{
  "type": "Domain",
  "indicator": "odgers.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/odgers.com",
    "alexa": "http://www.alexa.com/siteinfo/odgers.com",
    "indicator": "odgers.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4366981388,
      "indicator": "odgers.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "6a0b53626be41dfe6834d2e4",
          "name": "* Cross-Platform iOS Curveball Crypto Forgery Exploit  *   CAPE Sandbox",
          "description": "Standalone iOS Mobile Infrastrure Name: document.html (~1MB, 12,311 lines, null title tag) * MD5: 6816bd15813549fa95a543dc7593b2a3\n* SHA-1: d73716914eb0b2a0211...\n2. Malformed Mathematical Parsing Architecture\nThe js loader handles strings by evaluating positions directly from malformed cryptographic signatures rather than declaring standard network callbacks.\n* Script Target String Hash: 57c8a0597dcd4...\n-Internal File Path Queried\n-Location Isolation: The engine scans for multi-locale layout properties during browser rendering. By targeting string array offsets, the logic programmatically generates continuous queries.\n-Exploitation Vector: Leverages WebKit script execution directly within volatile mobile browser memory due to hollow processes [root+code] result likely xxs/f.\n-Floods local [exe] threads with continuous data-parsing tasks. This isolates the runtime process inside  iOS hardware, generating background loops, interface lag,&memory exhaustion w/o raising traditional system level malware flags.",
          "modified": "2026-05-20T08:57:18.461000",
          "created": "2026-05-18T17:58:58.565000",
          "tags": [
            "link",
            "calendar",
            "keep track",
            "apple support",
            "doctype html",
            "title",
            "locale",
            "performs dns",
            "https",
            "mitre attack",
            "network info",
            "processes extra",
            "t1055 process",
            "layer protocol",
            "overview",
            "overview zenbox",
            "verdict",
            "meta",
            "defense evasion",
            "next",
            "meta tags",
            "script tags"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120167&Signature=jjx58TOoBzcM3VAt6aHBhD4Uk3qycXhPqBQ8%2B8mz8WRFE4nQysuz0pE%2FJzqE8UZjK%2BX%2BAInP0ol%2FRWQbnzCDOo0O0F5e%2FPy2fpnO1vsZEOxNjdEtr2WkvWUDLO0qno2oh2JOVvZt1vgN4SNWIxyNjHTlG3fK01pZf1EQeRIp%2BAew7ogUBkxPG4u1kB31EZUg9aYJ%2BJfFOSHns2y38Qo9Nf7xOWRSWQL64s0fMLN%2FuJqo",
            "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120190&Signature=zS7YS90991jg3aJaHUHkbgiegDEmI0TwVITFGgNG24UVG73I%2FgH%2FAZlVbEbTAd5%2BugQgcGmZuWW8i0Uw0p0%2FDhDWK6pGhJtJK3y2Ulgjnhw%2FaPWFotHlWDB9oEQFybyHcGd%2BNasc5tq5pO4HZh9iGudQbMGnWYMA6pNesIB%2BE%2F3Mjov7QwGStPg0XfB325h5ywgvcB0YPEpItbGtIaNV38AWc7GLWaZ7H02vKioR54IZVg7aAjnWK6",
            "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120693&Signature=PVlkmBs1ypAK33UCMzZhLE7IQY1bFdSzhzuw67rSm6i4rNdSuRctwVViaGNmfwaEMtyJOO5F10u45F9x%2FXCSkpa27mW8a4CGp6bE5YSlMLespUT9sGxzgFnOhib4SXue%2B%2BSJDXmV%2FHsVXNWSpYtr9E%2Fithqwkr5P2KDnUgGp9T0aFrIdZxtTn4QtjdAduC7gCLDfRiNID7ZjPVJV0lq%2Fz1%2Fhu%2FQs0Sw4%2BX1iNvp%2Bed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 54,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 281,
            "hostname": 149,
            "URL": 255,
            "domain": 118
          },
