCII",
              "target": null
            },
            {
              "id": "Athena",
              "display_name": "Athena",
              "target": null
            },
            {
              "id": "Bambernek",
              "display_name": "Bambernek",
              "target": null
            },
            {
              "id": "BetaBot",
              "display_name": "BetaBot",
              "target": null
            },
            {
              "id": "COVID19",
              "display_name": "COVID19",
              "target": null
            },
            {
              "id": "Citadel",
              "display_name": "Citadel",
              "target": null
            },
            {
              "id": "Bondat",
              "display_name": "Bondat",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Hydra",
              "display_name": "Hydra",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 101,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8343,
            "FileHash-MD5": 953,
            "FileHash-SHA1": 489,
            "FileHash-SHA256": 3565,
            "domain": 1494,
            "hostname": 2218,
            "CVE": 6
          },
          "indicator_count": 17068,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "862 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "658449d3f6ec1af2f3aace46",
          "name": "Qakbot | Reddit",
          "description": "Qbot URL: https://seedbeej.pk/tin/index.php?QBOT.zip Qbot zip found in Reddit Honeypot link: https://www.reddit.com/user backdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork with many capabilities, attack methods and demands. An unsuspecting victim always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware  malvertizing, fraud services, leads to full control of badly compromised digital profile.",
          "modified": "2024-01-20T02:02:19.559000",
          "created": "2023-12-21T14:21:07.435000",
          "tags": [
            "ssl certificate",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "threat",
            "paste",
            "blacklist https",
            "qakbot",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "ascii text",
            "pattern match",
            "file",
            "windows nt",
            "appdata",
            "indicator",
            "crlf line",
            "unicode text",
            "jpeg image",
            "mitre att",
            "hybrid",
            "general",
            "local",
            "error",
            "click",
            "strings",
            "microsoft",
            "threat analyzer",
            "urls https",
            "no data",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "heur",
            "malware site",
            "malicious site",
            "safe site",
            "malware",
            "html",
            "phishing site",
            "site top",
            "riskware",
            "unsafe",
            "artemis",
            "quasar rat",
            "downldr",
            "agent",
            "presenoker",
            "applicunwnt",
            "crack",
            "cve201711882",
            "win64",
            "iframe",
            "quasar",
            "trojanspy",
            "exit",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "traffic",
            "anonymizer",
            "brasil",
            "phishing three",
            "united",
            "phishing bank",
            "virustotal",
            "tech",
            "bank",
            "maltiverse",
            "hidelink",
            "samples",
            "spyware",
            "injector",
            "mon jan",
            "tld count",
            "wed dec",
            "download",
            "first",
            "team",
            "simda",
            "bambernek",
            "simda simda",
            "infy",
            "alexa",
            "gregory",
            "cyber threat",
            "phishing",
            "engineering",
            "covid19",
            "telefonica co",
            "malicious",
            "zbot",
            "zeus",
            "betabot",
            "suppobox",
            "citadel",
            "pony",
            "kraken",
            "redline stealer",
            "ransomware",
            "vawtrak",
            "athena",
            "neutrino",
            "alina",
            "andromeda",
            "dexter",
            "unknown",
            "keylogger",
            "hawkeye",
            "phase",
            "jackpos",
            "plasma",
            "spyeye",
            "spitmo",
            "slingshot",
            "ramnit",
            "emotet",
            "pykspa",
            "virut",
            "installcore",
            "dorkbot",
            "bondat",
            "union",
            "vskimmer",
            "xtrat",
            "solar",
            "grandcrab",
            "nymaim",
            "matsnu",
            "cutwail",
            "cobalt strike",
            "hydra",
            "tinba",
            "nsis",
            "memscan",
            "deepscan",
            "runescape",
            "backdoor",
            "reddit",
            "tulach",
            "password stealer",
            "active threat",
            "apple",
            "pinkslipbot",
            "icloud",
            "free",
            "apple"
          ],
          "references": [
            "https://seedbeej.pk/tin/index.php?QBOT.zip.  [Qbot zip]",
            "https://tulach.cc/  [Botnet phishing]",
            "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
            "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
            "198.54.115.46            [exploit_source]",
            "gadyniw.com          [command_and_control]",
            "gahyqah.com          [command_and_control]",
            "galyqaz.com            [command_and_control]",
            "lyvyxor.com             [command_and_control]",
            "puzylyp.com           [command_and_control]",
            "malicious.high.ml   [dropper]",
            "https://www.reddit.com/user [honeypot]",
            "beacons.bcp.gvt.com   [tracking]",
            "https://www.norad.mil/   [tracking]",
            "www.norad.mil   [tracking]",
            "www.apple.com  [API property call]",
            "https://www.apple.com/qtactivex/qtplugin.cab   [https://www.icloud.com .cab]",
            "yesporn.fun",
            "http://114.114.114.114:90/p/cdbdd4a09a64909694281aec503746fd/mobile_index.html?MTE0LjExNC4xMTQuMTE0L2xvZ2luP2hhc19vcmlfdXJp [Tulach | Malicious]",
            "114.114.114.114  [Tulach | Virus Network IP]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Quasar",
              "display_name": "Quasar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Gregory",
              "display_name": "Gregory",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Matsnu",
              "display_name": "Matsnu",
              "target": null
            },
            {
              "id": "Vawtrak",
              "display_name": "Vawtrak",
              "target": null
            },
            {
              "id": "XRat",
              "display_name": "XRat",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "vSkimmer",
              "display_name": "vSkimmer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "SpyEye",
              "display_name": "SpyEye",
              "target": null
            },
            {
              "id": "Spitmo",
              "display_name": "Spitmo",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "DorkBot",
              "display_name": "DorkBot",
              "target": null
            },
            {
              "id": "Slingshot",
              "display_name": "Slingshot",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Plasma RAT",
              "display_name": "Plasma RAT",
              "target": null
            },
            {
              "id": "Neutrino",
              "display_name": "Neutrino",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "GrandCrab",
              "display_name": "GrandCrab",
              "target": null
            },
            {
              "id": "Andromeda",
              "display_name": "Andromeda",
              "target": null
            },
            {
              "id": "Alinaos",
              "display_name": "Alinaos",
              "target": null
            },
            {
              "id": "HawkEye",
              "display_name": "HawkEye",
              "target": null
            },
            {
              "id": "Kraken",
              "display_name": "Kraken",
              "target": null
            },
            {
              "id": "Infy",
              "display_name": "Infy",
              "target": null
            },
            {
              "id": "Dexter",
              "display_name": "Dexter",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "ASCII",
              "display_name": "ASCII",
              "target": null
            },
            {
              "id": "Athena",
              "display_name": "Athena",
              "target": null
            },
            {
              "id": "Bambernek",
              "display_name": "Bambernek",
              "target": null
            },
            {
              "id": "BetaBot",
              "display_name": "BetaBot",
              "target": null
            },
            {
              "id": "COVID19",
              "display_name": "COVID19",
              "target": null
            },
            {
              "id": "Citadel",
              "display_name": "Citadel",
              "target": null
            },
            {
              "id": "Bondat",
              "display_name": "Bondat",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Hydra",
              "display_name": "Hydra",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Pinkslipbot",
              "display_name": "Pinkslipbot",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 124,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8736,
            "FileHash-MD5": 953,
