{
  "type": "Domain",
  "indicator": "pod.link",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/pod.link",
    "alexa": "http://www.alexa.com/siteinfo/pod.link",
    "indicator": "pod.link",
    "type": "domain",
    "type_title": "Domain",
    "validation": [
      {
        "source": "majestic",
        "message": "Whitelisted domain pod.link",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3633012351,
      "indicator": "pod.link",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "68bc8015944465ffa1c03148",
          "name": "Security Affairs affecting Critical Infrastructure",
          "description": "Security affairs.com found in a State Policy & Financing website research due to social engineering &  insurance policies hacking scheme. \u2022 SecurityAffairs.com statement: The website specializes in cybersecurity and its related fields, providing insights into current threats and trends. \nContent:\nIt features news articles, investigative reports, and analyses from experts in the field. \nTopics:\nContent often includes discussions on:\ncybercrime,\ncybersecurity trends ,\nintelligence and geopolitics,\nemerging threats. (I can\u2019t verify because idk).\n\n(Auto populated: 335,923 out of 489,337 Fortinet firewalls vulnerable to CVE-2023-27997)\nAdversary auto populated: Suggested Adversaries:\nMember Ad-Hoc Working ADVERSARIES Group on Cyber Threat Landscapes, Ethical Hacker, Security Evangelist",
          "modified": "2025-10-06T18:03:15.359000",
          "created": "2025-09-06T18:40:21.276000",
          "tags": [
            "script urls",
            "security",
            "script domains",
            "ip address",
            "meta",
            "stealth window",
            "reads_self",
            "creates_largekey",
            "dynamic_function_loading",
            "script_created_process",
            "antivm_generic_disk",
            "ids",
            "infostealer_cookies",
            "infostealer_keylog",
            "custom malware",
            "suspicious_command_tools",
            "antisandbox_mouse_hook",
            "dynamicloader",
            "tlsv1",
            "ogoogle trust",
            "cngts ca",
            "tls handshake",
            "failure",
            "united",
            "high",
            "search",
            "write",
            "malware",
            "unknown",
            "extraction",
            "data upload",
            "extraction data",
            "enter soudae",
            "hdi ad",
            "temdac c",
            "extri",
            "include review",
            "trojandropper",
            "mtb jun",
            "passive dns",
            "files",
            "location united",
            "twitter",
            "exploit",
            "delete c",
            "intel",
            "ms windows",
            "medium",
            "pe32",
            "port",
            "destination",
            "present sep",
            "a domains",
            "creation date",
            "error",
            "title",
            "android",
            "known exploited",
            "google",
            "salesloft drift",
            "qantas",
            "july",
            "meetc2",
            "c2 framework",
            "google calendar",
            "apis",
            "critical",
            "rokrat",
            "windows",
            "tags none",
            "file type",
            "virustotal api",
            "screenshots",
            "comments",
            "learn",
            "suspicious",
            "informative",
            "adversaries",
            "ck id",
            "name tactics",
            "command",
            "defense evasion",
            "spawns",
            "t1590 gather",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "additional info",
            "yara signature",
            "unicode text",
            "utf8 text",
            "idat",
            "style",
            "defs",
            "command decode",
            "strings",
            "yxgbc",
            "core",
            "flag",
            "date",
            "markmonitor",
            "server",
            "automattic",
            "name server",
            "proxy",
            "llc name",
            "windir",
            "pattern match",
            "mitre att",
            "show technique",
            "ck matrix",
            "sha1",
            "show process",
            "hybrid",
            "general",
            "local",
            "path",
            "encrypt",
            "form",
            "iframe",
            "click",
            "server response",
            "google safe",
            "results aug",
            "affairs",
            "founder",
            "cybhorus",
            "cybaze",
            "member adhoc",
            "working group",
            "cyber threat",
            "landscapes",
            "ethical hacker",
            "hoc working",
            "ssl certificate",
            "initial access",
            "href",
            "ascii text"
          ],
          "references": [
            "https://securityaffairs.com/",
            "/181480/cyber-crime/iot-under-siege-the-return-of-the-mirai-based-gayfemboy-botnet.html",
            "https://securityaffairs.com/106770/deep-web/ubereats-data-leaked-dark-web.html",
            "https://securityaffairs.com/107190/data-breach/sodinokibi-ransomware-brown-forman.html",
            "https://securityaffairs.com/115693/apt/chinese-hackers-5g.html",
