{
  "type": "Domain",
  "indicator": "qegynuv.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/qegynuv.com",
    "alexa": "http://www.alexa.com/siteinfo/qegynuv.com",
    "indicator": "qegynuv.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 117395772,
      "indicator": "qegynuv.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 21,
      "pulses": [
        {
          "id": "6953775a0aed71947ca3f90e",
          "name": "Ransom WannaCrypt- Hackers masquerade as a law firm | Social Engineering |",
          "description": "Hackers , likely Colorado State employees masquerading as legal, entities, social\nengineering, financial exchanges involved. Fraud. Dangerous enterprise. Found in an \u2018alleged \u2018 Plaintiff Law Firms malicious link discovered in old print out, also seen in earlier pulse. [OTX generated description: Adversaries may be able to evade detection and network filtering by blending in with existing traffic, as well as using web protocols, in order to avoid detection/network filtering. and other measures.]",
          "modified": "2026-01-29T06:09:08.504000",
          "created": "2025-12-30T06:55:22.105000",
          "tags": [
            "united",
            "urls",
            "moved",
            "files",
            "ip address",
            "gmt content",
            "x adblock",
            "encrypt",
            "backdoor",
            "bq dec",
            "virtool",
            "ipv4 add",
            "ascii text",
            "pattern match",
            "ck id",
            "mitre att",
            "meta",
            "general",
            "local",
            "path",
            "click",
            "strings",
            "unknown",
            "simplified",
            "etpro trojan",
            "possible virut",
            "dga nxdomain",
            "responses",
            "virus",
            "medium",
            "virustotal",
            "vipre",
            "baidu",
            "vitro",
            "drweb",
            "mcafee",
            "panda",
            "malware",
            "write",
            "dynamicloader",
            "msie",
            "windows nt",
            "slcc2",
            "media center",
            "yara rule",
            "simda",
            "internal",
            "learn",
            "name tactics",
            "suspicious",
            "informative",
            "command",
            "spawns",
            "defense evasion",
            "t1480 execution",
            "discovery att",
            "ck matrix",
            "network traffic",
            "t1071",
            "t1057",
            "hybrid",
            "yara detections",
            "composite",
            "av detections",
            "ids detections",
            "alerts",
            "analysis date",
            "file score",
            "none related",
            "passive dns",
            "hosting",
            "reverse dns",
            "location united",
            "title",
            "ences s",
            "data upload",
            "extraction",
            "status",
            "hostname add",
            "url analysis",
            "push",
            "present sep",
            "present may",
            "present jul",
            "present jan",
            "win32small dec",
            "ransom",
            "write c",
            "show",
            "search",
            "high",
            "et exploit",
            "probe ms17010",
            "eternal blue",
            "englewood colorado",
            "wannacry",
            "wannacrypt",
            "ransom",
            "wanna"
          ],
          "references": [
            "https://aws.hirecar.net/",
            "w32.virut.cf \u2022 win32.virut.am \u2022 virut.cf \u2022 http://w32.virut.cf \u2022http://w32.virut.cf/ \u2022 https://w32.virut.cf",
            "pandacookie2018.xyz",
            "Antivirus Detections: Win.Ransomware.Wanna-9769986-0 ,  Ransom:Win32/WannaCrypt.H",
            "IDS Detections: Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS",
            "DNS Lookup) Possible ETERNALBLUE Probe MS17-010 (MSF style) Possible ETERNALBLUE Probe MS17-010 (Generic Flags) ETERNALBLUE Probe Vulnerable System Response MS17-010 Possible ETERNALBLUE MS17-010 Heap Spray More Yara Detections WannaCry_Ransomware ,  Win32_Ransomware_WannaCry ,  Wanna_Cry_Ransomware_Generic ,  MS17_010_WanaCry_worm ,  stack_string More Alerts 25 Alerts suspicious_iocontrol_codes persistence_autorun persistence_autorun_tasks stealth_file suricata_alert antivm_generic_disk anomalous_deletefil",
            "Domains Contacted: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com \u2022\u2019survey-smiles.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Backdoor:Win32/Small.IR",
              "display_name": "Backdoor:Win32/Small.IR",
              "target": "/malware/Backdoor:Win32/Small.IR"
            },
            {
              "id": "Win.Trojan.Agent-31853",
              "display_name": "Win.Trojan.Agent-31853",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Win.Ransomware.Wanna-9769986-0",
              "display_name": "Win.Ransomware.Wanna-9769986-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.H",
              "display_name": "Ransom:Win32/WannaCrypt.H",
              "target": "/malware/Ransom:Win32/WannaCrypt.H"
            },
            {
              "id": "Virtool:Win32/Injector.gen!BQ",
              "display_name": "Virtool:Win32/Injector.gen!BQ",
