{
  "type": "Domain",
  "indicator": "pdfobject.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/pdfobject.com",
    "alexa": "http://www.alexa.com/siteinfo/pdfobject.com",
    "indicator": "pdfobject.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3969958150,
      "indicator": "pdfobject.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "6a1bbf37e377ccaa110200e0",
          "name": "VirusTotal report\n                    for Papers_Please_APK_1_4_12.apk",
          "description": "[domain named \"homedepot.com\" has been banned by the internet service provider, Akama.net, for violating its rules on server transfer and deletion.. and the use of these terms.]  #barcodes",
          "modified": "2026-05-31T05:26:32.684000",
          "created": "2026-05-31T04:55:19.811000",
          "tags": [
            "as16625 akamai",
            "united",
            "as20940",
            "whitelisted",
            "united kingdom",
            "status",
            "servers",
            "a span",
            "name servers",
            "as3491 pccw",
            "date",
            "meta",
            "service",
            "path",
            "registrar abuse",
            "iana id",
            "contact phone",
            "domain status",
            "registrar url",
            "registrar whois",
            "server",
            "registrar",
            "csc corporate",
            "domains",
            "ferry road",
            "thumbprint",
            "algorithm",
            "full name",
            "v3 serial",
            "number",
            "issuer",
            "cus cndigicert",
            "ecc extended",
            "ca odigicert",
            "validity",
            "latlanta othe",
            "has permission",
            "file type",
            "sim provider",
            "mccmnc",
            "mobile",
            "iso country",
            "found",
            "t1417 input",
            "attack network",
            "info dropped",
            "loads",
            "persistence",
            "defense evasion",
            "malicious",
            "status valid",
            "issuer apple",
            "valid from",
            "valid",
            "serial number",
            "smv text",
            "ascii text",
            "cname",
            "key identifier",
            "x509v3 subject",
            "cus odigicert",
            "inc cndigicert",
            "global g3",
            "tls ecc",
            "organization",
            "dnssec",
            "domain name",
            "us registrant",
            "email",
            "contact",
            "macintosh disk",
            "image",
            "apple driver",
            "barcodes",
            "past barcode history 2023"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/64f04c6372d51323b3e9f6bdabf6f527513cbadf768b6e8a5301c1de1b168600_Zenbox%20android.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780202779&Signature=ZMlo%2Fyn5T4vPFNHF3XHVPIg82DVy8Q8bOKosyfxCm%2B0GKl64XZeMnYCqVW%2FZBPyZoGNk5dDbl6%2BDs0d76HzIX2YfSzuXsthugznxtiIV8X6rCxyXfC8q%2BTDTeEghlkBpNqLlmIBTljL%2BLG4nD7QUe5K%2F4%2Bhyg%2F7loJbK9LG2iybJRVImxSY7rB4HfbiDpjIav6y9%2BoTwehrf5FMM8D2DtgeoRL%2BMkzDYzyDS%2"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "United Kingdom of Great Britain and Northern Ireland",
            "Taiwan",
            "Korea, Republic of"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1406",
              "name": "Obfuscated Files or Information",
              "display_name": "T1406 - Obfuscated Files or Information"
            },
            {
              "id": "T1409",
              "name": "Access Stored Application Data",
              "display_name": "T1409 - Access Stored Application Data"
            },
            {
              "id": "T1417",
              "name": "Input Capture",
              "display_name": "T1417 - Input Capture"
            },
            {
              "id": "T1418",
              "name": "Application Discovery",
              "display_name": "T1418 - Application Discovery"
            },
            {
              "id": "T1421",
              "name": "System Network Connections Discovery",
              "display_name": "T1421 - System Network Connections Discovery"
            },
            {
              "id": "T1422",
              "name": "System Network Configuration Discovery",
              "display_name": "T1422 - System Network Configuration Discovery"
            },
            {
              "id": "T1424",
              "name": "Process Discovery",
              "display_name": "T1424 - Process Discovery"
            },
            {
              "id": "T1426",
              "name": "System Information Discovery",
              "display_name": "T1426 - System Information Discovery"
            },
            {
              "id": "T1430",
              "name": "Location Tracking",
              "display_name": "T1430 - Location Tracking"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 516,
            "URL": 285,
            "domain": 31,
            "email": 4,
            "hostname": 128,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 19,
            "FileHash-SHA256": 16,
            "Mutex": 1
          },