            "FileHash-SHA1": 489,
            "FileHash-SHA256": 3566,
            "domain": 1516,
            "hostname": 2221,
            "CVE": 6
          },
          "indicator_count": 17487,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "862 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "hanmail.net",
        "https://tulach.cc/ [phishing, exploits, malware spreader]",
        "malicious.high.ml   [dropper]",
        "sabey.com",
        "cellebrite.com",
        "fds.cellebrite.com",
        "http://download.virtualbox.org/virtualbox/debian",
        "asp.net",
        "http://dropbox.com/ [ intrusions/ dropbox stealer]",
        "lyvyxor.com             [command_and_control]",
        "remote.aciscomputers.com",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/image-recognition-and-searcher/id1450230225",
        "beacons.bcp.gvt.com   [tracking]",
        "198.54.115.46            [exploit_source]",
        "https://www.norad.mil/   [tracking]",
        "attorney-marketing-specialists.com ?",
        "http://flexlucky.com/isurvey/en/?devicemodel=iPhone&carrier=\u00aeion=Tbilisi&brand=Apple&browser=GoogleApp&prize=cur&u=track.bawiwia.com&isp=JSCGlobalErty&ts=29900ce7-726c-4c9f-b0c3-21ff2f859648&country=GE&click_id=wuo4jm6db011lufu2f8h138c&partner=5658402&skip=yes&frame={frame}&cost=0.010100&lang=en",
        "http://114.114.114.114:90/p/cdbdd4a09a64909694281aec503746fd/mobile_index.html?MTE0LjExNC4xMTQuMTE0L2xvZ2luP2hhc19vcmlfdXJp [Tulach | Malicious]",
        "cellebrite.com | https://cellebrite.com/en/federal-government/",
        "https://www.pornhub.com/video/search?search=tsara+brashears",
        "nr-data.net [Apple Private Data Collection]",
        "www.videolan.org [info solutions]",
        "match.pegasus.isi.edu",
        "gahyqah.com          [command_and_control]",
        "www.norad.mil   [tracking]",
        "work.a-poster.info",
        "https://www.apple.com/qtactivex/qtplugin.cab   [https://www.icloud.com .cab]",
        "healthcare.greatcall.com [fake call centers | PHI & PII info stealers]",
        "www2.blackbagtech.com [hidden users included]",
        "https://tulach.cc/  [Botnet phishing]",
        "https://seedbeej.pk/tin/index.php?QBOT.zip.  [Qbot zip]",
        "puzylyp.com           [command_and_control]",
        "www-stage40.pornhub.com",
        "go.sabey.com",
        "https://twitter.com/PORNO_SEXYBABES",
        "https://t.me/hermitspyware/24",
        "114.114.114.114 [Tulach]",
        "https://imazing.com/guides/detect-pegasus-and-other-spyware-on-iphone",
        "defenselawyernj.com",
        "http://pegasus.diskel.co.uk/ [phishing]",
        "www.apple.com  [API property call]",
        "114.114.114.114  [Tulach | Virus Network IP]",
        "http://watchhers.net/index.php [remote attackers | malware spreader]",
        "http://www1.mychartahn.org/?tm=1&subid4=1671014887.0191400000&kw=Patient+Portal&KW1=Patient+Access+Network&KW2=Patient+Self+Check+In+System&KW3=Electronic+Health+Record+EHR+System&KW4=Patient+Appointment+Scheduling+System&KW5=Medical+Billing+System+Software&KW6=Patient+Financial+Assistance&searchbox=0&domainname=0&backfill=0",
        "http://www.apple.com/appleca/AppleIncRootCertificate.cer",
        "api-stage.pornhub.com",
        "http://subtitles.rest7.com/subs/The.Expanse.S03E11.720p.HDTV.x264-KILLERS[eztv].mkv",
        "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
        "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
        "yesporn.fun",
        "114.114.114.114",
        "https://seedbeej.pk/tin/index.php?QBOT.zip",
        "hyundai-smg.com | http://hyundai-smg.com/index.php?route=information/contact | http://hyundai-smg.com/index.php?route=information/contact",
        "https://www.reddit.com/user [honeypot]",
        "gadyniw.com          [command_and_control]",
        "https://track.toccha.com/978eb025-0a62-46fa-827c-d71aa0524818?zoneid=5939372&ua=high&subzone_id=3038557&set=social&country=SY&region=49&isp=syriatelmobiletelecom&useragent=Mozilla/5.0",
        "galyqaz.com            [command_and_control]",
        "https://cellebrite.com/en/federal-government/  [Pegasus ck privilege collection]",
        "https://www.reddit.com/user",
        "https://tulach.cc/",
        "wapwon.live/category/tsara-brashears-assaulted-by-jeffrey-reimerAccept-Language",
        "newbrazzers.com [y8.com]"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Slingshot",
            "Tulach",
            "Kraken",
            "Installcore",
            "Vskimmer",
            "Trojanspy",
            "Cutwail",
            "Neutrino",
            "Athena",
            "Sabey",
            "Hacktool",
            "Zbot",
            "Spitmo",
            "Redline stealer",
            "Citadel",
            "Pykspa",
            "Virut",
            "Andromeda",
            "Dorkbot",
            "Betabot",
            "Kimsuky",
            "Hawkeye",
            "Ascii",
            "Pws:win32/raven",
            "Bondat",
            "Spyeye",
            "Quasar",
            "Quasar rat",
            "Zeus",
            "Virtool:win32/tofsee",
            "Nsis",
            "Grandcrab",
            "Qakbot",
            "Pony",
            "Nymaim",
            "Covid19",
            "Emotet",
            "Trojan:win32/comspec",
            "Ramnit",
            "Hydra",
            "Hallrender",
            "Exodus",
            "Vawtrak",
            "Suppobox",
            "Solar",
            "Xrat",
            "Infy",
            "Bambernek",
            "Pinkslipbot",
            "Matsnu",
            "Maltiverse",
            "Simda",
            "Plasma rat",
            "Alinaos",
            "Artemis",
            "Gregory",
            "Dexter",
            "Hidelink"
          ],
          "industries": [
            "Patient",
            "Healthcare",
            "Survivor",
            "Individual"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 9,
  "pulses": [
    {
      "id": "69b2b76c9a490b69b6a085b3",
      "name": "Exodus/cellbrite clone by Q Vashti",
      "description": "",
      "modified": "2026-03-12T12:54:04.160000",
      "created": "2026-03-12T12:54:04.160000",
      "tags": [
        "ssl certificate",
        "network",
        "malware",
        "whois record",
        "contacted",
        "pegasus",
        "resolutions",
        "communicating",
        "sa victim",
        "assaulter",
        "quasar",
        "brian sabey",
        "go.sabey",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls https",
        "samples",
        "united",
        "aaaa",
        "status",
        "susp",
        "search",
        "passive dns",
        "urls",
        "domain",
        "creation date",
        "date",
        "next",
        "show",
        "domain related",
        "feeds ioc",
        "maltiverse",
        "analyze",
        "scan endpoints",
        "all octoseek",
        "url https",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "all search",
        "otx octoseek",
        "hostname",
        "pulse submit",
        "url analysis",
        "files",
        "china unknown",
        "as4134 chinanet",
        "unknown",
        "name servers",
        "showing",
        "namesilo",
        "domain name",
        "dynadot llc",
        "as8075",
        "script urls",
        "netherlands",
        "a domains",
        "capture",
        "asnone united",
        "record value",
        "expiration date",
        "entries",
        "cname",
        "tulach",
        "algorithm",
        "v3 serial",
        "number",
        "key algorithm",
        "key identifier",
        "subject key",
        "identifier",
        "x509v3 key",
        "usage",
        "x509v3 extended",
        "info",
        "first",
        "server",
        "available from",
        "iana id",
        "registrar abuse",
        "registrar url",
        "registrar whois",
        "abuse contact",
        "email",
        "registry domain",
        "code",
        "win32 exe",
        "ufed iphone",
        "cellebrite ufed",
        "setup",
        "tjprojmain",
        "ufed4pc",
        "win32 dll",
        "detections type",
        "name",
        "responder",
        "exodus",
        "android",
        "office open",
        "xml document",
        "cellebrite",
        "type name",
        "pdf cellebrite",
        "ufed release",
        "cellbrite",
        "privilege https",
        "targets sa",
        "survivor",
        "getprocaddress",
        "indicator",
        "prefetch8",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "file",
        "pattern match",
        "observed email",
        "path",
        "factory",
        "hybrid",
        "general",
        "model",
        "comspec",
        "click",
        "title",
        "page",
        "body doctype",
        "quoth",
        "raven",
        "gmt content",
        "type",
        "vary",
        "accept",
        "october",
        "december",
        "copy",
        "execution",
        "awful",
        "referrer",
        "april",
        "kimsuky",
        "malicious",
        "crypto",
        "startpage",
        "hacktool",
        "installer",
        "tofsee",
        "historical ssl",
        "threat roundup",
        "phishing",
        "utc submissions",
        "submitters",
        "csc corporate",
        "domains",
        "twitter",
        "dropbox",
        "incapsula",
        "summary iocs",
        "graph community",
        "registrarsafe",
        "gandi sas",
        "google llc",
        "amazon02",
        "google",
        "akamaias",
        "facebook",
        "service",
        "patch",
        "namecheapnet",
        "cloudflarenet",
        "amazonaes",
        "gmo internet",
        "apple",
        "tsara brashears",
        "keylogger"
      ],
      "references": [
        "https://tulach.cc/",
        "cellebrite.com | https://cellebrite.com/en/federal-government/",
        "https://www.pornhub.com/video/search?search=tsara+brashears",
        "https://twitter.com/PORNO_SEXYBABES",