          "indicator_count": 864,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "11 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0b5364337dfd91041f4d22",
          "name": "* Cross-Platform iOS Curveball Crypto Forgery Exploit  *   CAPE Sandbox",
          "description": "Standalone iOS Mobile Infrastrure Name: document.html (~1MB, 12,311 lines, null title tag) * MD5: 6816bd15813549fa95a543dc7593b2a3\n* SHA-1: d73716914eb0b2a0211...\n2. Malformed Mathematical Parsing Architecture\nThe js loader handles strings by evaluating positions directly from malformed cryptographic signatures rather than declaring standard network callbacks.\n* Script Target String Hash: 57c8a0597dcd4...\n-Internal File Path Queried\n-Location Isolation: The engine scans for multi-locale layout properties during browser rendering. By targeting string array offsets, the logic programmatically generates continuous queries.\n-Exploitation Vector: Leverages WebKit script execution directly within volatile mobile browser memory due to hollow processes [root+code] result likely xxs/f.\n-Floods local [exe] threads with continuous data-parsing tasks. This isolates the runtime process inside  iOS hardware, generating background loops, interface lag,&memory exhaustion w/o raising traditional system level malware flags.",
          "modified": "2026-05-20T08:56:56.059000",
          "created": "2026-05-18T17:59:00.842000",
          "tags": [
            "link",
            "calendar",
            "keep track",
            "apple support",
            "doctype html",
            "title",
            "locale",
            "performs dns",
            "https",
            "mitre attack",
            "network info",
            "processes extra",
            "t1055 process",
            "layer protocol",
            "overview",
            "overview zenbox",
            "verdict",
            "meta",
            "defense evasion",
            "next",
            "meta tags",
            "script tags"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120167&Signature=jjx58TOoBzcM3VAt6aHBhD4Uk3qycXhPqBQ8%2B8mz8WRFE4nQysuz0pE%2FJzqE8UZjK%2BX%2BAInP0ol%2FRWQbnzCDOo0O0F5e%2FPy2fpnO1vsZEOxNjdEtr2WkvWUDLO0qno2oh2JOVvZt1vgN4SNWIxyNjHTlG3fK01pZf1EQeRIp%2BAew7ogUBkxPG4u1kB31EZUg9aYJ%2BJfFOSHns2y38Qo9Nf7xOWRSWQL64s0fMLN%2FuJqo",
            "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120190&Signature=zS7YS90991jg3aJaHUHkbgiegDEmI0TwVITFGgNG24UVG73I%2FgH%2FAZlVbEbTAd5%2BugQgcGmZuWW8i0Uw0p0%2FDhDWK6pGhJtJK3y2Ulgjnhw%2FaPWFotHlWDB9oEQFybyHcGd%2BNasc5tq5pO4HZh9iGudQbMGnWYMA6pNesIB%2BE%2F3Mjov7QwGStPg0XfB325h5ywgvcB0YPEpItbGtIaNV38AWc7GLWaZ7H02vKioR54IZVg7aAjnWK6",
            "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120693&Signature=PVlkmBs1ypAK33UCMzZhLE7IQY1bFdSzhzuw67rSm6i4rNdSuRctwVViaGNmfwaEMtyJOO5F10u45F9x%2FXCSkpa27mW8a4CGp6bE5YSlMLespUT9sGxzgFnOhib4SXue%2B%2BSJDXmV%2FHsVXNWSpYtr9E%2Fithqwkr5P2KDnUgGp9T0aFrIdZxtTn4QtjdAduC7gCLDfRiNID7ZjPVJV0lq%2Fz1%2Fhu%2FQs0Sw4%2BX1iNvp%2Bed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 54,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 281,
            "hostname": 149,
            "URL": 255,
            "domain": 118
          },
          "indicator_count": 864,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "11 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0b535b1d8235c877c4fc81",
