{
  "type": "Domain",
  "indicator": "onlinescholaraccess.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/onlinescholaraccess.com",
    "alexa": "http://www.alexa.com/siteinfo/onlinescholaraccess.com",
    "indicator": "onlinescholaraccess.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3901793628,
      "indicator": "onlinescholaraccess.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "698ef344417f9985660e698b",
          "name": "Pulse Data",
          "description": "A complete summary of all the key points in the analysis of the W32.virus, compiled by the University of California, Los Angeles, at the end of May, 2014, and published online.",
          "modified": "2026-03-28T07:23:23.210000",
          "created": "2026-02-13T09:47:48.788000",
          "tags": [
            "imphash",
            "file type",
            "pulse pulses",
            "av detections",
            "ids detections",
            "yara detections",
            "alerts",
            "analysis date",
            "file score",
            "detections tls",
            "zeppelin"
          ],
          "references": [
            "",
            "4860f9c5ec1ab473f1d63d19a31c82798d65a8d2 Add to Pulse Pulses 2 AV Detections 1 IDS Detections 5 YARA Detections 3 Alerts 0 Analysis Overview Analysis Date 4 days ago File Score 12 Malicious Antivirus Detections TrojanDownloader:Win32/Tugspay.A IDS Detections TLS Handshake Failure 403 Forbidden Yara Detections Win32_PUA_Domaiq ,  aPLib ,  PECompact_2xx Alerts 31 Alerts antivm_display infostealer_browser infostealer_cookies procmem_yara static_pe_anomaly suricata_alert antivm_bochs_keys physical_drive_access "
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 646,
            "FileHash-SHA1": 604,
            "FileHash-SHA256": 1373,
            "hostname": 1143,
            "domain": 1381,
            "URL": 2537,
            "CVE": 101,
            "email": 25,
            "SSLCertFingerprint": 9
          },
          "indicator_count": 7819,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "64 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "660b176a98b0c92ba5a962bc",
          "name": "\"No Problems\" - UAlberta TLD (Confirmed TLD - 08.04.24) & Subdomain compromise",
          "description": "Basically the above\n\n\"No Problems\", \"We are Unhackable\", etc. etc. causing problems.",
          "modified": "2024-09-04T05:01:56.993000",
          "created": "2024-04-01T20:22:02.851000",
          "tags": [
            "BEC"
          ],
          "references": [
            "https://www.virustotal.com/gui/collection/b8a6d1fcd73207ba46eae6806b946c4b539f301e718f3fba21fa4e797d4b5783/summary",
            "https://www.virustotal.com/gui/collection/b8a6d1fcd73207ba46eae6806b946c4b539f301e718f3fba21fa4e797d4b5783/iocs",
            "https://www.virustotal.com/graph/embed/gead337f35cdd4241b225b68ff0528a3834be5d60876745fa99254ff7f8a0df22?theme=dark",
            "https://www.virustotal.com/graph/embed/g1e31eca6803a433a9a33437d593a2bbdf979ff77c91340d1ab624d10dc8732b3?theme=dark",
            "https://dnstwist.it/#ea665d15-6507-4057-b2c9-18a2e546ee95",
            "https://malpedia.caad.fkie.fraunhofer.de/details/win.nanocore",
            "https://blog.checkpoint.com/security/march-2023s-most-wanted-malware-new-emotet-campaign-bypasses-microsoft-blocks-to-distribute-malicious-onenote-files/",
            "https://malpedia.caad.fkie.fraunhofer.de/details/win.mydoom",
            "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkgate"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada",
            "United States of America",
            "Netherlands"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Education",
            "Technology",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 233,
            "FileHash-SHA1": 230,
            "FileHash-SHA256": 6703,
            "URL": 4450,
            "CIDR": 3,
            "domain": 6223,
            "hostname": 2863,
            "email": 7,
            "CVE": 53
          },
          "indicator_count": 20765,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 130,
          "modified_text": "634 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6663311a8c529069bb34a06f",
          "name": "Injection | Win.Worm.Mydoom | Ransomware | Android Device attack",