          "indicator_count": 1006,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "13 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1bbf3891b8d5e7f5fda895",
          "name": "VirusTotal report\n                    for Papers_Please_APK_1_4_12.apk",
          "description": "[domain named \"homedepot.com\" has been banned by the internet service provider, Akama.net, for violating its rules on server transfer and deletion.. and the use of these terms.]  #barcodes",
          "modified": "2026-05-31T05:26:32.273000",
          "created": "2026-05-31T04:55:20.446000",
          "tags": [
            "as16625 akamai",
            "united",
            "as20940",
            "whitelisted",
            "united kingdom",
            "status",
            "servers",
            "a span",
            "name servers",
            "as3491 pccw",
            "date",
            "meta",
            "service",
            "path",
            "registrar abuse",
            "iana id",
            "contact phone",
            "domain status",
            "registrar url",
            "registrar whois",
            "server",
            "registrar",
            "csc corporate",
            "domains",
            "ferry road",
            "thumbprint",
            "algorithm",
            "full name",
            "v3 serial",
            "number",
            "issuer",
            "cus cndigicert",
            "ecc extended",
            "ca odigicert",
            "validity",
            "latlanta othe",
            "has permission",
            "file type",
            "sim provider",
            "mccmnc",
            "mobile",
            "iso country",
            "found",
            "t1417 input",
            "attack network",
            "info dropped",
            "loads",
            "persistence",
            "defense evasion",
            "malicious",
            "status valid",
            "issuer apple",
            "valid from",
            "valid",
            "serial number",
            "smv text",
            "ascii text",
            "cname",
            "key identifier",
            "x509v3 subject",
            "cus odigicert",
            "inc cndigicert",
            "global g3",
            "tls ecc",
            "organization",
            "dnssec",
            "domain name",
            "us registrant",
            "email",
            "contact",
            "macintosh disk",
            "image",
            "apple driver",
            "barcodes",
            "past barcode history 2023"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/64f04c6372d51323b3e9f6bdabf6f527513cbadf768b6e8a5301c1de1b168600_Zenbox%20android.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780202779&Signature=ZMlo%2Fyn5T4vPFNHF3XHVPIg82DVy8Q8bOKosyfxCm%2B0GKl64XZeMnYCqVW%2FZBPyZoGNk5dDbl6%2BDs0d76HzIX2YfSzuXsthugznxtiIV8X6rCxyXfC8q%2BTDTeEghlkBpNqLlmIBTljL%2BLG4nD7QUe5K%2F4%2Bhyg%2F7loJbK9LG2iybJRVImxSY7rB4HfbiDpjIav6y9%2BoTwehrf5FMM8D2DtgeoRL%2BMkzDYzyDS%2"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "United Kingdom of Great Britain and Northern Ireland",
            "Taiwan",
            "Korea, Republic of"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1406",
              "name": "Obfuscated Files or Information",
              "display_name": "T1406 - Obfuscated Files or Information"
            },
            {
              "id": "T1409",
              "name": "Access Stored Application Data",
              "display_name": "T1409 - Access Stored Application Data"
            },
            {
              "id": "T1417",
              "name": "Input Capture",
              "display_name": "T1417 - Input Capture"
            },
            {
              "id": "T1418",
              "name": "Application Discovery",
              "display_name": "T1418 - Application Discovery"
            },
            {
              "id": "T1421",
              "name": "System Network Connections Discovery",
              "display_name": "T1421 - System Network Connections Discovery"
            },
            {
              "id": "T1422",
              "name": "System Network Configuration Discovery",
              "display_name": "T1422 - System Network Configuration Discovery"
            },
            {
              "id": "T1424",
              "name": "Process Discovery",
              "display_name": "T1424 - Process Discovery"
            },
            {
              "id": "T1426",
              "name": "System Information Discovery",
              "display_name": "T1426 - System Information Discovery"
            },
            {
              "id": "T1430",
              "name": "Location Tracking",
              "display_name": "T1430 - Location Tracking"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 516,
            "URL": 285,
            "domain": 31,
            "email": 4,
            "hostname": 128,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 19,
            "FileHash-SHA256": 16,
            "Mutex": 1
          },
          "indicator_count": 1006,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "13 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a01e30169f50d6baa7e86cf",
          "name": "Invite to Bid Campaign Credit ThreatForceOne [clone]",
          "description": "",