        "hanmail.net",
        "114.114.114.114",
        "work.a-poster.info",
        "www-stage40.pornhub.com",
        "go.sabey.com",
        "sabey.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Exodus",
          "display_name": "Exodus",
          "target": null
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "PWS:Win32/Raven",
          "display_name": "PWS:Win32/Raven",
          "target": "/malware/PWS:Win32/Raven"
        },
        {
          "id": "Kimsuky",
          "display_name": "Kimsuky",
          "target": null
        },
        {
          "id": "VirTool:Win32/Tofsee",
          "display_name": "VirTool:Win32/Tofsee",
          "target": "/malware/VirTool:Win32/Tofsee"
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1588",
          "name": "Obtain Capabilities",
          "display_name": "T1588 - Obtain Capabilities"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "6916e098df39114161354b23",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4295,
        "FileHash-MD5": 322,
        "FileHash-SHA1": 296,
        "FileHash-SHA256": 3255,
        "domain": 2911,
        "hostname": 2894,
        "CVE": 2,
        "email": 9,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 13986,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 65,
      "modified_text": "80 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6952febb1dbcf05ee601f050",
      "name": "Pegasus Ongoing l Cellbrite | Exodus | Brian Sabey | HallRender | Tulach (1.29.24)",
      "description": "",
      "modified": "2025-12-29T22:20:43.238000",
      "created": "2025-12-29T22:20:43.238000",
      "tags": [
        "ssl certificate",
        "network",
        "malware",
        "whois record",
        "contacted",
        "pegasus",
        "resolutions",
        "communicating",
        "sa victim",
        "assaulter",
        "quasar",
        "brian sabey",
        "go.sabey",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls https",
        "samples",
        "united",
        "aaaa",
        "status",
        "susp",
        "search",
        "passive dns",
        "urls",
        "domain",
        "creation date",
        "date",
        "next",
        "show",
        "domain related",
        "feeds ioc",
        "maltiverse",
        "analyze",
        "scan endpoints",
        "all octoseek",
        "url https",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "all search",
        "otx octoseek",
        "hostname",
        "pulse submit",
        "url analysis",
        "files",
        "china unknown",
        "as4134 chinanet",
        "unknown",
        "name servers",
        "showing",
        "namesilo",
        "domain name",
        "dynadot llc",
        "as8075",
        "script urls",
        "netherlands",
        "a domains",
        "capture",
        "asnone united",
        "record value",
        "expiration date",
        "entries",
        "cname",
        "tulach",
        "algorithm",
        "v3 serial",
        "number",
        "key algorithm",
        "key identifier",
        "subject key",
        "identifier",
        "x509v3 key",
        "usage",
        "x509v3 extended",
        "info",
        "first",
        "server",
        "available from",
        "iana id",
        "registrar abuse",
        "registrar url",
        "registrar whois",
        "abuse contact",
        "email",
        "registry domain",
        "code",
        "win32 exe",
        "ufed iphone",
        "cellebrite ufed",
        "setup",
        "tjprojmain",
        "ufed4pc",
        "win32 dll",
        "detections type",
        "name",
        "responder",
        "exodus",
        "android",
        "office open",
        "xml document",
        "cellebrite",
        "type name",
        "pdf cellebrite",
        "ufed release",
        "cellbrite",
        "privilege https",
        "targets sa",
        "survivor",
        "getprocaddress",
        "indicator",
        "prefetch8",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "file",
        "pattern match",
        "observed email",
        "path",
        "factory",
        "hybrid",
        "general",
        "model",
        "comspec",
        "click",
        "title",
        "page",
        "body doctype",
        "quoth",
        "raven",
        "gmt content",
        "type",
        "vary",
        "accept",
        "october",
        "december",
        "copy",
        "execution",
        "awful",
        "referrer",
        "april",
        "kimsuky",
        "malicious",
        "crypto",
        "startpage",
        "hacktool",
        "installer",
        "tofsee",
        "historical ssl",
        "threat roundup",
        "phishing",
        "utc submissions",
        "submitters",
        "csc corporate",
        "domains",
        "twitter",
        "dropbox",
        "incapsula",
        "summary iocs",
        "graph community",
        "registrarsafe",
        "gandi sas",
        "google llc",
        "amazon02",
        "google",
        "akamaias",
        "facebook",
        "service",
        "patch",
        "namecheapnet",
        "cloudflarenet",
        "amazonaes",
        "gmo internet",
        "apple",
        "tsara brashears",
        "keylogger"
      ],
      "references": [
        "https://tulach.cc/",
        "cellebrite.com | https://cellebrite.com/en/federal-government/",
        "https://www.pornhub.com/video/search?search=tsara+brashears",
        "https://twitter.com/PORNO_SEXYBABES",
        "hanmail.net",
        "114.114.114.114",
        "work.a-poster.info",
        "www-stage40.pornhub.com",
        "go.sabey.com",
        "sabey.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Exodus",
          "display_name": "Exodus",
          "target": null
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "PWS:Win32/Raven",
          "display_name": "PWS:Win32/Raven",
          "target": "/malware/PWS:Win32/Raven"
        },
        {
          "id": "Kimsuky",
          "display_name": "Kimsuky",
          "target": null
        },
        {
          "id": "VirTool:Win32/Tofsee",
          "display_name": "VirTool:Win32/Tofsee",
          "target": "/malware/VirTool:Win32/Tofsee"
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1588",
          "name": "Obtain Capabilities",
          "display_name": "T1588 - Obtain Capabilities"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65b80a20bbcd0eb305a740ec",
      "export_count": 40656,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4101,
        "FileHash-MD5": 322,
        "FileHash-SHA1": 296,
        "FileHash-SHA256": 3155,
        "domain": 2894,
        "hostname": 2847,
        "CVE": 2,
        "email": 9,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 13628,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 145,
      "modified_text": "152 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6916e098df39114161354b23",
      "name": "Exodus l Cellbrite \u2022 Pegasus | Brian Sabey | HallRender | Tulach ",
      "description": "",
      "modified": "2025-12-14T07:05:42.106000",
      "created": "2025-11-14T07:56:08.872000",
      "tags": [
        "ssl certificate",
        "network",
        "malware",
        "whois record",
        "contacted",
        "pegasus",
        "resolutions",
        "communicating",
        "sa victim",
        "assaulter",
        "quasar",
        "brian sabey",
        "go.sabey",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls https",
        "samples",
        "united",
        "aaaa",
        "status",
        "susp",
        "search",
        "passive dns",
        "urls",
        "domain",
        "creation date",
        "date",
        "next",
        "show",
        "domain related",
        "feeds ioc",
        "maltiverse",
        "analyze",
        "scan endpoints",
        "all octoseek",
        "url https",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "all search",
        "otx octoseek",
        "hostname",
        "pulse submit",
        "url analysis",
        "files",
        "china unknown",
        "as4134 chinanet",
        "unknown",
        "name servers",
        "showing",
        "namesilo",
        "domain name",
        "dynadot llc",
        "as8075",
        "script urls",
        "netherlands",
        "a domains",
        "capture",
        "asnone united",
        "record value",
        "expiration date",
        "entries",
        "cname",
        "tulach",
        "algorithm",
        "v3 serial",
        "number",
        "key algorithm",
        "key identifier",
        "subject key",
        "identifier",
        "x509v3 key",
        "usage",
        "x509v3 extended",
        "info",
        "first",
        "server",
        "available from",
        "iana id",
        "registrar abuse",
        "registrar url",
        "registrar whois",
        "abuse contact",
        "email",
        "registry domain",
        "code",
        "win32 exe",
        "ufed iphone",
        "cellebrite ufed",
        "setup",
        "tjprojmain",
        "ufed4pc",
        "win32 dll",
        "detections type",
        "name",
        "responder",
        "exodus",
        "android",
        "office open",
        "xml document",
        "cellebrite",
        "type name",
        "pdf cellebrite",
        "ufed release",
        "cellbrite",
        "privilege https",
        "targets sa",
        "survivor",
        "getprocaddress",
        "indicator",
        "prefetch8",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "file",
        "pattern match",
        "observed email",
        "path",
        "factory",
        "hybrid",
        "general",
        "model",
        "comspec",
        "click",
        "title",
        "page",
        "body doctype",
        "quoth",
        "raven",
        "gmt content",
        "type",
        "vary",
        "accept",
        "october",
        "december",
        "copy",
        "execution",
        "awful",
        "referrer",
        "april",