          "name": "* Cross-Platform iOS Curveball Crypto Forgery Exploit  *   CAPE Sandbox",
          "description": "Standalone iOS Mobile Infrastrure Name: document.html (~1MB, 12,311 lines, null title tag) * MD5: 6816bd15813549fa95a543dc7593b2a3\n* SHA-1: d73716914eb0b2a0211...\n2. Malformed Mathematical Parsing Architecture\nThe js loader handles strings by evaluating positions directly from malformed cryptographic signatures rather than declaring standard network callbacks.\n* Script Target String Hash: 57c8a0597dcd4...\n-Internal File Path Queried\n-Location Isolation: The engine scans for multi-locale layout properties during browser rendering. By targeting string array offsets, the logic programmatically generates continuous queries.\n-Exploitation Vector: Leverages WebKit script execution directly within volatile mobile browser memory due to hollow processes [root+code] result likely xxs/f.\n-Floods local [exe] threads with continuous data-parsing tasks. This isolates the runtime process inside  iOS hardware, generating background loops, interface lag,&memory exhaustion w/o raising traditional system level malware flags.",
          "modified": "2026-05-20T08:52:51.376000",
          "created": "2026-05-18T17:58:51.398000",
          "tags": [
            "link",
            "calendar",
            "keep track",
            "apple support",
            "doctype html",
            "title",
            "locale",
            "performs dns",
            "https",
            "mitre attack",
            "network info",
            "processes extra",
            "t1055 process",
            "layer protocol",
            "overview",
            "overview zenbox",
            "verdict",
            "meta",
            "defense evasion",
            "next",
            "meta tags",
            "script tags"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120167&Signature=jjx58TOoBzcM3VAt6aHBhD4Uk3qycXhPqBQ8%2B8mz8WRFE4nQysuz0pE%2FJzqE8UZjK%2BX%2BAInP0ol%2FRWQbnzCDOo0O0F5e%2FPy2fpnO1vsZEOxNjdEtr2WkvWUDLO0qno2oh2JOVvZt1vgN4SNWIxyNjHTlG3fK01pZf1EQeRIp%2BAew7ogUBkxPG4u1kB31EZUg9aYJ%2BJfFOSHns2y38Qo9Nf7xOWRSWQL64s0fMLN%2FuJqo",
            "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120190&Signature=zS7YS90991jg3aJaHUHkbgiegDEmI0TwVITFGgNG24UVG73I%2FgH%2FAZlVbEbTAd5%2BugQgcGmZuWW8i0Uw0p0%2FDhDWK6pGhJtJK3y2Ulgjnhw%2FaPWFotHlWDB9oEQFybyHcGd%2BNasc5tq5pO4HZh9iGudQbMGnWYMA6pNesIB%2BE%2F3Mjov7QwGStPg0XfB325h5ywgvcB0YPEpItbGtIaNV38AWc7GLWaZ7H02vKioR54IZVg7aAjnWK6",
            "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120693&Signature=PVlkmBs1ypAK33UCMzZhLE7IQY1bFdSzhzuw67rSm6i4rNdSuRctwVViaGNmfwaEMtyJOO5F10u45F9x%2FXCSkpa27mW8a4CGp6bE5YSlMLespUT9sGxzgFnOhib4SXue%2B%2BSJDXmV%2FHsVXNWSpYtr9E%2Fithqwkr5P2KDnUgGp9T0aFrIdZxtTn4QtjdAduC7gCLDfRiNID7ZjPVJV0lq%2Fz1%2Fhu%2FQs0Sw4%2BX1iNvp%2Bed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 54,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 281,
            "hostname": 149,
            "URL": 255,
            "domain": 117
          },
          "indicator_count": 863,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "11 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120167&Signature=jjx58TOoBzcM3VAt6aHBhD4Uk3qycXhPqBQ8%2B8mz8WRFE4nQysuz0pE%2FJzqE8UZjK%2BX%2BAInP0ol%2FRWQbnzCDOo0O0F5e%2FPy2fpnO1vsZEOxNjdEtr2WkvWUDLO0qno2oh2JOVvZt1vgN4SNWIxyNjHTlG3fK01pZf1EQeRIp%2BAew7ogUBkxPG4u1kB31EZUg9aYJ%2BJfFOSHns2y38Qo9Nf7xOWRSWQL64s0fMLN%2FuJqo",
