{
  "type": "Domain",
  "indicator": "phsonyf.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/phsonyf.com",
    "alexa": "http://www.alexa.com/siteinfo/phsonyf.com",
    "indicator": "phsonyf.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 1579281531,
      "indicator": "phsonyf.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "5bec53edbc977065131869ff",
          "name": "Mylobot Continues Global Infections",
          "description": "CenturyLink Threat Research Labs has been tracking the Mylobot botnet, a sophisticated malware family that is categorized as a downloader. What makes Mylobot dangerous is its ability to download and execute any type of payload after it infects a host. This means at any time it could download any other type of malware the attacker desires. A detailed walkthrough and reverse engineering analysis of Mylobot was first reported in June by Deep Instinct. During the time we have been monitoring Mylobot we have observed it downloading the Khalesi malware as a second stage to infected hosts. Kaspersky Lab reports that the information stealing Khalesi malware is one of the top downloaded malware families in 2018.",
          "modified": "2019-05-07T11:43:26.115000",
          "created": "2018-11-14T16:57:16.907000",
          "tags": [
            "mylobot"
          ],
          "references": [
            "https://www.netformation.com/our-pov/mylobot-continues-global-infections/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 119,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1411,
            "FileHash-SHA256": 4,
            "URL": 1397
          },
          "indicator_count": 2812,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 387127,
          "modified_text": "2583 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68beb866c8ed898ed0ece438",
          "name": "BlackieVirus . Expanded- Apple",
          "description": "",
          "modified": "2025-10-08T10:00:30.227000",
          "created": "2025-09-08T11:05:10.064000",
          "tags": [
            "present may",
            "present apr",
            "unknown ns",
            "present sep",
            "unknown aaaa",
            "present jun",
            "present dec",
            "passive dns",
            "ip address",
            "virtool",
            "win32cve sep",
            "trojan",
            "mtb sep",
            "ipv4",
            "urls",
            "trojanspy",
            "united states",
            "dynamicloader",
            "ms windows",
            "observed dns",
            "query",
            "windows nt",
            "wow64",
            "khtml",
            "gecko",
            "pe32",
            "write",
            "media",
            "malware",
            "suspicious",
            "learn",
            "ck id",
            "name tactics",
            "informative",
            "command",
            "defense evasion",
            "adversaries",
            "spawns",
            "t1204 user",
            "mitre att",
            "ck matrix",
            "null",
            "error",
            "click",
            "general",
            "local",
            "path",
            "strings",
            "refresh",
            "tools",
            "meta",
            "onload",
            "span",
            "apple",
            "entries",
            "write c",
            "defender",
            "tencent",
            "hostname add",
            "pulse submit",
            "url analysis",
            "present jul",
            "present mar",
            "present oct",
            "saudi arabia",
            "united",
            "present feb",
            "creation date",
            "search",
            "title",
            "date",
            "botnet"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "#VirTool:Win32/Obfuscator.ADB",
              "display_name": "#VirTool:Win32/Obfuscator.ADB",
              "target": "/malware/#VirTool:Win32/Obfuscator.ADB"
            },
            {
              "id": "Win.Trojan.Filerepmalware-10008115-0",
              "display_name": "Win.Trojan.Filerepmalware-10008115-0",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:Ransom:Win32/CVE",
              "display_name": "ALF:HeraklezEval:Ransom:Win32/CVE",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 951,
            "hostname": 1766,
            "URL": 4969,
            "FileHash-MD5": 337,
            "FileHash-SHA1": 317,
            "FileHash-SHA256": 4296,
            "CVE": 1,
            "SSLCertFingerprint": 1,
            "email": 1
          },
          "indicator_count": 12639,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 146,
          "modified_text": "238 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.netformation.com/our-pov/mylobot-continues-global-infections/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "#virtool:win32/obfuscator.adb",
            "Alf:heraklezeval:ransom:win32/cve",
            "Win.trojan.filerepmalware-10008115-0"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "5bec53edbc977065131869ff",
      "name": "Mylobot Continues Global Infections",
      "description": "CenturyLink Threat Research Labs has been tracking the Mylobot botnet, a sophisticated malware family that is categorized as a downloader. What makes Mylobot dangerous is its ability to download and execute any type of payload after it infects a host. This means at any time it could download any other type of malware the attacker desires. A detailed walkthrough and reverse engineering analysis of Mylobot was first reported in June by Deep Instinct. During the time we have been monitoring Mylobot we have observed it downloading the Khalesi malware as a second stage to infected hosts. Kaspersky Lab reports that the information stealing Khalesi malware is one of the top downloaded malware families in 2018.",
      "modified": "2019-05-07T11:43:26.115000",
      "created": "2018-11-14T16:57:16.907000",
      "tags": [
        "mylobot"
      ],
      "references": [
        "https://www.netformation.com/our-pov/mylobot-continues-global-infections/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 119,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1411,
        "FileHash-SHA256": 4,
        "URL": 1397
      },
      "indicator_count": 2812,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 387127,
      "modified_text": "2583 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68beb866c8ed898ed0ece438",
      "name": "BlackieVirus . Expanded- Apple",
      "description": "",
      "modified": "2025-10-08T10:00:30.227000",
      "created": "2025-09-08T11:05:10.064000",
      "tags": [
        "present may",
        "present apr",
        "unknown ns",
        "present sep",
        "unknown aaaa",
        "present jun",
        "present dec",
        "passive dns",
        "ip address",
        "virtool",
        "win32cve sep",
        "trojan",
        "mtb sep",
        "ipv4",
        "urls",
        "trojanspy",
        "united states",
        "dynamicloader",
        "ms windows",
        "observed dns",
        "query",
        "windows nt",
        "wow64",
        "khtml",
        "gecko",
        "pe32",
        "write",
        "media",
        "malware",
        "suspicious",
        "learn",
        "ck id",
        "name tactics",
        "informative",
        "command",
        "defense evasion",
        "adversaries",
        "spawns",
        "t1204 user",
        "mitre att",
        "ck matrix",
        "null",
        "error",
        "click",
        "general",
        "local",
        "path",
        "strings",
        "refresh",
        "tools",
        "meta",
        "onload",
        "span",
        "apple",
        "entries",
        "write c",
        "defender",
        "tencent",
        "hostname add",
        "pulse submit",
        "url analysis",
        "present jul",
        "present mar",
        "present oct",
        "saudi arabia",
        "united",
        "present feb",
        "creation date",
        "search",
        "title",
        "date",
        "botnet"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "#VirTool:Win32/Obfuscator.ADB",
          "display_name": "#VirTool:Win32/Obfuscator.ADB",
          "target": "/malware/#VirTool:Win32/Obfuscator.ADB"
        },
        {
          "id": "Win.Trojan.Filerepmalware-10008115-0",
          "display_name": "Win.Trojan.Filerepmalware-10008115-0",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:Ransom:Win32/CVE",
          "display_name": "ALF:HeraklezEval:Ransom:Win32/CVE",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 951,
        "hostname": 1766,
        "URL": 4969,
        "FileHash-MD5": 337,
        "FileHash-SHA1": 317,
        "FileHash-SHA256": 4296,
        "CVE": 1,
        "SSLCertFingerprint": 1,
        "email": 1
      },
      "indicator_count": 12639,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 146,
      "modified_text": "238 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "phsonyf.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "phsonyf.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780485675.936
}