          "description": "Android device, remotely modified, hidden users, 'zombie' device, targeting, framing, unknown admin.",
          "modified": "2024-07-07T15:00:25.739000",
          "created": "2024-06-07T16:11:06.485000",
          "tags": [
            "november",
            "threat roundup",
            "axelo",
            "atkafij0",
            "referrer",
            "historical ssl",
            "dynamicloader",
            "write c",
            "yara rule",
            "delete c",
            "ms windows",
            "medium",
            "yara detections",
            "show",
            "search",
            "united",
            "write",
            "copy",
            "create c",
            "read c",
            "flashpix",
            "high",
            "template",
            "persistence",
            "execution",
            "next",
            "unknown",
            "shared address",
            "html info",
            "title rfc",
            "ipv4 prefix",
            "space meta",
            "tags",
            "prefix",
            "space",
            "script tags",
            "anchor hrefs",
            "sha256",
            "vhash",
            "ssdeep",
            "html internet",
            "magic html",
            "ascii text",
            "magika html",
            "file size",
            "internet",
            "iana",
            "city",
            "los angeles",
            "orgabusephone",
            "orgid",
            "iana ref",
            "net192",
            "net1920000",
            "iana special",
            "detections type",
            "name",
            "win32 exe",
            "runresdll",
            "android",
            "trojan",
            "files",
            "installer",
            "10357",
            "javascript",
            "malibot",
            "pe32",
            "intel",
            "linux x8664",
            "khtml",
            "win32",
            "process32nextw",
            "discovery",
            "discovery t1057",
            "t1057",
            "t1045",
            "memcommit",
            "regopenkeyexw",
            "regsetvalueexa",
            "writeconsolea",
            "minute tr",
            "highest f",
            "regdword",
            "del f",
            "start",
            "memreserve",
            "dock"
          ],
          "references": [
            "http://tools.ietf.org/html/rfc6598 | Found in android device| Block: 100:116.200.0/? [Special Use /Non - IANA]",
            "AV Detection: Win.Downloader.68062-1 | Yara Detections: MS_Visual_Basic_6_0 ,  Cabinet_Archive",
            "High Priority Alerts: dead_host network_icmp dumped_buffer2 nolookup_communication modifies_certificates",
            "Alerts: dumped_buffer network_http allocates_rwx antisandbox_sleep antivm_disk_size exe_appdata antivm_network_adapters privilege_luid_check",
            "Alerts: antivm_queries_computername checks_debugger recon_fingerprint antivm_memory_available",
            "Image: https://otx.alienvault.com/otxapi/indicators/file/screenshot/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811",
            "https://otx.alienvault.com/indicator/file/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811 [Win.Downloader.68062-1]",
            "https://otx.alienvault.com/indicator/file/0000374bffccbcd54ea9a1c51514b671a8caf732ef3bef2cc8cccd4bf01665cf [Win.Worm.Mydoom-5]",
            "Yara Detections: Nrv2x , upx_3 ,  UPX_OEP_place , UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser , UPX",
            "High Priority Alerts: procmem_yara network_bind persistence_autorun",
            "Alerts: dynamic_function_loading powershell_download reads_self suspicious_tld dead_connect",
            "buildbot.tools.ietf.org [Win32:Malware-gen]",
            "Yara Detections: MS_Visual_Cpp_2008 | High Priority Alerts:  dead_host network_icmp",
            "Priority Alerts: dumped_buffer network_http suspicious_tld allocates_rwx creates_exe exe_appdata antivm_network_adapters pe_features",
            "Yara: Detections Skype User-Agent detected, LZMA"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Win.Downloader.68062-1",
              "display_name": "Win.Downloader.68062-1",
              "target": null
            },
            {