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120190&Signature=zS7YS90991jg3aJaHUHkbgiegDEmI0TwVITFGgNG24UVG73I%2FgH%2FAZlVbEbTAd5%2BugQgcGmZuWW8i0Uw0p0%2FDhDWK6pGhJtJK3y2Ulgjnhw%2FaPWFotHlWDB9oEQFybyHcGd%2BNasc5tq5pO4HZh9iGudQbMGnWYMA6pNesIB%2BE%2F3Mjov7QwGStPg0XfB325h5ywgvcB0YPEpItbGtIaNV38AWc7GLWaZ7H02vKioR54IZVg7aAjnWK6",
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120693&Signature=PVlkmBs1ypAK33UCMzZhLE7IQY1bFdSzhzuw67rSm6i4rNdSuRctwVViaGNmfwaEMtyJOO5F10u45F9x%2FXCSkpa27mW8a4CGp6bE5YSlMLespUT9sGxzgFnOhib4SXue%2B%2BSJDXmV%2FHsVXNWSpYtr9E%2Fithqwkr5P2KDnUgGp9T0aFrIdZxtTn4QtjdAduC7gCLDfRiNID7ZjPVJV0lq%2Fz1%2Fhu%2FQs0Sw4%2BX1iNvp%2Bed"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "6a0b53626be41dfe6834d2e4",
      "name": "* Cross-Platform iOS Curveball Crypto Forgery Exploit  *   CAPE Sandbox",
      "description": "Standalone iOS Mobile Infrastrure Name: document.html (~1MB, 12,311 lines, null title tag) * MD5: 6816bd15813549fa95a543dc7593b2a3\n* SHA-1: d73716914eb0b2a0211...\n2. Malformed Mathematical Parsing Architecture\nThe js loader handles strings by evaluating positions directly from malformed cryptographic signatures rather than declaring standard network callbacks.\n* Script Target String Hash: 57c8a0597dcd4...\n-Internal File Path Queried\n-Location Isolation: The engine scans for multi-locale layout properties during browser rendering. By targeting string array offsets, the logic programmatically generates continuous queries.\n-Exploitation Vector: Leverages WebKit script execution directly within volatile mobile browser memory due to hollow processes [root+code] result likely xxs/f.\n-Floods local [exe] threads with continuous data-parsing tasks. This isolates the runtime process inside  iOS hardware, generating background loops, interface lag,&memory exhaustion w/o raising traditional system level malware flags.",
      "modified": "2026-05-20T08:57:18.461000",
      "created": "2026-05-18T17:58:58.565000",
      "tags": [
        "link",
        "calendar",
        "keep track",
        "apple support",
        "doctype html",
        "title",
        "locale",
        "performs dns",
        "https",
        "mitre attack",
        "network info",
        "processes extra",
        "t1055 process",
        "layer protocol",
        "overview",
        "overview zenbox",
        "verdict",
        "meta",
        "defense evasion",
        "next",
        "meta tags",
        "script tags"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120167&Signature=jjx58TOoBzcM3VAt6aHBhD4Uk3qycXhPqBQ8%2B8mz8WRFE4nQysuz0pE%2FJzqE8UZjK%2BX%2BAInP0ol%2FRWQbnzCDOo0O0F5e%2FPy2fpnO1vsZEOxNjdEtr2WkvWUDLO0qno2oh2JOVvZt1vgN4SNWIxyNjHTlG3fK01pZf1EQeRIp%2BAew7ogUBkxPG4u1kB31EZUg9aYJ%2BJfFOSHns2y38Qo9Nf7xOWRSWQL64s0fMLN%2FuJqo",
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120190&Signature=zS7YS90991jg3aJaHUHkbgiegDEmI0TwVITFGgNG24UVG73I%2FgH%2FAZlVbEbTAd5%2BugQgcGmZuWW8i0Uw0p0%2FDhDWK6pGhJtJK3y2Ulgjnhw%2FaPWFotHlWDB9oEQFybyHcGd%2BNasc5tq5pO4HZh9iGudQbMGnWYMA6pNesIB%2BE%2F3Mjov7QwGStPg0XfB325h5ywgvcB0YPEpItbGtIaNV38AWc7GLWaZ7H02vKioR54IZVg7aAjnWK6",
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120693&Signature=PVlkmBs1ypAK33UCMzZhLE7IQY1bFdSzhzuw67rSm6i4rNdSuRctwVViaGNmfwaEMtyJOO5F10u45F9x%2FXCSkpa27mW8a4CGp6bE5YSlMLespUT9sGxzgFnOhib4SXue%2B%2BSJDXmV%2FHsVXNWSpYtr9E%2Fithqwkr5P2KDnUgGp9T0aFrIdZxtTn4QtjdAduC7gCLDfRiNID7ZjPVJV0lq%2Fz1%2Fhu%2FQs0Sw4%2BX1iNvp%2Bed"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 54,