            "https://securityaffairs.com/109224/data-breach/food-delivery-service-chowbus-hack.html",
            "https://securityaffairs.com/112637/cyber-crime/the-hospital-group-revil.html",
            "https://securityaffairs.com/139472/data-breach/commonspirit-data-breach-623k-patients.html",
            "https://securityaffairs.com/148110/hackinq/fortinet-fortios-vulnerable-devices-online.html",
            "https://securityaffairs.com/148110/hackinq/fortinet-fortios-vulnerable-devices-online.html",
            "Multiple other undocumented malware"
          ],
          "public": 1,
          "adversary": "Hoc Working",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "!#AddsCopyToStartup",
              "display_name": "!#AddsCopyToStartup",
              "target": null
            },
            {
              "id": "!#LowFiWriteMZInUnusualExtension",
              "display_name": "!#LowFiWriteMZInUnusualExtension",
              "target": null
            },
            {
              "id": "Trojan:Win32/QQpass",
              "display_name": "Trojan:Win32/QQpass",
              "target": "/malware/Trojan:Win32/QQpass"
            },
            {
              "id": "\"prepending (enc) ransomware\" (Not an official name)",
              "display_name": "\"prepending (enc) ransomware\" (Not an official name)",
              "target": null
            },
            {
              "id": ".A ,  ALF:HeraklezEval:PWS:Win32/Ldpinch!rfn",
              "display_name": ".A ,  ALF:HeraklezEval:PWS:Win32/Ldpinch!rfn",
              "target": null
            },
            {
              "id": "PWS:Win32/Ymacco.AA50",
              "display_name": "PWS:Win32/Ymacco.AA50",
              "target": "/malware/PWS:Win32/Ymacco.AA50"
            },
            {
              "id": "ALF:HeraklezEval:Trojan:Win32/Salgorea!rfn",
              "display_name": "ALF:HeraklezEval:Trojan:Win32/Salgorea!rfn",
              "target": null
            },
            {
              "id": "CVE-2025-42957",
              "display_name": "CVE-2025-42957",
              "target": null
            },
            {
              "id": "CVE-2023-27997",
              "display_name": "CVE-2023-27997",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Government",
            "Manufacturing",
            "Critical Infrastructure"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 187,
            "FileHash-SHA1": 152,
            "FileHash-SHA256": 1140,
            "URL": 1258,
            "domain": 237,
            "email": 1,
            "hostname": 470,
            "SSLCertFingerprint": 17,
            "CVE": 3
          },
          "indicator_count": 3465,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 144,
          "modified_text": "237 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63eabe6f6a9aaa48a17d66e0",
          "name": "Google Chrome",
          "description": "Google has released a version of its operating system that stops automatically checking for security updates and instead instead uses the 'cros' tool to automatically install them on to the Google Chrome operating systems, as well as the Android version.",
          "modified": "2023-03-16T00:12:03.978000",
          "created": "2023-02-13T22:49:19.557000",
          "tags": [
            "license",
            "copyright",
            "android open",
            "source project",
            "apache license",
            "version",
            "unless",
            "as is",
            "basis",
            "or conditions",
            "disables",
            "please",
            "google",
            "private key",
            "software",
            "work",
            "licensor",
            "a particular",
            "direct",
            "february",
            "generator",
            "david",
            "code",
            "bunny",
            "neither",
            "apache",
            "june",
            "uboot",
            "except",
            "bsd3clause",
            "bsd2clause",
            "library name",
            "link",
            "license name",
            "binaries",
            "qt websockets",
            "tink",
            "qt widgets",
            "unknown",
            "format",
            "branch",
            "any kind"
          ],
          "references": [
            "cros-garcon.conf",
            "source.properties",
            "LICENSE",
            "android-info.txt",
            "android-sdk-preview-license",
            "web.dev.har",
            "NOTICE.csv",
            "android-sdk-license",
            "NOTICE.txt",
            "Downloads.pem",
            "weston.ini",
            "package.xml",
            "mkfs.ext3",
            "mkfs.ext4",
            "mkfs.ext2"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Lillylillith39",
            "id": "221303",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 453,
            "hostname": 81,
            "FileHash-SHA256": 245,
            "domain": 62,
            "email": 7,
            "FileHash-SHA1": 3,
            "YARA": 1
          },
          "indicator_count": 852,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 32,
          "modified_text": "1173 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "mkfs.ext3",
        "package.xml",
        "Multiple other undocumented malware",
        "https://securityaffairs.com/",
        "LICENSE",
        "https://securityaffairs.com/107190/data-breach/sodinokibi-ransomware-brown-forman.html",