              "id": "Win.Worm.Mydoom-5",
              "display_name": "Win.Worm.Mydoom-5",
              "target": null
            },
            {
              "id": "Win32:Trojan-gen",
              "display_name": "Win32:Trojan-gen",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Hera.A!bit",
              "display_name": "Backdoor:Win32/Hera.A!bit",
              "target": "/malware/Backdoor:Win32/Hera.A!bit"
            }
          ],
          "attack_ids": [
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 350,
            "FileHash-SHA1": 318,
            "FileHash-SHA256": 1929,
            "URL": 1885,
            "hostname": 1600,
            "domain": 1380,
            "email": 7,
            "SSLCertFingerprint": 40
          },
          "indicator_count": 7509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 233,
          "modified_text": "693 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "Yara Detections: Nrv2x , upx_3 ,  UPX_OEP_place , UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser , UPX",
        "https://www.virustotal.com/gui/collection/b8a6d1fcd73207ba46eae6806b946c4b539f301e718f3fba21fa4e797d4b5783/summary",
        "https://www.virustotal.com/graph/embed/gead337f35cdd4241b225b68ff0528a3834be5d60876745fa99254ff7f8a0df22?theme=dark",
        "https://www.virustotal.com/gui/collection/b8a6d1fcd73207ba46eae6806b946c4b539f301e718f3fba21fa4e797d4b5783/iocs",
        "AV Detection: Win.Downloader.68062-1 | Yara Detections: MS_Visual_Basic_6_0 ,  Cabinet_Archive",
        "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkgate",
        "https://otx.alienvault.com/indicator/file/0000374bffccbcd54ea9a1c51514b671a8caf732ef3bef2cc8cccd4bf01665cf [Win.Worm.Mydoom-5]",
        "https://malpedia.caad.fkie.fraunhofer.de/details/win.nanocore",
        "http://tools.ietf.org/html/rfc6598 | Found in android device| Block: 100:116.200.0/? [Special Use /Non - IANA]",
        "Image: https://otx.alienvault.com/otxapi/indicators/file/screenshot/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811",
        "https://malpedia.caad.fkie.fraunhofer.de/details/win.mydoom",
        "4860f9c5ec1ab473f1d63d19a31c82798d65a8d2 Add to Pulse Pulses 2 AV Detections 1 IDS Detections 5 YARA Detections 3 Alerts 0 Analysis Overview Analysis Date 4 days ago File Score 12 Malicious Antivirus Detections TrojanDownloader:Win32/Tugspay.A IDS Detections TLS Handshake Failure 403 Forbidden Yara Detections Win32_PUA_Domaiq ,  aPLib ,  PECompact_2xx Alerts 31 Alerts antivm_display infostealer_browser infostealer_cookies procmem_yara static_pe_anomaly suricata_alert antivm_bochs_keys physical_drive_access ",
        "Yara Detections: MS_Visual_Cpp_2008 | High Priority Alerts:  dead_host network_icmp",
        "Alerts: dynamic_function_loading powershell_download reads_self suspicious_tld dead_connect",
        "Yara: Detections Skype User-Agent detected, LZMA",
        "https://otx.alienvault.com/indicator/file/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811 [Win.Downloader.68062-1]",
        "Alerts: dumped_buffer network_http allocates_rwx antisandbox_sleep antivm_disk_size exe_appdata antivm_network_adapters privilege_luid_check",
        "High Priority Alerts: dead_host network_icmp dumped_buffer2 nolookup_communication modifies_certificates",
        "Alerts: antivm_queries_computername checks_debugger recon_fingerprint antivm_memory_available",
        "buildbot.tools.ietf.org [Win32:Malware-gen]",
        "https://www.virustotal.com/graph/embed/g1e31eca6803a433a9a33437d593a2bbdf979ff77c91340d1ab624d10dc8732b3?theme=dark",
        "High Priority Alerts: procmem_yara network_bind persistence_autorun",
        "Priority Alerts: dumped_buffer network_http suspicious_tld allocates_rwx creates_exe exe_appdata antivm_network_adapters pe_features",
        "https://dnstwist.it/#ea665d15-6507-4057-b2c9-18a2e546ee95",
        "https://blog.checkpoint.com/security/march-2023s-most-wanted-malware-new-emotet-campaign-bypasses-microsoft-blocks-to-distribute-malicious-onenote-files/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Backdoor:win32/hera.a!bit",
            "Win.worm.mydoom-5",
            "Win32:trojan-gen",
            "Win.downloader.68062-1"
          ],
          "industries": [
            "Technology",
            "Education",