        "FileHash-MD5": 6,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 281,
        "hostname": 149,
        "URL": 255,
        "domain": 118
      },
      "indicator_count": 864,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "11 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a0b5364337dfd91041f4d22",
      "name": "* Cross-Platform iOS Curveball Crypto Forgery Exploit  *   CAPE Sandbox",
      "description": "Standalone iOS Mobile Infrastrure Name: document.html (~1MB, 12,311 lines, null title tag) * MD5: 6816bd15813549fa95a543dc7593b2a3\n* SHA-1: d73716914eb0b2a0211...\n2. Malformed Mathematical Parsing Architecture\nThe js loader handles strings by evaluating positions directly from malformed cryptographic signatures rather than declaring standard network callbacks.\n* Script Target String Hash: 57c8a0597dcd4...\n-Internal File Path Queried\n-Location Isolation: The engine scans for multi-locale layout properties during browser rendering. By targeting string array offsets, the logic programmatically generates continuous queries.\n-Exploitation Vector: Leverages WebKit script execution directly within volatile mobile browser memory due to hollow processes [root+code] result likely xxs/f.\n-Floods local [exe] threads with continuous data-parsing tasks. This isolates the runtime process inside  iOS hardware, generating background loops, interface lag,&memory exhaustion w/o raising traditional system level malware flags.",
      "modified": "2026-05-20T08:56:56.059000",
      "created": "2026-05-18T17:59:00.842000",
      "tags": [
        "link",
        "calendar",
        "keep track",
        "apple support",
        "doctype html",
        "title",
        "locale",
        "performs dns",
        "https",
        "mitre attack",
        "network info",
        "processes extra",
        "t1055 process",
        "layer protocol",
        "overview",
        "overview zenbox",
        "verdict",
        "meta",
        "defense evasion",
        "next",
        "meta tags",
        "script tags"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120167&Signature=jjx58TOoBzcM3VAt6aHBhD4Uk3qycXhPqBQ8%2B8mz8WRFE4nQysuz0pE%2FJzqE8UZjK%2BX%2BAInP0ol%2FRWQbnzCDOo0O0F5e%2FPy2fpnO1vsZEOxNjdEtr2WkvWUDLO0qno2oh2JOVvZt1vgN4SNWIxyNjHTlG3fK01pZf1EQeRIp%2BAew7ogUBkxPG4u1kB31EZUg9aYJ%2BJfFOSHns2y38Qo9Nf7xOWRSWQL64s0fMLN%2FuJqo",
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120190&Signature=zS7YS90991jg3aJaHUHkbgiegDEmI0TwVITFGgNG24UVG73I%2FgH%2FAZlVbEbTAd5%2BugQgcGmZuWW8i0Uw0p0%2FDhDWK6pGhJtJK3y2Ulgjnhw%2FaPWFotHlWDB9oEQFybyHcGd%2BNasc5tq5pO4HZh9iGudQbMGnWYMA6pNesIB%2BE%2F3Mjov7QwGStPg0XfB325h5ywgvcB0YPEpItbGtIaNV38AWc7GLWaZ7H02vKioR54IZVg7aAjnWK6",
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120693&Signature=PVlkmBs1ypAK33UCMzZhLE7IQY1bFdSzhzuw67rSm6i4rNdSuRctwVViaGNmfwaEMtyJOO5F10u45F9x%2FXCSkpa27mW8a4CGp6bE5YSlMLespUT9sGxzgFnOhib4SXue%2B%2BSJDXmV%2FHsVXNWSpYtr9E%2Fithqwkr5P2KDnUgGp9T0aFrIdZxtTn4QtjdAduC7gCLDfRiNID7ZjPVJV0lq%2Fz1%2Fhu%2FQs0Sw4%2BX1iNvp%2Bed"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 54,
        "FileHash-MD5": 6,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 281,
        "hostname": 149,
        "URL": 255,
        "domain": 118
      },