        "kimsuky",
        "malicious",
        "crypto",
        "startpage",
        "hacktool",
        "installer",
        "tofsee",
        "historical ssl",
        "threat roundup",
        "phishing",
        "utc submissions",
        "submitters",
        "csc corporate",
        "domains",
        "twitter",
        "dropbox",
        "incapsula",
        "summary iocs",
        "graph community",
        "registrarsafe",
        "gandi sas",
        "google llc",
        "amazon02",
        "google",
        "akamaias",
        "facebook",
        "service",
        "patch",
        "namecheapnet",
        "cloudflarenet",
        "amazonaes",
        "gmo internet",
        "apple",
        "tsara brashears",
        "keylogger"
      ],
      "references": [
        "https://tulach.cc/",
        "cellebrite.com | https://cellebrite.com/en/federal-government/",
        "https://www.pornhub.com/video/search?search=tsara+brashears",
        "https://twitter.com/PORNO_SEXYBABES",
        "hanmail.net",
        "114.114.114.114",
        "work.a-poster.info",
        "www-stage40.pornhub.com",
        "go.sabey.com",
        "sabey.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Exodus",
          "display_name": "Exodus",
          "target": null
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "PWS:Win32/Raven",
          "display_name": "PWS:Win32/Raven",
          "target": "/malware/PWS:Win32/Raven"
        },
        {
          "id": "Kimsuky",
          "display_name": "Kimsuky",
          "target": null
        },
        {
          "id": "VirTool:Win32/Tofsee",
          "display_name": "VirTool:Win32/Tofsee",
          "target": "/malware/VirTool:Win32/Tofsee"
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1588",
          "name": "Obtain Capabilities",
          "display_name": "T1588 - Obtain Capabilities"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65a76c2901b34c79a681596d",
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4295,
        "FileHash-MD5": 322,
        "FileHash-SHA1": 296,
        "FileHash-SHA256": 3255,
        "domain": 2911,
        "hostname": 2894,
        "CVE": 2,
        "email": 9,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 13986,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "168 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65a76c2901b34c79a681596d",
      "name": "Exodus l Cellbrite | Brian Sabey | HallRender | Tulach",
      "description": "Brian Sabey of Hall Render Law firm is incredibly entrenched in spying on a single target. Having made contact,impersonal invitations to meet, filing a lawsuit dismissed by a judge , paying to silence SA victim and spending many years spying, destroying digital profile m libel, malvertizing is concerning. \nConsidering Brashears death threats, following ,  being approached and attempts on her personal safety is unwarranted. Brashears was the confirmed victim of life threatening SA. How does the Federal Government allow this? Found embedded in Brashears link that came from her iPhone.",
      "modified": "2024-02-16T05:03:15.321000",
      "created": "2024-01-17T05:56:57.948000",
      "tags": [
        "ssl certificate",
        "network",
        "malware",
        "whois record",
        "contacted",
        "pegasus",
        "resolutions",
        "communicating",
        "sa victim",
        "assaulter",
        "quasar",
        "brian sabey",
        "go.sabey",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls https",
        "samples",
        "united",
        "aaaa",
        "status",
        "susp",
        "search",
        "passive dns",
        "urls",
        "domain",
        "creation date",
        "date",
        "next",
        "show",
        "domain related",
        "feeds ioc",
        "maltiverse",
        "analyze",
        "scan endpoints",
        "all octoseek",
        "url https",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "all search",
        "otx octoseek",
        "hostname",
        "pulse submit",
        "url analysis",
        "files",
        "china unknown",
        "as4134 chinanet",
        "unknown",
        "name servers",
        "showing",
        "namesilo",
        "domain name",
        "dynadot llc",
        "as8075",
        "script urls",
        "netherlands",
        "a domains",
        "capture",
        "asnone united",
        "record value",
        "expiration date",
        "entries",
        "cname",
        "tulach",
        "algorithm",
        "v3 serial",
        "number",
        "key algorithm",
        "key identifier",
        "subject key",
        "identifier",
        "x509v3 key",
        "usage",
        "x509v3 extended",
        "info",
        "first",
        "server",
        "available from",
        "iana id",
        "registrar abuse",
        "registrar url",
        "registrar whois",
        "abuse contact",
        "email",
        "registry domain",
        "code",
        "win32 exe",
        "ufed iphone",
        "cellebrite ufed",
        "setup",
        "tjprojmain",
        "ufed4pc",
        "win32 dll",
        "detections type",
        "name",
        "responder",
        "exodus",
        "android",
        "office open",
        "xml document",
        "cellebrite",
        "type name",
        "pdf cellebrite",
        "ufed release",
        "cellbrite",
        "privilege https",
        "targets sa",
        "survivor",
        "getprocaddress",
        "indicator",
        "prefetch8",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "file",
        "pattern match",
        "observed email",
        "path",
        "factory",
        "hybrid",
        "general",
        "model",
        "comspec",
        "click",
        "title",
        "page",
        "body doctype",
        "quoth",
        "raven",
        "gmt content",
        "type",
        "vary",
        "accept",
        "october",
        "december",
        "copy",
        "execution",
        "awful",
        "referrer",
        "april",
        "kimsuky",
        "malicious",
        "crypto",
        "startpage",
        "hacktool",
        "installer",
        "tofsee",
        "historical ssl",
        "threat roundup",
        "phishing",
        "utc submissions",
        "submitters",
        "csc corporate",
        "domains",
        "twitter",
        "dropbox",
        "incapsula",
        "summary iocs",
        "graph community",
        "registrarsafe",
        "gandi sas",
        "google llc",
        "amazon02",
        "google",
        "akamaias",
        "facebook",
        "service",
        "patch",
        "namecheapnet",
        "cloudflarenet",
        "amazonaes",
        "gmo internet",
        "apple",
        "tsara brashears",
        "keylogger"
      ],
      "references": [
        "https://tulach.cc/",
        "cellebrite.com | https://cellebrite.com/en/federal-government/",
        "https://www.pornhub.com/video/search?search=tsara+brashears",
        "https://twitter.com/PORNO_SEXYBABES",
        "hanmail.net",
        "114.114.114.114",
        "work.a-poster.info",
        "www-stage40.pornhub.com",
        "go.sabey.com",
        "sabey.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Exodus",
          "display_name": "Exodus",
          "target": null
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "PWS:Win32/Raven",
          "display_name": "PWS:Win32/Raven",
          "target": "/malware/PWS:Win32/Raven"
        },
        {
          "id": "Kimsuky",
          "display_name": "Kimsuky",
          "target": null
        },
        {
          "id": "VirTool:Win32/Tofsee",
          "display_name": "VirTool:Win32/Tofsee",
          "target": "/malware/VirTool:Win32/Tofsee"
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1588",
          "name": "Obtain Capabilities",
          "display_name": "T1588 - Obtain Capabilities"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4101,
        "FileHash-MD5": 322,
        "FileHash-SHA1": 296,
        "FileHash-SHA256": 3155,
        "domain": 2894,
        "hostname": 2847,
        "CVE": 2,
        "email": 9,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 13628,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "835 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65a77c6a22a236495c4548d6",
      "name": "PEGASUS | Exodus l Cellbrite | Brian Sabey | HallRender | Tulach",
      "description": "I'm unclear if the legitimatecy of use of Cellbrite considering Brashears was the attacked. Brashears has spoken with every authority on her own terms. Law enforcement 'you're not that important. You're not a suspect .' FBI -' Brashears victim of Identity theft case that lasted months. Alleged false reports removed.'  PI's - 'someone is abusing privilege' Was a SA advocate Non Profit. Awareness Saves & social media deleted by hackers",
      "modified": "2024-02-16T05:03:15.321000",
      "created": "2024-01-17T07:06:18.453000",
      "tags": [
        "ssl certificate",
        "network",
        "malware",
        "whois record",
        "contacted",
        "pegasus",
        "resolutions",
        "communicating",
        "sa victim",
        "assaulter",
        "quasar",
        "brian sabey",
        "go.sabey",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls https",
        "samples",
        "united",
        "aaaa",
        "status",
        "susp",
        "search",
        "passive dns",
        "urls",
        "domain",
        "creation date",
        "date",
        "next",
        "show",
        "domain related",
        "feeds ioc",
        "maltiverse",
        "analyze",
        "scan endpoints",
        "all octoseek",
        "url https",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "all search",
        "otx octoseek",
        "hostname",
        "pulse submit",
        "url analysis",
        "files",
        "china unknown",
        "as4134 chinanet",
        "unknown",
        "name servers",
        "showing",
        "namesilo",
        "domain name",