        "NOTICE.csv",
        "https://securityaffairs.com/106770/deep-web/ubereats-data-leaked-dark-web.html",
        "https://securityaffairs.com/139472/data-breach/commonspirit-data-breach-623k-patients.html",
        "source.properties",
        "https://securityaffairs.com/148110/hackinq/fortinet-fortios-vulnerable-devices-online.html",
        "cros-garcon.conf",
        "https://securityaffairs.com/109224/data-breach/food-delivery-service-chowbus-hack.html",
        "android-sdk-license",
        "https://securityaffairs.com/112637/cyber-crime/the-hospital-group-revil.html",
        "https://securityaffairs.com/115693/apt/chinese-hackers-5g.html",
        "web.dev.har",
        "mkfs.ext4",
        "android-sdk-preview-license",
        "Downloads.pem",
        "NOTICE.txt",
        "mkfs.ext2",
        "android-info.txt",
        "/181480/cyber-crime/iot-under-siege-the-return-of-the-mirai-based-gayfemboy-botnet.html",
        "weston.ini"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Hoc Working"
          ],
          "malware_families": [
            "\"prepending (enc) ransomware\" (not an official name)",
            "Alf:heraklezeval:trojan:win32/salgorea!rfn",
            "Pws:win32/ymacco.aa50",
            "Trojan:win32/qqpass",
            "!#addscopytostartup",
            "Cve-2023-27997",
            "Cve-2025-42957",
            ".a ,  alf:heraklezeval:pws:win32/ldpinch!rfn",
            "!#lowfiwritemzinunusualextension"
          ],
          "industries": [
            "Critical infrastructure",
            "Government",
            "Manufacturing"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "68bc8015944465ffa1c03148",
      "name": "Security Affairs affecting Critical Infrastructure",
      "description": "Security affairs.com found in a State Policy & Financing website research due to social engineering &  insurance policies hacking scheme. \u2022 SecurityAffairs.com statement: The website specializes in cybersecurity and its related fields, providing insights into current threats and trends. \nContent:\nIt features news articles, investigative reports, and analyses from experts in the field. \nTopics:\nContent often includes discussions on:\ncybercrime,\ncybersecurity trends ,\nintelligence and geopolitics,\nemerging threats. (I can\u2019t verify because idk).\n\n(Auto populated: 335,923 out of 489,337 Fortinet firewalls vulnerable to CVE-2023-27997)\nAdversary auto populated: Suggested Adversaries:\nMember Ad-Hoc Working ADVERSARIES Group on Cyber Threat Landscapes, Ethical Hacker, Security Evangelist",
      "modified": "2025-10-06T18:03:15.359000",
      "created": "2025-09-06T18:40:21.276000",
      "tags": [
        "script urls",
        "security",
        "script domains",
        "ip address",
        "meta",
        "stealth window",
        "reads_self",
        "creates_largekey",
        "dynamic_function_loading",
        "script_created_process",
        "antivm_generic_disk",
        "ids",
        "infostealer_cookies",
        "infostealer_keylog",
        "custom malware",
        "suspicious_command_tools",
        "antisandbox_mouse_hook",
        "dynamicloader",
        "tlsv1",
        "ogoogle trust",
        "cngts ca",
        "tls handshake",
        "failure",
        "united",
        "high",
        "search",
        "write",
        "malware",
        "unknown",
        "extraction",
        "data upload",
        "extraction data",
        "enter soudae",
        "hdi ad",
        "temdac c",
        "extri",
        "include review",
        "trojandropper",
        "mtb jun",
        "passive dns",
        "files",
        "location united",
        "twitter",
        "exploit",
        "delete c",
        "intel",
        "ms windows",
        "medium",
        "pe32",
        "port",
        "destination",
        "present sep",
        "a domains",
        "creation date",
        "error",
        "title",
        "android",
        "known exploited",
        "google",
        "salesloft drift",
        "qantas",
        "july",
        "meetc2",
        "c2 framework",
        "google calendar",
        "apis",
        "critical",
        "rokrat",
        "windows",
        "tags none",
        "file type",
        "virustotal api",
        "screenshots",
        "comments",
        "learn",
        "suspicious",
        "informative",
        "adversaries",
        "ck id",
        "name tactics",
        "command",
        "defense evasion",
        "spawns",
        "t1590 gather",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "additional info",
        "yara signature",
        "unicode text",
        "utf8 text",
        "idat",
        "style",
        "defs",
        "command decode",
        "strings",
        "yxgbc",
        "core",
        "flag",
        "date",
        "markmonitor",
        "server",
        "automattic",
        "name server",
        "proxy",
        "llc name",
        "windir",
        "pattern match",
        "mitre att",
        "show technique",
        "ck matrix",
        "sha1",
        "show process",
        "hybrid",
        "general",
        "local",
        "path",
        "encrypt",
        "form",
        "iframe",
        "click",
        "server response",
        "google safe",
        "results aug",
        "affairs",
        "founder",
        "cybhorus",
        "cybaze",
        "member adhoc",
        "working group",
        "cyber threat",