      "indicator_count": 864,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "11 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a0b535b1d8235c877c4fc81",
      "name": "* Cross-Platform iOS Curveball Crypto Forgery Exploit  *   CAPE Sandbox",
      "description": "Standalone iOS Mobile Infrastrure Name: document.html (~1MB, 12,311 lines, null title tag) * MD5: 6816bd15813549fa95a543dc7593b2a3\n* SHA-1: d73716914eb0b2a0211...\n2. Malformed Mathematical Parsing Architecture\nThe js loader handles strings by evaluating positions directly from malformed cryptographic signatures rather than declaring standard network callbacks.\n* Script Target String Hash: 57c8a0597dcd4...\n-Internal File Path Queried\n-Location Isolation: The engine scans for multi-locale layout properties during browser rendering. By targeting string array offsets, the logic programmatically generates continuous queries.\n-Exploitation Vector: Leverages WebKit script execution directly within volatile mobile browser memory due to hollow processes [root+code] result likely xxs/f.\n-Floods local [exe] threads with continuous data-parsing tasks. This isolates the runtime process inside  iOS hardware, generating background loops, interface lag,&memory exhaustion w/o raising traditional system level malware flags.",
      "modified": "2026-05-20T08:52:51.376000",
      "created": "2026-05-18T17:58:51.398000",
      "tags": [
        "link",
        "calendar",
        "keep track",
        "apple support",
        "doctype html",
        "title",
        "locale",
        "performs dns",
        "https",
        "mitre attack",
        "network info",
        "processes extra",
        "t1055 process",
        "layer protocol",
        "overview",
        "overview zenbox",
        "verdict",
        "meta",
        "defense evasion",
        "next",
        "meta tags",
        "script tags"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120167&Signature=jjx58TOoBzcM3VAt6aHBhD4Uk3qycXhPqBQ8%2B8mz8WRFE4nQysuz0pE%2FJzqE8UZjK%2BX%2BAInP0ol%2FRWQbnzCDOo0O0F5e%2FPy2fpnO1vsZEOxNjdEtr2WkvWUDLO0qno2oh2JOVvZt1vgN4SNWIxyNjHTlG3fK01pZf1EQeRIp%2BAew7ogUBkxPG4u1kB31EZUg9aYJ%2BJfFOSHns2y38Qo9Nf7xOWRSWQL64s0fMLN%2FuJqo",
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120190&Signature=zS7YS90991jg3aJaHUHkbgiegDEmI0TwVITFGgNG24UVG73I%2FgH%2FAZlVbEbTAd5%2BugQgcGmZuWW8i0Uw0p0%2FDhDWK6pGhJtJK3y2Ulgjnhw%2FaPWFotHlWDB9oEQFybyHcGd%2BNasc5tq5pO4HZh9iGudQbMGnWYMA6pNesIB%2BE%2F3Mjov7QwGStPg0XfB325h5ywgvcB0YPEpItbGtIaNV38AWc7GLWaZ7H02vKioR54IZVg7aAjnWK6",
        "https://vtbehaviour.commondatastorage.googleapis.com/f7f1f6f2f1b195829c5429c213d2e28536971247d42ec0ed7e7704de48f5d1b8_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779120693&Signature=PVlkmBs1ypAK33UCMzZhLE7IQY1bFdSzhzuw67rSm6i4rNdSuRctwVViaGNmfwaEMtyJOO5F10u45F9x%2FXCSkpa27mW8a4CGp6bE5YSlMLespUT9sGxzgFnOhib4SXue%2B%2BSJDXmV%2FHsVXNWSpYtr9E%2Fithqwkr5P2KDnUgGp9T0aFrIdZxtTn4QtjdAduC7gCLDfRiNID7ZjPVJV0lq%2Fz1%2Fhu%2FQs0Sw4%2BX1iNvp%2Bed"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 54,
        "FileHash-MD5": 6,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 281,
        "hostname": 149,
        "URL": 255,
        "domain": 117
      },
      "indicator_count": 863,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "11 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "odgers.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "odgers.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780255715.4441123
}