          "modified": "2026-05-12T06:39:52.164000",
          "created": "2026-05-11T14:09:05.057000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6a01de1b0e8d9c5a1637650c",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 4,
            "URL": 10,
            "domain": 74,
            "FileHash-SHA1": 2,
            "hostname": 3,
            "FileHash-SHA256": 10
          },
          "indicator_count": 103,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "19 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a01de1c6f83f9f73ce518e3",
          "name": "Invite To Bid Phishing Campaign",
          "description": "Phishing campaign targeting AEC/Construction firms.",
          "modified": "2026-05-11T13:48:10.106000",
          "created": "2026-05-11T13:48:10.106000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ThreatForceOne",
            "id": "385041",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 4,
            "URL": 2,
            "domain": 3
          },
          "indicator_count": 9,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 12,
          "modified_text": "20 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "683e4307a059dee6d1ade4ed",
          "name": "lumma",
          "description": "",
          "modified": "2026-01-04T22:52:50.774000",
          "created": "2025-06-03T00:34:15.050000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 31,
            "FileHash-SHA1": 22,
            "FileHash-SHA256": 90,
            "URL": 550,
            "domain": 380,
            "hostname": 33
          },
          "indicator_count": 1106,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 182,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6774e823196d078c848ed0e7",
          "name": "Threat Intel Report - W52-2024",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2025-01-31T06:04:58.629000",
          "created": "2025-01-01T07:00:51.580000",
          "tags": [
            "mozi",
            "germany",
            "united kingdom",
            "asyncrat link",
            "russia",
            "brazil",
            "quakbot",
            "singapore",
            "week",
            "asyncrat",
            "ukraine",
            "mexico",
            "indonesia",
            "emmenhtal",
            "amadey",
            "play ransomware",
            "malware",
            "date",
            "paraguay",
            "slovakia",
            "first",
            "cryptbot",
            "lumma stealer",
            "alliance",
            "june",
            "android",
            "powershell"
          ],
          "references": [
            "https://any.run/malware-trends/",
            "https://urlhaus.abuse.ch/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 70,
            "hostname": 92,
            "URL": 223,
            "CVE": 1,
            "FileHash-MD5": 12,
            "FileHash-SHA1": 12,
            "FileHash-SHA256": 16
          },
          "indicator_count": 426,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 106,
          "modified_text": "485 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/64f04c6372d51323b3e9f6bdabf6f527513cbadf768b6e8a5301c1de1b168600_Zenbox%20android.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780202779&Signature=ZMlo%2Fyn5T4vPFNHF3XHVPIg82DVy8Q8bOKosyfxCm%2B0GKl64XZeMnYCqVW%2FZBPyZoGNk5dDbl6%2BDs0d76HzIX2YfSzuXsthugznxtiIV8X6rCxyXfC8q%2BTDTeEghlkBpNqLlmIBTljL%2BLG4nD7QUe5K%2F4%2Bhyg%2F7loJbK9LG2iybJRVImxSY7rB4HfbiDpjIav6y9%2BoTwehrf5FMM8D2DtgeoRL%2BMkzDYzyDS%2",
        "https://urlhaus.abuse.ch/",
        "https://any.run/malware-trends/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "6a1bbf37e377ccaa110200e0",
      "name": "VirusTotal report\n                    for Papers_Please_APK_1_4_12.apk",
      "description": "[domain named \"homedepot.com\" has been banned by the internet service provider, Akama.net, for violating its rules on server transfer and deletion.. and the use of these terms.]  #barcodes",
      "modified": "2026-05-31T05:26:32.684000",
      "created": "2026-05-31T04:55:19.811000",
      "tags": [
        "as16625 akamai",
        "united",
        "as20940",
        "whitelisted",
        "united kingdom",
        "status",
        "servers",
        "a span",
        "name servers",
        "as3491 pccw",
        "date",
        "meta",
        "service",
        "path",
        "registrar abuse",
        "iana id",
        "contact phone",
        "domain status",
        "registrar url",
        "registrar whois",
        "server",
        "registrar",
        "csc corporate",
        "domains",
        "ferry road",
        "thumbprint",
        "algorithm",
        "full name",
        "v3 serial",
        "number",
        "issuer",
        "cus cndigicert",
        "ecc extended",
        "ca odigicert",
        "validity",
        "latlanta othe",
        "has permission",
        "file type",
        "sim provider",
        "mccmnc",
        "mobile",
        "iso country",
        "found",
        "t1417 input",
        "attack network",
        "info dropped",
        "loads",
        "persistence",
        "defense evasion",
        "malicious",
        "status valid",
        "issuer apple",
        "valid from",
        "valid",