        "dynadot llc",
        "as8075",
        "script urls",
        "netherlands",
        "a domains",
        "capture",
        "asnone united",
        "record value",
        "expiration date",
        "entries",
        "cname",
        "tulach",
        "algorithm",
        "v3 serial",
        "number",
        "key algorithm",
        "key identifier",
        "subject key",
        "identifier",
        "x509v3 key",
        "usage",
        "x509v3 extended",
        "info",
        "first",
        "server",
        "available from",
        "iana id",
        "registrar abuse",
        "registrar url",
        "registrar whois",
        "abuse contact",
        "email",
        "registry domain",
        "code",
        "win32 exe",
        "ufed iphone",
        "cellebrite ufed",
        "setup",
        "tjprojmain",
        "ufed4pc",
        "win32 dll",
        "detections type",
        "name",
        "responder",
        "exodus",
        "android",
        "office open",
        "xml document",
        "cellebrite",
        "type name",
        "pdf cellebrite",
        "ufed release",
        "cellbrite",
        "privilege https",
        "targets sa",
        "survivor",
        "getprocaddress",
        "indicator",
        "prefetch8",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "file",
        "pattern match",
        "observed email",
        "path",
        "factory",
        "hybrid",
        "general",
        "model",
        "comspec",
        "click",
        "title",
        "page",
        "body doctype",
        "quoth",
        "raven",
        "gmt content",
        "type",
        "vary",
        "accept",
        "october",
        "december",
        "copy",
        "execution",
        "awful",
        "referrer",
        "april",
        "kimsuky",
        "malicious",
        "crypto",
        "startpage",
        "hacktool",
        "installer",
        "tofsee",
        "historical ssl",
        "threat roundup",
        "phishing",
        "utc submissions",
        "submitters",
        "csc corporate",
        "domains",
        "twitter",
        "dropbox",
        "incapsula",
        "summary iocs",
        "graph community",
        "registrarsafe",
        "gandi sas",
        "google llc",
        "amazon02",
        "google",
        "akamaias",
        "facebook",
        "service",
        "patch",
        "namecheapnet",
        "cloudflarenet",
        "amazonaes",
        "gmo internet",
        "remote",
        "malvertizing",
        "spying",
        "cyber stalking"
      ],
      "references": [
        "https://tulach.cc/",
        "go.sabey.com",
        "sabey.com",
        "cellebrite.com",
        "https://cellebrite.com/en/federal-government/  [Pegasus ck privilege collection]",
        "https://www.pornhub.com/video/search?search=tsara+brashears",
        "remote.aciscomputers.com",
        "https://track.toccha.com/978eb025-0a62-46fa-827c-d71aa0524818?zoneid=5939372&ua=high&subzone_id=3038557&set=social&country=SY&region=49&isp=syriatelmobiletelecom&useragent=Mozilla/5.0",
        "114.114.114.114 [Tulach]",
        "nr-data.net [Apple Private Data Collection]",
        "defenselawyernj.com",
        "attorney-marketing-specialists.com ?",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/image-recognition-and-searcher/id1450230225",
        "http://www.apple.com/appleca/AppleIncRootCertificate.cer",
        "http://flexlucky.com/isurvey/en/?devicemodel=iPhone&carrier=\u00aeion=Tbilisi&brand=Apple&browser=GoogleApp&prize=cur&u=track.bawiwia.com&isp=JSCGlobalErty&ts=29900ce7-726c-4c9f-b0c3-21ff2f859648&country=GE&click_id=wuo4jm6db011lufu2f8h138c&partner=5658402&skip=yes&frame={frame}&cost=0.010100&lang=en",
        "https://t.me/hermitspyware/24",
        "hyundai-smg.com | http://hyundai-smg.com/index.php?route=information/contact | http://hyundai-smg.com/index.php?route=information/contact",
        "https://imazing.com/guides/detect-pegasus-and-other-spyware-on-iphone",
        "http://watchhers.net/index.php [remote attackers | malware spreader]",
        "api-stage.pornhub.com",
        "newbrazzers.com [y8.com]",
        "www.videolan.org [info solutions]",
        "www2.blackbagtech.com [hidden users included]",
        "http://subtitles.rest7.com/subs/The.Expanse.S03E11.720p.HDTV.x264-KILLERS[eztv].mkv",
        "http://pegasus.diskel.co.uk/ [phishing]",
        "wapwon.live/category/tsara-brashears-assaulted-by-jeffrey-reimerAccept-Language",
        "fds.cellebrite.com",
        "http://www1.mychartahn.org/?tm=1&subid4=1671014887.0191400000&kw=Patient+Portal&KW1=Patient+Access+Network&KW2=Patient+Self+Check+In+System&KW3=Electronic+Health+Record+EHR+System&KW4=Patient+Appointment+Scheduling+System&KW5=Medical+Billing+System+Software&KW6=Patient+Financial+Assistance&searchbox=0&domainname=0&backfill=0",
        "healthcare.greatcall.com [fake call centers | PHI & PII info stealers]",
        "http://download.virtualbox.org/virtualbox/debian",
        "match.pegasus.isi.edu",
        "asp.net",
        "http://dropbox.com/ [ intrusions/ dropbox stealer]"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Exodus",
          "display_name": "Exodus",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "Sabey",
          "display_name": "Sabey",
          "target": null
        },
        {
          "id": "VirTool:Win32/Tofsee",
          "display_name": "VirTool:Win32/Tofsee",
          "target": "/malware/VirTool:Win32/Tofsee"
        },
        {
          "id": "Kimsuky",
          "display_name": "Kimsuky",
          "target": null
        },
        {
          "id": "PWS:Win32/Raven",
          "display_name": "PWS:Win32/Raven",
          "target": "/malware/PWS:Win32/Raven"
        },
        {
          "id": "Trojan:Win32/Comspec",
          "display_name": "Trojan:Win32/Comspec",
          "target": "/malware/Trojan:Win32/Comspec"
        },
        {
          "id": "HallRender",
          "display_name": "HallRender",
          "target": null
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1588",
          "name": "Obtain Capabilities",
          "display_name": "T1588 - Obtain Capabilities"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1588.004",
          "name": "Digital Certificates",
          "display_name": "T1588.004 - Digital Certificates"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1546.015",
          "name": "Component Object Model Hijacking",
          "display_name": "T1546.015 - Component Object Model Hijacking"
        },
        {
          "id": "T1071.003",
          "name": "Mail Protocols",
          "display_name": "T1071.003 - Mail Protocols"
        }
      ],
      "industries": [
        "Individual",
        "Patient",
        "Healthcare",
        "Survivor"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4101,
        "FileHash-MD5": 322,
        "FileHash-SHA1": 296,
        "FileHash-SHA256": 3157,
        "domain": 2903,
        "hostname": 2847,
        "CVE": 2,
        "email": 9,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 13639,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "835 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65b80a20bbcd0eb305a740ec",
      "name": "Exodus l Cellbrite | Brian Sabey | HallRender | Tulach",
      "description": "",
      "modified": "2024-02-16T05:03:15.321000",
      "created": "2024-01-29T20:27:12.899000",
      "tags": [
        "ssl certificate",
        "network",
        "malware",
        "whois record",
        "contacted",
        "pegasus",
        "resolutions",
        "communicating",
        "sa victim",
        "assaulter",
        "quasar",
        "brian sabey",
        "go.sabey",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls https",
        "samples",
        "united",
        "aaaa",
        "status",
        "susp",
        "search",
        "passive dns",
        "urls",
        "domain",
        "creation date",
        "date",
        "next",
        "show",
        "domain related",
        "feeds ioc",
        "maltiverse",
        "analyze",
        "scan endpoints",
        "all octoseek",
        "url https",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "all search",
        "otx octoseek",
        "hostname",
        "pulse submit",
        "url analysis",
        "files",
        "china unknown",
        "as4134 chinanet",
        "unknown",
        "name servers",
        "showing",
        "namesilo",
        "domain name",
        "dynadot llc",
        "as8075",
        "script urls",
        "netherlands",
        "a domains",
        "capture",
        "asnone united",
        "record value",
        "expiration date",
        "entries",
        "cname",
        "tulach",
        "algorithm",
        "v3 serial",
        "number",
        "key algorithm",
        "key identifier",
        "subject key",
        "identifier",
        "x509v3 key",
        "usage",
        "x509v3 extended",
        "info",
        "first",
        "server",
        "available from",
        "iana id",
        "registrar abuse",
        "registrar url",
        "registrar whois",
        "abuse contact",
        "email",
        "registry domain",
        "code",
        "win32 exe",
        "ufed iphone",
        "cellebrite ufed",
        "setup",
        "tjprojmain",
        "ufed4pc",
        "win32 dll",
        "detections type",
        "name",
        "responder",
        "exodus",
        "android",
        "office open",
        "xml document",
        "cellebrite",
        "type name",
        "pdf cellebrite",
        "ufed release",
        "cellbrite",
        "privilege https",
        "targets sa",
        "survivor",
        "getprocaddress",
        "indicator",
        "prefetch8",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "file",
        "pattern match",
        "observed email",
        "path",
        "factory",
        "hybrid",
        "general",
        "model",
        "comspec",
        "click",
        "title",
        "page",