            "Government"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "698ef344417f9985660e698b",
      "name": "Pulse Data",
      "description": "A complete summary of all the key points in the analysis of the W32.virus, compiled by the University of California, Los Angeles, at the end of May, 2014, and published online.",
      "modified": "2026-03-28T07:23:23.210000",
      "created": "2026-02-13T09:47:48.788000",
      "tags": [
        "imphash",
        "file type",
        "pulse pulses",
        "av detections",
        "ids detections",
        "yara detections",
        "alerts",
        "analysis date",
        "file score",
        "detections tls",
        "zeppelin"
      ],
      "references": [
        "",
        "4860f9c5ec1ab473f1d63d19a31c82798d65a8d2 Add to Pulse Pulses 2 AV Detections 1 IDS Detections 5 YARA Detections 3 Alerts 0 Analysis Overview Analysis Date 4 days ago File Score 12 Malicious Antivirus Detections TrojanDownloader:Win32/Tugspay.A IDS Detections TLS Handshake Failure 403 Forbidden Yara Detections Win32_PUA_Domaiq ,  aPLib ,  PECompact_2xx Alerts 31 Alerts antivm_display infostealer_browser infostealer_cookies procmem_yara static_pe_anomaly suricata_alert antivm_bochs_keys physical_drive_access "
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 646,
        "FileHash-SHA1": 604,
        "FileHash-SHA256": 1373,
        "hostname": 1143,
        "domain": 1381,
        "URL": 2537,
        "CVE": 101,
        "email": 25,
        "SSLCertFingerprint": 9
      },
      "indicator_count": 7819,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "64 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "660b176a98b0c92ba5a962bc",
      "name": "\"No Problems\" - UAlberta TLD (Confirmed TLD - 08.04.24) & Subdomain compromise",
      "description": "Basically the above\n\n\"No Problems\", \"We are Unhackable\", etc. etc. causing problems.",
      "modified": "2024-09-04T05:01:56.993000",
      "created": "2024-04-01T20:22:02.851000",
      "tags": [
        "BEC"
      ],
      "references": [
        "https://www.virustotal.com/gui/collection/b8a6d1fcd73207ba46eae6806b946c4b539f301e718f3fba21fa4e797d4b5783/summary",
        "https://www.virustotal.com/gui/collection/b8a6d1fcd73207ba46eae6806b946c4b539f301e718f3fba21fa4e797d4b5783/iocs",
        "https://www.virustotal.com/graph/embed/gead337f35cdd4241b225b68ff0528a3834be5d60876745fa99254ff7f8a0df22?theme=dark",
        "https://www.virustotal.com/graph/embed/g1e31eca6803a433a9a33437d593a2bbdf979ff77c91340d1ab624d10dc8732b3?theme=dark",
        "https://dnstwist.it/#ea665d15-6507-4057-b2c9-18a2e546ee95",
        "https://malpedia.caad.fkie.fraunhofer.de/details/win.nanocore",
        "https://blog.checkpoint.com/security/march-2023s-most-wanted-malware-new-emotet-campaign-bypasses-microsoft-blocks-to-distribute-malicious-onenote-files/",
        "https://malpedia.caad.fkie.fraunhofer.de/details/win.mydoom",
        "https://malpedia.caad.fkie.fraunhofer.de/details/win.darkgate"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada",
        "United States of America",
        "Netherlands"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Education",
        "Technology",
        "Government"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 233,
        "FileHash-SHA1": 230,
        "FileHash-SHA256": 6703,
        "URL": 4450,
        "CIDR": 3,
        "domain": 6223,
        "hostname": 2863,
        "email": 7,
        "CVE": 53
      },
      "indicator_count": 20765,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 130,
      "modified_text": "634 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6663311a8c529069bb34a06f",
      "name": "Injection | Win.Worm.Mydoom | Ransomware | Android Device attack",
      "description": "Android device, remotely modified, hidden users, 'zombie' device, targeting, framing, unknown admin.",
      "modified": "2024-07-07T15:00:25.739000",
      "created": "2024-06-07T16:11:06.485000",
      "tags": [
        "november",
        "threat roundup",
        "axelo",
        "atkafij0",
        "referrer",
        "historical ssl",
        "dynamicloader",
        "write c",
        "yara rule",
        "delete c",
        "ms windows",
        "medium",
        "yara detections",
        "show",
        "search",