        "serial number",
        "smv text",
        "ascii text",
        "cname",
        "key identifier",
        "x509v3 subject",
        "cus odigicert",
        "inc cndigicert",
        "global g3",
        "tls ecc",
        "organization",
        "dnssec",
        "domain name",
        "us registrant",
        "email",
        "contact",
        "macintosh disk",
        "image",
        "apple driver",
        "barcodes",
        "past barcode history 2023"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/64f04c6372d51323b3e9f6bdabf6f527513cbadf768b6e8a5301c1de1b168600_Zenbox%20android.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780202779&Signature=ZMlo%2Fyn5T4vPFNHF3XHVPIg82DVy8Q8bOKosyfxCm%2B0GKl64XZeMnYCqVW%2FZBPyZoGNk5dDbl6%2BDs0d76HzIX2YfSzuXsthugznxtiIV8X6rCxyXfC8q%2BTDTeEghlkBpNqLlmIBTljL%2BLG4nD7QUe5K%2F4%2Bhyg%2F7loJbK9LG2iybJRVImxSY7rB4HfbiDpjIav6y9%2BoTwehrf5FMM8D2DtgeoRL%2BMkzDYzyDS%2"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "United Kingdom of Great Britain and Northern Ireland",
        "Taiwan",
        "Korea, Republic of"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1406",
          "name": "Obfuscated Files or Information",
          "display_name": "T1406 - Obfuscated Files or Information"
        },
        {
          "id": "T1409",
          "name": "Access Stored Application Data",
          "display_name": "T1409 - Access Stored Application Data"
        },
        {
          "id": "T1417",
          "name": "Input Capture",
          "display_name": "T1417 - Input Capture"
        },
        {
          "id": "T1418",
          "name": "Application Discovery",
          "display_name": "T1418 - Application Discovery"
        },
        {
          "id": "T1421",
          "name": "System Network Connections Discovery",
          "display_name": "T1421 - System Network Connections Discovery"
        },
        {
          "id": "T1422",
          "name": "System Network Configuration Discovery",
          "display_name": "T1422 - System Network Configuration Discovery"
        },
        {
          "id": "T1424",
          "name": "Process Discovery",
          "display_name": "T1424 - Process Discovery"
        },
        {
          "id": "T1426",
          "name": "System Information Discovery",
          "display_name": "T1426 - System Information Discovery"
        },
        {
          "id": "T1430",
          "name": "Location Tracking",
          "display_name": "T1430 - Location Tracking"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 516,
        "URL": 285,
        "domain": 31,
        "email": 4,
        "hostname": 128,
        "FileHash-MD5": 6,
        "FileHash-SHA1": 19,
        "FileHash-SHA256": 16,
        "Mutex": 1
      },
      "indicator_count": 1006,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "13 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1bbf3891b8d5e7f5fda895",
      "name": "VirusTotal report\n                    for Papers_Please_APK_1_4_12.apk",
      "description": "[domain named \"homedepot.com\" has been banned by the internet service provider, Akama.net, for violating its rules on server transfer and deletion.. and the use of these terms.]  #barcodes",
      "modified": "2026-05-31T05:26:32.273000",
      "created": "2026-05-31T04:55:20.446000",
      "tags": [
        "as16625 akamai",
        "united",
        "as20940",
        "whitelisted",
        "united kingdom",
        "status",
        "servers",
        "a span",
        "name servers",
        "as3491 pccw",
        "date",
        "meta",
        "service",
        "path",
        "registrar abuse",
        "iana id",
        "contact phone",
        "domain status",
        "registrar url",
        "registrar whois",
        "server",
        "registrar",
        "csc corporate",
        "domains",
        "ferry road",
        "thumbprint",
        "algorithm",
        "full name",
        "v3 serial",
        "number",
        "issuer",
        "cus cndigicert",
        "ecc extended",
        "ca odigicert",
        "validity",
        "latlanta othe",
        "has permission",
        "file type",
        "sim provider",
        "mccmnc",
        "mobile",
        "iso country",
        "found",
        "t1417 input",
        "attack network",
        "info dropped",
        "loads",
        "persistence",
        "defense evasion",
        "malicious",
        "status valid",
        "issuer apple",
        "valid from",
        "valid",
        "serial number",
        "smv text",
        "ascii text",
        "cname",
        "key identifier",
        "x509v3 subject",
        "cus odigicert",
        "inc cndigicert",
        "global g3",
        "tls ecc",
        "organization",
        "dnssec",
        "domain name",
        "us registrant",
        "email",
        "contact",
        "macintosh disk",
        "image",
        "apple driver",
        "barcodes",
        "past barcode history 2023"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/64f04c6372d51323b3e9f6bdabf6f527513cbadf768b6e8a5301c1de1b168600_Zenbox%20android.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780202779&Signature=ZMlo%2Fyn5T4vPFNHF3XHVPIg82DVy8Q8bOKosyfxCm%2B0GKl64XZeMnYCqVW%2FZBPyZoGNk5dDbl6%2BDs0d76HzIX2YfSzuXsthugznxtiIV8X6rCxyXfC8q%2BTDTeEghlkBpNqLlmIBTljL%2BLG4nD7QUe5K%2F4%2Bhyg%2F7loJbK9LG2iybJRVImxSY7rB4HfbiDpjIav6y9%2BoTwehrf5FMM8D2DtgeoRL%2BMkzDYzyDS%2"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "United Kingdom of Great Britain and Northern Ireland",