        "body doctype",
        "quoth",
        "raven",
        "gmt content",
        "type",
        "vary",
        "accept",
        "october",
        "december",
        "copy",
        "execution",
        "awful",
        "referrer",
        "april",
        "kimsuky",
        "malicious",
        "crypto",
        "startpage",
        "hacktool",
        "installer",
        "tofsee",
        "historical ssl",
        "threat roundup",
        "phishing",
        "utc submissions",
        "submitters",
        "csc corporate",
        "domains",
        "twitter",
        "dropbox",
        "incapsula",
        "summary iocs",
        "graph community",
        "registrarsafe",
        "gandi sas",
        "google llc",
        "amazon02",
        "google",
        "akamaias",
        "facebook",
        "service",
        "patch",
        "namecheapnet",
        "cloudflarenet",
        "amazonaes",
        "gmo internet",
        "apple",
        "tsara brashears",
        "keylogger"
      ],
      "references": [
        "https://tulach.cc/",
        "cellebrite.com | https://cellebrite.com/en/federal-government/",
        "https://www.pornhub.com/video/search?search=tsara+brashears",
        "https://twitter.com/PORNO_SEXYBABES",
        "hanmail.net",
        "114.114.114.114",
        "work.a-poster.info",
        "www-stage40.pornhub.com",
        "go.sabey.com",
        "sabey.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Exodus",
          "display_name": "Exodus",
          "target": null
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "PWS:Win32/Raven",
          "display_name": "PWS:Win32/Raven",
          "target": "/malware/PWS:Win32/Raven"
        },
        {
          "id": "Kimsuky",
          "display_name": "Kimsuky",
          "target": null
        },
        {
          "id": "VirTool:Win32/Tofsee",
          "display_name": "VirTool:Win32/Tofsee",
          "target": "/malware/VirTool:Win32/Tofsee"
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1588",
          "name": "Obtain Capabilities",
          "display_name": "T1588 - Obtain Capabilities"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65a76c2901b34c79a681596d",
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4101,
        "FileHash-MD5": 322,
        "FileHash-SHA1": 296,
        "FileHash-SHA256": 3155,
        "domain": 2894,
        "hostname": 2847,
        "CVE": 2,
        "email": 9,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 13628,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 230,
      "modified_text": "835 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6583e3a2d1432cbf9054d26d",
      "name": "Qkbot | Reddit",
      "description": "Qbot URL:  https://seedbeej.pk/tin/index.php?QBOT.zip found in Reddit Honeypot link: https://www.reddit.com/user\nbackdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork  with many capabilities, attack methods and demands.  An unsuspecting victim  always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware, malvertizing, fraud services, full control of badly compromised digital profiles which have been discovered.",
      "modified": "2024-01-20T02:02:19.559000",
      "created": "2023-12-21T07:05:06.936000",
      "tags": [
        "ssl certificate",
        "iocs",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "search",
        "threat",
        "paste",
        "blacklist https",
        "qakbot",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "ascii text",
        "pattern match",
        "file",
        "windows nt",
        "appdata",
        "indicator",
        "crlf line",
        "unicode text",
        "jpeg image",
        "mitre att",
        "hybrid",
        "general",
        "local",
        "error",
        "click",
        "strings",
        "microsoft",
        "threat analyzer",
        "urls https",
        "no data",
        "tag count",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "heur",
        "malware site",
        "malicious site",
        "safe site",
        "malware",
        "html",
        "phishing site",
        "site top",
        "riskware",
        "unsafe",
        "artemis",
        "quasar rat",
        "downldr",
        "agent",
        "presenoker",
        "applicunwnt",
        "crack",
        "cve201711882",
        "win64",
        "iframe",
        "quasar",
        "trojanspy",
        "exit",
        "node tcp",
        "tor known",
        "tor relayrouter",
        "traffic",
        "anonymizer",
        "brasil",
        "phishing three",
        "united",
        "phishing bank",
        "virustotal",
        "tech",
        "bank",
        "maltiverse",
        "hidelink",
        "samples",
        "spyware",
        "injector",
        "mon jan",
        "tld count",
        "wed dec",
        "download",
        "first",
        "team",
        "simda",
        "bambernek",
        "simda simda",
        "infy",
        "alexa",
        "gregory",
        "cyber threat",
        "phishing",
        "engineering",
        "covid19",
        "telefonica co",
        "malicious",
        "zbot",
        "zeus",
        "betabot",
        "suppobox",
        "citadel",
        "pony",
        "kraken",
        "redline stealer",
        "ransomware",
        "vawtrak",
        "athena",
        "neutrino",
        "alina",
        "andromeda",
        "dexter",
        "unknown",
        "keylogger",
        "hawkeye",
        "phase",
        "jackpos",
        "plasma",
        "spyeye",
        "spitmo",
        "slingshot",
        "ramnit",
        "emotet",
        "pykspa",
        "virut",
        "installcore",
        "dorkbot",
        "bondat",
        "union",
        "vskimmer",
        "xtrat",
        "solar",
        "grandcrab",
        "nymaim",
        "matsnu",
        "cutwail",
        "cobalt strike",
        "hydra",
        "tinba",
        "nsis",
        "memscan",
        "deepscan",
        "runescape",
        "backdoor",
        "reddit",
        "tulach"
      ],
      "references": [
        "https://seedbeej.pk/tin/index.php?QBOT.zip",
        "https://tulach.cc/ [phishing, exploits, malware spreader]",
        "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
        "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
        "198.54.115.46            [exploit_source]",
        "gadyniw.com          [command_and_control]",
        "gahyqah.com          [command_and_control]",
        "galyqaz.com            [command_and_control]",
        "lyvyxor.com             [command_and_control]",
        "puzylyp.com           [command_and_control]",
        "malicious.high.ml   [dropper]",
        "https://www.reddit.com/user"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Qakbot",
          "display_name": "Qakbot",
          "target": null
        },
        {
          "id": "Quasar",
          "display_name": "Quasar",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "HideLink",
          "display_name": "HideLink",
          "target": null
        },
        {
          "id": "Gregory",
          "display_name": "Gregory",
          "target": null
        },
        {
          "id": "Cutwail",
          "display_name": "Cutwail",
          "target": null
        },
        {
          "id": "Matsnu",
          "display_name": "Matsnu",
          "target": null
        },
        {
          "id": "Vawtrak",
          "display_name": "Vawtrak",
          "target": null
        },
        {
          "id": "XRat",
          "display_name": "XRat",
          "target": null
        },
        {
          "id": "Zbot",
          "display_name": "Zbot",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "ZeuS",
          "display_name": "ZeuS",
          "target": null
        },
        {
          "id": "vSkimmer",
          "display_name": "vSkimmer",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Simda",
          "display_name": "Simda",
          "target": null
        },
        {
          "id": "Pykspa",
          "display_name": "Pykspa",
          "target": null
        },
        {
          "id": "SpyEye",
          "display_name": "SpyEye",
          "target": null
        },
        {
          "id": "Spitmo",
          "display_name": "Spitmo",
          "target": null
        },
        {
          "id": "Solar",
          "display_name": "Solar",
          "target": null
        },
        {
          "id": "Nymaim",
          "display_name": "Nymaim",
          "target": null
        },
        {
          "id": "DorkBot",
          "display_name": "DorkBot",
          "target": null
        },
        {
          "id": "Slingshot",
          "display_name": "Slingshot",
          "target": null
        },
        {
          "id": "Pony",
          "display_name": "Pony",
          "target": null
        },
        {
          "id": "Plasma RAT",
          "display_name": "Plasma RAT",
          "target": null
        },
        {
          "id": "Neutrino",
          "display_name": "Neutrino",
          "target": null
        },
        {
          "id": "Ramnit",
          "display_name": "Ramnit",
          "target": null
        },
        {
          "id": "NSIS",
          "display_name": "NSIS",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "InstallCore",
          "display_name": "InstallCore",
          "target": null
        },
        {
          "id": "GrandCrab",
          "display_name": "GrandCrab",
          "target": null
        },
        {
          "id": "Andromeda",
          "display_name": "Andromeda",
          "target": null
        },
        {
          "id": "Alinaos",
          "display_name": "Alinaos",
          "target": null
        },
        {
          "id": "HawkEye",
          "display_name": "HawkEye",
          "target": null
        },
        {
          "id": "Kraken",
          "display_name": "Kraken",
          "target": null
        },
        {
          "id": "Infy",
          "display_name": "Infy",
          "target": null
        },