        "landscapes",
        "ethical hacker",
        "hoc working",
        "ssl certificate",
        "initial access",
        "href",
        "ascii text"
      ],
      "references": [
        "https://securityaffairs.com/",
        "/181480/cyber-crime/iot-under-siege-the-return-of-the-mirai-based-gayfemboy-botnet.html",
        "https://securityaffairs.com/106770/deep-web/ubereats-data-leaked-dark-web.html",
        "https://securityaffairs.com/107190/data-breach/sodinokibi-ransomware-brown-forman.html",
        "https://securityaffairs.com/115693/apt/chinese-hackers-5g.html",
        "https://securityaffairs.com/109224/data-breach/food-delivery-service-chowbus-hack.html",
        "https://securityaffairs.com/112637/cyber-crime/the-hospital-group-revil.html",
        "https://securityaffairs.com/139472/data-breach/commonspirit-data-breach-623k-patients.html",
        "https://securityaffairs.com/148110/hackinq/fortinet-fortios-vulnerable-devices-online.html",
        "https://securityaffairs.com/148110/hackinq/fortinet-fortios-vulnerable-devices-online.html",
        "Multiple other undocumented malware"
      ],
      "public": 1,
      "adversary": "Hoc Working",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "!#AddsCopyToStartup",
          "display_name": "!#AddsCopyToStartup",
          "target": null
        },
        {
          "id": "!#LowFiWriteMZInUnusualExtension",
          "display_name": "!#LowFiWriteMZInUnusualExtension",
          "target": null
        },
        {
          "id": "Trojan:Win32/QQpass",
          "display_name": "Trojan:Win32/QQpass",
          "target": "/malware/Trojan:Win32/QQpass"
        },
        {
          "id": "\"prepending (enc) ransomware\" (Not an official name)",
          "display_name": "\"prepending (enc) ransomware\" (Not an official name)",
          "target": null
        },
        {
          "id": ".A ,  ALF:HeraklezEval:PWS:Win32/Ldpinch!rfn",
          "display_name": ".A ,  ALF:HeraklezEval:PWS:Win32/Ldpinch!rfn",
          "target": null
        },
        {
          "id": "PWS:Win32/Ymacco.AA50",
          "display_name": "PWS:Win32/Ymacco.AA50",
          "target": "/malware/PWS:Win32/Ymacco.AA50"
        },
        {
          "id": "ALF:HeraklezEval:Trojan:Win32/Salgorea!rfn",
          "display_name": "ALF:HeraklezEval:Trojan:Win32/Salgorea!rfn",
          "target": null
        },
        {
          "id": "CVE-2025-42957",
          "display_name": "CVE-2025-42957",
          "target": null
        },
        {
          "id": "CVE-2023-27997",
          "display_name": "CVE-2023-27997",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [
        "Government",
        "Manufacturing",
        "Critical Infrastructure"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 187,
        "FileHash-SHA1": 152,
        "FileHash-SHA256": 1140,
        "URL": 1258,
        "domain": 237,
        "email": 1,
        "hostname": 470,
        "SSLCertFingerprint": 17,
        "CVE": 3
      },
      "indicator_count": 3465,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 144,
      "modified_text": "237 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63eabe6f6a9aaa48a17d66e0",
      "name": "Google Chrome",
      "description": "Google has released a version of its operating system that stops automatically checking for security updates and instead instead uses the 'cros' tool to automatically install them on to the Google Chrome operating systems, as well as the Android version.",
      "modified": "2023-03-16T00:12:03.978000",
      "created": "2023-02-13T22:49:19.557000",
      "tags": [
        "license",
        "copyright",
        "android open",
        "source project",
        "apache license",
        "version",
        "unless",
        "as is",
        "basis",
        "or conditions",
        "disables",
        "please",
        "google",
        "private key",
        "software",
        "work",
        "licensor",
        "a particular",
        "direct",
        "february",
        "generator",
        "david",
        "code",
        "bunny",
        "neither",
        "apache",
        "june",
        "uboot",
        "except",
        "bsd3clause",
        "bsd2clause",
        "library name",
        "link",
        "license name",
        "binaries",
        "qt websockets",
        "tink",
        "qt widgets",
        "unknown",
        "format",
        "branch",
        "any kind"
      ],
      "references": [
        "cros-garcon.conf",
        "source.properties",
        "LICENSE",
        "android-info.txt",
        "android-sdk-preview-license",
        "web.dev.har",
        "NOTICE.csv",
        "android-sdk-license",
        "NOTICE.txt",
        "Downloads.pem",
        "weston.ini",
        "package.xml",
        "mkfs.ext3",
        "mkfs.ext4",
        "mkfs.ext2"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Lillylillith39",
        "id": "221303",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 453,
        "hostname": 81,
        "FileHash-SHA256": 245,
        "domain": 62,
        "email": 7,
        "FileHash-SHA1": 3,
        "YARA": 1
      },
      "indicator_count": 852,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 32,
      "modified_text": "1173 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "pod.link",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "pod.link",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780319957.293562
}