        "united",
        "write",
        "copy",
        "create c",
        "read c",
        "flashpix",
        "high",
        "template",
        "persistence",
        "execution",
        "next",
        "unknown",
        "shared address",
        "html info",
        "title rfc",
        "ipv4 prefix",
        "space meta",
        "tags",
        "prefix",
        "space",
        "script tags",
        "anchor hrefs",
        "sha256",
        "vhash",
        "ssdeep",
        "html internet",
        "magic html",
        "ascii text",
        "magika html",
        "file size",
        "internet",
        "iana",
        "city",
        "los angeles",
        "orgabusephone",
        "orgid",
        "iana ref",
        "net192",
        "net1920000",
        "iana special",
        "detections type",
        "name",
        "win32 exe",
        "runresdll",
        "android",
        "trojan",
        "files",
        "installer",
        "10357",
        "javascript",
        "malibot",
        "pe32",
        "intel",
        "linux x8664",
        "khtml",
        "win32",
        "process32nextw",
        "discovery",
        "discovery t1057",
        "t1057",
        "t1045",
        "memcommit",
        "regopenkeyexw",
        "regsetvalueexa",
        "writeconsolea",
        "minute tr",
        "highest f",
        "regdword",
        "del f",
        "start",
        "memreserve",
        "dock"
      ],
      "references": [
        "http://tools.ietf.org/html/rfc6598 | Found in android device| Block: 100:116.200.0/? [Special Use /Non - IANA]",
        "AV Detection: Win.Downloader.68062-1 | Yara Detections: MS_Visual_Basic_6_0 ,  Cabinet_Archive",
        "High Priority Alerts: dead_host network_icmp dumped_buffer2 nolookup_communication modifies_certificates",
        "Alerts: dumped_buffer network_http allocates_rwx antisandbox_sleep antivm_disk_size exe_appdata antivm_network_adapters privilege_luid_check",
        "Alerts: antivm_queries_computername checks_debugger recon_fingerprint antivm_memory_available",
        "Image: https://otx.alienvault.com/otxapi/indicators/file/screenshot/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811",
        "https://otx.alienvault.com/indicator/file/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811 [Win.Downloader.68062-1]",
        "https://otx.alienvault.com/indicator/file/0000374bffccbcd54ea9a1c51514b671a8caf732ef3bef2cc8cccd4bf01665cf [Win.Worm.Mydoom-5]",
        "Yara Detections: Nrv2x , upx_3 ,  UPX_OEP_place , UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser , UPX",
        "High Priority Alerts: procmem_yara network_bind persistence_autorun",
        "Alerts: dynamic_function_loading powershell_download reads_self suspicious_tld dead_connect",
        "buildbot.tools.ietf.org [Win32:Malware-gen]",
        "Yara Detections: MS_Visual_Cpp_2008 | High Priority Alerts:  dead_host network_icmp",
        "Priority Alerts: dumped_buffer network_http suspicious_tld allocates_rwx creates_exe exe_appdata antivm_network_adapters pe_features",
        "Yara: Detections Skype User-Agent detected, LZMA"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Win.Downloader.68062-1",
          "display_name": "Win.Downloader.68062-1",
          "target": null
        },
        {
          "id": "Win.Worm.Mydoom-5",
          "display_name": "Win.Worm.Mydoom-5",
          "target": null
        },
        {
          "id": "Win32:Trojan-gen",
          "display_name": "Win32:Trojan-gen",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Hera.A!bit",
          "display_name": "Backdoor:Win32/Hera.A!bit",
          "target": "/malware/Backdoor:Win32/Hera.A!bit"
        }
      ],
      "attack_ids": [
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 350,
        "FileHash-SHA1": 318,
        "FileHash-SHA256": 1929,
        "URL": 1885,
        "hostname": 1600,
        "domain": 1380,
        "email": 7,
        "SSLCertFingerprint": 40
      },
      "indicator_count": 7509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 233,
      "modified_text": "693 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "onlinescholaraccess.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "onlinescholaraccess.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780259156.4907897
}