        {
          "id": "Dexter",
          "display_name": "Dexter",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "ASCII",
          "display_name": "ASCII",
          "target": null
        },
        {
          "id": "Athena",
          "display_name": "Athena",
          "target": null
        },
        {
          "id": "Bambernek",
          "display_name": "Bambernek",
          "target": null
        },
        {
          "id": "BetaBot",
          "display_name": "BetaBot",
          "target": null
        },
        {
          "id": "COVID19",
          "display_name": "COVID19",
          "target": null
        },
        {
          "id": "Citadel",
          "display_name": "Citadel",
          "target": null
        },
        {
          "id": "Bondat",
          "display_name": "Bondat",
          "target": null
        },
        {
          "id": "HideLink",
          "display_name": "HideLink",
          "target": null
        },
        {
          "id": "Hydra",
          "display_name": "Hydra",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 98,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 8343,
        "FileHash-MD5": 953,
        "FileHash-SHA1": 489,
        "FileHash-SHA256": 3565,
        "domain": 1494,
        "hostname": 2218,
        "CVE": 6
      },
      "indicator_count": 17068,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "862 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6583e3acc7f464d48a3503d1",
      "name": "Qkbot | Reddit",
      "description": "Qbot URL:  https://seedbeej.pk/tin/index.php?QBOT.zip found in Reddit Honeypot link: https://www.reddit.com/user\nbackdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork  with many capabilities, attack methods and demands.  An unsuspecting victim  always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware, malvertizing, fraud services, full control of badly compromised digital profiles which have been discovered.",
      "modified": "2024-01-20T02:02:19.559000",
      "created": "2023-12-21T07:05:16.695000",
      "tags": [
        "ssl certificate",
        "iocs",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "search",
        "threat",
        "paste",
        "blacklist https",
        "qakbot",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "ascii text",
        "pattern match",
        "file",
        "windows nt",
        "appdata",
        "indicator",
        "crlf line",
        "unicode text",
        "jpeg image",
        "mitre att",
        "hybrid",
        "general",
        "local",
        "error",
        "click",
        "strings",
        "microsoft",
        "threat analyzer",
        "urls https",
        "no data",
        "tag count",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "heur",
        "malware site",
        "malicious site",
        "safe site",
        "malware",
        "html",
        "phishing site",
        "site top",
        "riskware",
        "unsafe",
        "artemis",
        "quasar rat",
        "downldr",
        "agent",
        "presenoker",
        "applicunwnt",
        "crack",
        "cve201711882",
        "win64",
        "iframe",
        "quasar",
        "trojanspy",
        "exit",
        "node tcp",
        "tor known",
        "tor relayrouter",
        "traffic",
        "anonymizer",
        "brasil",
        "phishing three",
        "united",
        "phishing bank",
        "virustotal",
        "tech",
        "bank",
        "maltiverse",
        "hidelink",
        "samples",
        "spyware",
        "injector",
        "mon jan",
        "tld count",
        "wed dec",
        "download",
        "first",
        "team",
        "simda",
        "bambernek",
        "simda simda",
        "infy",
        "alexa",
        "gregory",
        "cyber threat",
        "phishing",
        "engineering",
        "covid19",
        "telefonica co",
        "malicious",
        "zbot",
        "zeus",
        "betabot",
        "suppobox",
        "citadel",
        "pony",
        "kraken",
        "redline stealer",
        "ransomware",
        "vawtrak",
        "athena",
        "neutrino",
        "alina",
        "andromeda",
        "dexter",
        "unknown",
        "keylogger",
        "hawkeye",
        "phase",
        "jackpos",
        "plasma",
        "spyeye",
        "spitmo",
        "slingshot",
        "ramnit",
        "emotet",
        "pykspa",
        "virut",
        "installcore",
        "dorkbot",
        "bondat",
        "union",
        "vskimmer",
        "xtrat",
        "solar",
        "grandcrab",
        "nymaim",
        "matsnu",
        "cutwail",
        "cobalt strike",
        "hydra",
        "tinba",
        "nsis",
        "memscan",
        "deepscan",
        "runescape",
        "backdoor",
        "reddit",
        "tulach"
      ],
      "references": [
        "https://seedbeej.pk/tin/index.php?QBOT.zip",
        "https://tulach.cc/ [phishing, exploits, malware spreader]",
        "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
        "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
        "198.54.115.46            [exploit_source]",
        "gadyniw.com          [command_and_control]",
        "gahyqah.com          [command_and_control]",
        "galyqaz.com            [command_and_control]",
        "lyvyxor.com             [command_and_control]",
        "puzylyp.com           [command_and_control]",
        "malicious.high.ml   [dropper]",
        "https://www.reddit.com/user"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Qakbot",
          "display_name": "Qakbot",
          "target": null
        },
        {
          "id": "Quasar",
          "display_name": "Quasar",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "HideLink",
          "display_name": "HideLink",
          "target": null
        },
        {
          "id": "Gregory",
          "display_name": "Gregory",
          "target": null
        },
        {
          "id": "Cutwail",
          "display_name": "Cutwail",
          "target": null
        },
        {
          "id": "Matsnu",
          "display_name": "Matsnu",
          "target": null
        },
        {
          "id": "Vawtrak",
          "display_name": "Vawtrak",
          "target": null
        },
        {
          "id": "XRat",
          "display_name": "XRat",
          "target": null
        },
        {
          "id": "Zbot",
          "display_name": "Zbot",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "ZeuS",
          "display_name": "ZeuS",
          "target": null
        },
        {
          "id": "vSkimmer",
          "display_name": "vSkimmer",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Simda",
          "display_name": "Simda",
          "target": null
        },
        {
          "id": "Pykspa",
          "display_name": "Pykspa",
          "target": null
        },
        {
          "id": "SpyEye",
          "display_name": "SpyEye",
          "target": null
        },
        {
          "id": "Spitmo",
          "display_name": "Spitmo",
          "target": null
        },
        {
          "id": "Solar",
          "display_name": "Solar",
          "target": null
        },
        {
          "id": "Nymaim",
          "display_name": "Nymaim",
          "target": null
        },
        {
          "id": "DorkBot",
          "display_name": "DorkBot",
          "target": null
        },
        {
          "id": "Slingshot",
          "display_name": "Slingshot",
          "target": null
        },
        {
          "id": "Pony",
          "display_name": "Pony",
          "target": null
        },
        {
          "id": "Plasma RAT",
          "display_name": "Plasma RAT",
          "target": null
        },
        {
          "id": "Neutrino",
          "display_name": "Neutrino",
          "target": null
        },
        {
          "id": "Ramnit",
          "display_name": "Ramnit",
          "target": null
        },
        {
          "id": "NSIS",
          "display_name": "NSIS",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "InstallCore",
          "display_name": "InstallCore",
          "target": null
        },
        {
          "id": "GrandCrab",
          "display_name": "GrandCrab",
          "target": null
        },
        {
          "id": "Andromeda",
          "display_name": "Andromeda",
          "target": null
        },
        {
          "id": "Alinaos",
          "display_name": "Alinaos",
          "target": null
        },
        {
          "id": "HawkEye",
          "display_name": "HawkEye",
          "target": null
        },
        {
          "id": "Kraken",
          "display_name": "Kraken",
          "target": null
        },
        {
          "id": "Infy",
          "display_name": "Infy",
          "target": null
        },
        {
          "id": "Dexter",
          "display_name": "Dexter",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "ASCII",
          "display_name": "ASCII",
          "target": null
        },
        {
          "id": "Athena",
          "display_name": "Athena",
          "target": null
        },
        {
          "id": "Bambernek",
          "display_name": "Bambernek",
          "target": null
        },
        {
          "id": "BetaBot",
          "display_name": "BetaBot",
          "target": null
        },
        {
          "id": "COVID19",
          "display_name": "COVID19",
          "target": null
        },
        {
          "id": "Citadel",
          "display_name": "Citadel",
          "target": null
        },
        {
          "id": "Bondat",
          "display_name": "Bondat",
          "target": null
        },
        {
          "id": "HideLink",
          "display_name": "HideLink",
          "target": null
        },
        {
          "id": "Hydra",
          "display_name": "Hydra",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 101,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 8343,
