{
  "type": "Domain",
  "indicator": "pcxrl.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/pcxrl.com",
    "alexa": "http://www.alexa.com/siteinfo/pcxrl.com",
    "indicator": "pcxrl.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4014049605,
      "indicator": "pcxrl.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "672f6ed2b564f00b7c5cb13f",
          "name": "Threatfox Recent Additions",
          "description": "",
          "modified": "2025-06-13T19:00:02.811000",
          "created": "2024-11-09T14:16:50.032000",
          "tags": [],
          "references": [
            "",
            "https://threatfox.abuse.ch/export/csv/recent/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 96,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ameermane",
            "id": "77501",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 47587,
            "URL": 18714,
            "FileHash-SHA256": 36311,
            "FileHash-MD5": 1630,
            "FileHash-SHA1": 418,
            "hostname": 18190
          },
          "indicator_count": 122850,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 144,
          "modified_text": "354 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6842ca684b5413baf27aa136",
          "name": "Satori Threat Intelligence Disruption: BADBOX 2.0 Targets Consumer Devices with Multiple Fraud Schemes - HUMAN Security",
          "description": "Learn more about HUMAN, the artificial intelligence company designed to prevent bot attacks and fraud on ad tech platforms and digital publishers, from exploiting customers' valuable online accounts and other online services, and from partners.",
          "modified": "2025-06-06T11:00:56.776000",
          "created": "2025-06-06T11:00:56.776000",
          "tags": [],
          "references": [
            "https://humansecurity.com/learn/blog/satori-threat-intelligence-disruption-badbox-2-0/"
          ],
          "public": 1,
          "adversary": "Lemon",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 110,
            "hostname": 1
          },
          "indicator_count": 111,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 864,
          "modified_text": "361 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6762dbde3930a74843860f4c",
          "name": "BADBOX Botnet Is Back | Bitsight",
          "description": "Find out more about Bitsight, a leading cyber risk management company, on the web, at www.btsight.com and on our app and Facebook page, and here are the highlights.",
          "modified": "2025-01-17T11:00:16.991000",
          "created": "2024-12-18T14:27:42.647000",
          "tags": [
            "badbox",
            "android tv",
            "russia",
            "badbox malware",
            "yndx smart",
            "android",
            "china",
            "belarus",
            "bitsight",
            "amazon",
            "triada",
            "april",
            "guerrilla",
            "first",
            "ukraine",
            "peachpit",
            "c2"
          ],
          "references": [
            "https://www.bitsight.com/blog/badbox-botnet-back"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Germany",
            "Saudi Arabia",
            "Kazakhstan",
            "Czechia",
            "United States of America",
            "France",
            "Netherlands",
            "Russian Federation",
            "China"
          ],
          "malware_families": [
            {
              "id": "PEACHPIT",
              "display_name": "PEACHPIT",
              "target": null
            },
            {
              "id": "Bitsight",
              "display_name": "Bitsight",
              "target": null
            },
            {
              "id": "C2",
              "display_name": "C2",
              "target": null
            },
            {
              "id": "BADBOX",
              "display_name": "BADBOX",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1195",
              "name": "Supply Chain Compromise",
              "display_name": "T1195 - Supply Chain Compromise"
            },
            {
              "id": "T1495",
              "name": "Firmware Corruption",
              "display_name": "T1495 - Firmware Corruption"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "URL": 2,
            "domain": 27,
            "hostname": 4
          },
          "indicator_count": 35,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "501 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "https://www.bitsight.com/blog/badbox-botnet-back",
        "https://humansecurity.com/learn/blog/satori-threat-intelligence-disruption-badbox-2-0/",
        "https://threatfox.abuse.ch/export/csv/recent/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Lemon"
          ],
          "malware_families": [
            "Badbox",
            "C2",
            "Peachpit",
            "Bitsight"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "672f6ed2b564f00b7c5cb13f",
      "name": "Threatfox Recent Additions",
      "description": "",
      "modified": "2025-06-13T19:00:02.811000",
      "created": "2024-11-09T14:16:50.032000",
      "tags": [],
      "references": [
        "",
        "https://threatfox.abuse.ch/export/csv/recent/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 96,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "ameermane",
        "id": "77501",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 47587,
        "URL": 18714,
        "FileHash-SHA256": 36311,
        "FileHash-MD5": 1630,
        "FileHash-SHA1": 418,
        "hostname": 18190
      },
      "indicator_count": 122850,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 144,
      "modified_text": "354 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6842ca684b5413baf27aa136",
      "name": "Satori Threat Intelligence Disruption: BADBOX 2.0 Targets Consumer Devices with Multiple Fraud Schemes - HUMAN Security",
      "description": "Learn more about HUMAN, the artificial intelligence company designed to prevent bot attacks and fraud on ad tech platforms and digital publishers, from exploiting customers' valuable online accounts and other online services, and from partners.",
      "modified": "2025-06-06T11:00:56.776000",
      "created": "2025-06-06T11:00:56.776000",
      "tags": [],
      "references": [
        "https://humansecurity.com/learn/blog/satori-threat-intelligence-disruption-badbox-2-0/"
      ],
      "public": 1,
      "adversary": "Lemon",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 110,
        "hostname": 1
      },
      "indicator_count": 111,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 864,
      "modified_text": "361 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6762dbde3930a74843860f4c",
      "name": "BADBOX Botnet Is Back | Bitsight",
      "description": "Find out more about Bitsight, a leading cyber risk management company, on the web, at www.btsight.com and on our app and Facebook page, and here are the highlights.",
      "modified": "2025-01-17T11:00:16.991000",
      "created": "2024-12-18T14:27:42.647000",
      "tags": [
        "badbox",
        "android tv",
        "russia",
        "badbox malware",
        "yndx smart",
        "android",
        "china",
        "belarus",
        "bitsight",
        "amazon",
        "triada",
        "april",
        "guerrilla",
        "first",
        "ukraine",
        "peachpit",
        "c2"
      ],
      "references": [
        "https://www.bitsight.com/blog/badbox-botnet-back"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Germany",
        "Saudi Arabia",
        "Kazakhstan",
        "Czechia",
        "United States of America",
        "France",
        "Netherlands",
        "Russian Federation",
        "China"
      ],
      "malware_families": [
        {
          "id": "PEACHPIT",
          "display_name": "PEACHPIT",
          "target": null
        },
        {
          "id": "Bitsight",
          "display_name": "Bitsight",
          "target": null
        },
        {
          "id": "C2",
          "display_name": "C2",
          "target": null
        },
        {
          "id": "BADBOX",
          "display_name": "BADBOX",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1195",
          "name": "Supply Chain Compromise",
          "display_name": "T1195 - Supply Chain Compromise"
        },
        {
          "id": "T1495",
          "name": "Firmware Corruption",
          "display_name": "T1495 - Firmware Corruption"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "URL": 2,
        "domain": 27,
        "hostname": 4
      },
      "indicator_count": 35,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 863,
      "modified_text": "501 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "pcxrl.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "pcxrl.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780452920.9579403
}