        "Taiwan",
        "Korea, Republic of"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1406",
          "name": "Obfuscated Files or Information",
          "display_name": "T1406 - Obfuscated Files or Information"
        },
        {
          "id": "T1409",
          "name": "Access Stored Application Data",
          "display_name": "T1409 - Access Stored Application Data"
        },
        {
          "id": "T1417",
          "name": "Input Capture",
          "display_name": "T1417 - Input Capture"
        },
        {
          "id": "T1418",
          "name": "Application Discovery",
          "display_name": "T1418 - Application Discovery"
        },
        {
          "id": "T1421",
          "name": "System Network Connections Discovery",
          "display_name": "T1421 - System Network Connections Discovery"
        },
        {
          "id": "T1422",
          "name": "System Network Configuration Discovery",
          "display_name": "T1422 - System Network Configuration Discovery"
        },
        {
          "id": "T1424",
          "name": "Process Discovery",
          "display_name": "T1424 - Process Discovery"
        },
        {
          "id": "T1426",
          "name": "System Information Discovery",
          "display_name": "T1426 - System Information Discovery"
        },
        {
          "id": "T1430",
          "name": "Location Tracking",
          "display_name": "T1430 - Location Tracking"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 516,
        "URL": 285,
        "domain": 31,
        "email": 4,
        "hostname": 128,
        "FileHash-MD5": 6,
        "FileHash-SHA1": 19,
        "FileHash-SHA256": 16,
        "Mutex": 1
      },
      "indicator_count": 1006,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "13 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a01e30169f50d6baa7e86cf",
      "name": "Invite to Bid Campaign Credit ThreatForceOne [clone]",
      "description": "",
      "modified": "2026-05-12T06:39:52.164000",
      "created": "2026-05-11T14:09:05.057000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6a01de1b0e8d9c5a1637650c",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 4,
        "URL": 10,
        "domain": 74,
        "FileHash-SHA1": 2,
        "hostname": 3,
        "FileHash-SHA256": 10
      },
      "indicator_count": 103,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "19 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a01de1c6f83f9f73ce518e3",
      "name": "Invite To Bid Phishing Campaign",
      "description": "Phishing campaign targeting AEC/Construction firms.",
      "modified": "2026-05-11T13:48:10.106000",
      "created": "2026-05-11T13:48:10.106000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "ThreatForceOne",
        "id": "385041",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 4,
        "URL": 2,
        "domain": 3
      },
      "indicator_count": 9,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 12,
      "modified_text": "20 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "683e4307a059dee6d1ade4ed",
      "name": "lumma",
      "description": "",
      "modified": "2026-01-04T22:52:50.774000",
      "created": "2025-06-03T00:34:15.050000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 31,
        "FileHash-SHA1": 22,
        "FileHash-SHA256": 90,
        "URL": 550,
        "domain": 380,
        "hostname": 33
      },
      "indicator_count": 1106,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 182,
      "modified_text": "146 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6774e823196d078c848ed0e7",
      "name": "Threat Intel Report - W52-2024",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2025-01-31T06:04:58.629000",
      "created": "2025-01-01T07:00:51.580000",
      "tags": [
        "mozi",
        "germany",
        "united kingdom",
        "asyncrat link",
        "russia",
        "brazil",
        "quakbot",
        "singapore",
        "week",
        "asyncrat",
        "ukraine",
        "mexico",
        "indonesia",
        "emmenhtal",
        "amadey",
        "play ransomware",
        "malware",
        "date",
        "paraguay",
        "slovakia",
        "first",
        "cryptbot",
        "lumma stealer",
        "alliance",
        "june",
        "android",
        "powershell"
      ],
      "references": [
        "https://any.run/malware-trends/",
        "https://urlhaus.abuse.ch/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 70,
        "hostname": 92,
        "URL": 223,
        "CVE": 1,
        "FileHash-MD5": 12,
        "FileHash-SHA1": 12,
        "FileHash-SHA256": 16
      },
      "indicator_count": 426,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 106,
      "modified_text": "485 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "pdfobject.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "pdfobject.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780254861.6413743
}