        "FileHash-MD5": 953,
        "FileHash-SHA1": 489,
        "FileHash-SHA256": 3565,
        "domain": 1494,
        "hostname": 2218,
        "CVE": 6
      },
      "indicator_count": 17068,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "862 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "658449d3f6ec1af2f3aace46",
      "name": "Qakbot | Reddit",
      "description": "Qbot URL: https://seedbeej.pk/tin/index.php?QBOT.zip Qbot zip found in Reddit Honeypot link: https://www.reddit.com/user backdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork with many capabilities, attack methods and demands. An unsuspecting victim always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware  malvertizing, fraud services, leads to full control of badly compromised digital profile.",
      "modified": "2024-01-20T02:02:19.559000",
      "created": "2023-12-21T14:21:07.435000",
      "tags": [
        "ssl certificate",
        "iocs",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "search",
        "threat",
        "paste",
        "blacklist https",
        "qakbot",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "ascii text",
        "pattern match",
        "file",
        "windows nt",
        "appdata",
        "indicator",
        "crlf line",
        "unicode text",
        "jpeg image",
        "mitre att",
        "hybrid",
        "general",
        "local",
        "error",
        "click",
        "strings",
        "microsoft",
        "threat analyzer",
        "urls https",
        "no data",
        "tag count",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "heur",
        "malware site",
        "malicious site",
        "safe site",
        "malware",
        "html",
        "phishing site",
        "site top",
        "riskware",
        "unsafe",
        "artemis",
        "quasar rat",
        "downldr",
        "agent",
        "presenoker",
        "applicunwnt",
        "crack",
        "cve201711882",
        "win64",
        "iframe",
        "quasar",
        "trojanspy",
        "exit",
        "node tcp",
        "tor known",
        "tor relayrouter",
        "traffic",
        "anonymizer",
        "brasil",
        "phishing three",
        "united",
        "phishing bank",
        "virustotal",
        "tech",
        "bank",
        "maltiverse",
        "hidelink",
        "samples",
        "spyware",
        "injector",
        "mon jan",
        "tld count",
        "wed dec",
        "download",
        "first",
        "team",
        "simda",
        "bambernek",
        "simda simda",
        "infy",
        "alexa",
        "gregory",
        "cyber threat",
        "phishing",
        "engineering",
        "covid19",
        "telefonica co",
        "malicious",
        "zbot",
        "zeus",
        "betabot",
        "suppobox",
        "citadel",
        "pony",
        "kraken",
        "redline stealer",
        "ransomware",
        "vawtrak",
        "athena",
        "neutrino",
        "alina",
        "andromeda",
        "dexter",
        "unknown",
        "keylogger",
        "hawkeye",
        "phase",
        "jackpos",
        "plasma",
        "spyeye",
        "spitmo",
        "slingshot",
        "ramnit",
        "emotet",
        "pykspa",
        "virut",
        "installcore",
        "dorkbot",
        "bondat",
        "union",
        "vskimmer",
        "xtrat",
        "solar",
        "grandcrab",
        "nymaim",
        "matsnu",
        "cutwail",
        "cobalt strike",
        "hydra",
        "tinba",
        "nsis",
        "memscan",
        "deepscan",
        "runescape",
        "backdoor",
        "reddit",
        "tulach",
        "password stealer",
        "active threat",
        "apple",
        "pinkslipbot",
        "icloud",
        "free",
        "apple"
      ],
      "references": [
        "https://seedbeej.pk/tin/index.php?QBOT.zip.  [Qbot zip]",
        "https://tulach.cc/  [Botnet phishing]",
        "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
        "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
        "198.54.115.46            [exploit_source]",
        "gadyniw.com          [command_and_control]",
        "gahyqah.com          [command_and_control]",
        "galyqaz.com            [command_and_control]",
        "lyvyxor.com             [command_and_control]",
        "puzylyp.com           [command_and_control]",
        "malicious.high.ml   [dropper]",
        "https://www.reddit.com/user [honeypot]",
        "beacons.bcp.gvt.com   [tracking]",
        "https://www.norad.mil/   [tracking]",
        "www.norad.mil   [tracking]",
        "www.apple.com  [API property call]",
        "https://www.apple.com/qtactivex/qtplugin.cab   [https://www.icloud.com .cab]",
        "yesporn.fun",
        "http://114.114.114.114:90/p/cdbdd4a09a64909694281aec503746fd/mobile_index.html?MTE0LjExNC4xMTQuMTE0L2xvZ2luP2hhc19vcmlfdXJp [Tulach | Malicious]",
        "114.114.114.114  [Tulach | Virus Network IP]"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Qakbot",
          "display_name": "Qakbot",
          "target": null
        },
        {
          "id": "Quasar",
          "display_name": "Quasar",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "HideLink",
          "display_name": "HideLink",
          "target": null
        },
        {
          "id": "Gregory",
          "display_name": "Gregory",
          "target": null
        },
        {
          "id": "Cutwail",
          "display_name": "Cutwail",
          "target": null
        },
        {
          "id": "Matsnu",
          "display_name": "Matsnu",
          "target": null
        },
        {
          "id": "Vawtrak",
          "display_name": "Vawtrak",
          "target": null
        },
        {
          "id": "XRat",
          "display_name": "XRat",
          "target": null
        },
        {
          "id": "Zbot",
          "display_name": "Zbot",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "ZeuS",
          "display_name": "ZeuS",
          "target": null
        },
        {
          "id": "vSkimmer",
          "display_name": "vSkimmer",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Simda",
          "display_name": "Simda",
          "target": null
        },
        {
          "id": "Pykspa",
          "display_name": "Pykspa",
          "target": null
        },
        {
          "id": "SpyEye",
          "display_name": "SpyEye",
          "target": null
        },
        {
          "id": "Spitmo",
          "display_name": "Spitmo",
          "target": null
        },
        {
          "id": "Solar",
          "display_name": "Solar",
          "target": null
        },
        {
          "id": "Nymaim",
          "display_name": "Nymaim",
          "target": null
        },
        {
          "id": "DorkBot",
          "display_name": "DorkBot",
          "target": null
        },
        {
          "id": "Slingshot",
          "display_name": "Slingshot",
          "target": null
        },
        {
          "id": "Pony",
          "display_name": "Pony",
          "target": null
        },
        {
          "id": "Plasma RAT",
          "display_name": "Plasma RAT",
          "target": null
        },
        {
          "id": "Neutrino",
          "display_name": "Neutrino",
          "target": null
        },
        {
          "id": "Ramnit",
          "display_name": "Ramnit",
          "target": null
        },
        {
          "id": "NSIS",
          "display_name": "NSIS",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "InstallCore",
          "display_name": "InstallCore",
          "target": null
        },
        {
          "id": "GrandCrab",
          "display_name": "GrandCrab",
          "target": null
        },
        {
          "id": "Andromeda",
          "display_name": "Andromeda",
          "target": null
        },
        {
          "id": "Alinaos",
          "display_name": "Alinaos",
          "target": null
        },
        {
          "id": "HawkEye",
          "display_name": "HawkEye",
          "target": null
        },
        {
          "id": "Kraken",
          "display_name": "Kraken",
          "target": null
        },
        {
          "id": "Infy",
          "display_name": "Infy",
          "target": null
        },
        {
          "id": "Dexter",
          "display_name": "Dexter",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "ASCII",
          "display_name": "ASCII",
          "target": null
        },
        {
          "id": "Athena",
          "display_name": "Athena",
          "target": null
        },
        {
          "id": "Bambernek",
          "display_name": "Bambernek",
          "target": null
        },
        {
          "id": "BetaBot",
          "display_name": "BetaBot",
          "target": null
        },
        {
          "id": "COVID19",
          "display_name": "COVID19",
          "target": null
        },
        {
          "id": "Citadel",
          "display_name": "Citadel",
          "target": null
        },
        {
          "id": "Bondat",
          "display_name": "Bondat",
          "target": null
        },
        {
          "id": "HideLink",
          "display_name": "HideLink",
          "target": null
        },
        {
          "id": "Hydra",
          "display_name": "Hydra",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "Pinkslipbot",
          "display_name": "Pinkslipbot",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 124,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 8736,
        "FileHash-MD5": 953,
        "FileHash-SHA1": 489,
        "FileHash-SHA256": 3566,
        "domain": 1516,
        "hostname": 2221,
        "CVE": 6
      },
      "indicator_count": 17487,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "862 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "nyames.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "nyames.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780235801.172992
}