              "target": "/malware/Virtool:Win32/Injector.gen!BQ"
            }
          ],
          "attack_ids": [
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [
            "Government",
            "Technology",
            "Legal"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8605,
            "domain": 1228,
            "email": 2,
            "hostname": 1981,
            "FileHash-SHA256": 1617,
            "FileHash-SHA1": 184,
            "FileHash-MD5": 206,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 13825,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "122 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68705b9e13e074fa3c778902",
          "name": "check",
          "description": "",
          "modified": "2026-01-23T01:10:39.457000",
          "created": "2025-07-11T00:32:30.277000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 421,
            "FileHash-MD5": 25,
            "FileHash-SHA1": 22,
            "FileHash-SHA256": 133,
            "domain": 270,
            "hostname": 35
          },
          "indicator_count": 906,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 182,
          "modified_text": "128 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "688d5bab9ce44c4321064457",
          "name": "xloader",
          "description": "",
          "modified": "2026-01-12T23:06:55.682000",
          "created": "2025-08-02T00:28:27.331000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 388,
            "FileHash-MD5": 83,
            "FileHash-SHA1": 45,
            "FileHash-SHA256": 308,
            "domain": 392,
            "hostname": 107
          },
          "indicator_count": 1323,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 182,
          "modified_text": "139 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69312c4db6fe7eb34abd179d",
          "name": "BeeLineRouter.Net \u2022 Apple \u2022 Worms \u2022 Ransom \u2022 SpyWare",
          "description": "Direct- remotely accesses iOS devices. Same threat actors. Further research warranted.| \n\n#theyswarm #apple #worms #spyware #ransom #quasi",
          "modified": "2026-01-03T05:02:11.376000",
          "created": "2025-12-04T06:38:05.504000",
          "tags": [
            "worm",
            "readme.exe",
            "foto.pif",
            "z1nic.exe",
            "dynamicloader",
            "high",
            "windows",
            "checks",
            "named pipe",
            "http traffic",
            "ids detections",
            "yara detections",
            "alerts",
            "launch",
            "defense evasion",
            "ta0005",
            "files",
            "msie",
            "next dropped",
            "process name",
            "pe32",
            "intel",
            "ms windows",
            "unknown",
            "united",
            "tlsv1",
            "as14618",
            "top source",
            "top destination",
            "port",
            "destination",
            "source source",
            "matches rule",
            "hidden file",
            "extension",
            "connection",
            "http vary",
            "tulach",
            "url https",
            "indicator role",
            "active related",
            "ipv4",
            "url http",
            "macintosh",
            "intel mac",
            "os x",
            "search",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "bq dec",
            "virtool",
            "win32mydoom dec",
            "trojan",
            "win32cve dec",
            "avast avg",
            "mtb dec",
            "crlf line",
            "unicode text",
            "utf8",
            "ee fc",
            "ff d5",
            "yara rule",
            "ascii text",
            "f0 ff",
            "eb e1",
            "write",
            "malware",
            "suspicious",
            "observed dns",
            "query",
            "exploits",
            "sid name",
            "malware cve",
            "exif data",
            "show",
            "value exe",
            "next",
            "all ipv4",
            "pulse pulses",
            "passive dns",
            "urls",
            "reverse dns",
            "location united",
            "america flag",
            "ashburn",
            "status",
            "name servers",
            "ip address",
            "showing",
            "domain",
            "files ip",
            "windows nt",
            "slcc2",
            "media center",
            "medium",
            "simda",
            "internal",
            "local",
            "write c",
            "domain add",
            "ip whois",
            "registrar",
            "hostname",
            "present jul",
            "unknown ns",
            "present dec",
            "music",
            "servers",
            "hostname add",
            "pulse submit",
            "url analysis",
            "aaaa",
            "backdoor",
            "entries",
            "found",
            "next associated",
            "gmt connection",
            "control",
            "content type",
            "twitter",
            "certificate",
            "redirect date",
            "cache",
            "record value",
            "emails",
            "win32",
            "mtb may",
            "invalid url",
            "ransom",
            "trojanspy",
            "msil",
            "akamai",
            "expiration date",
            "body html",
            "present nov",
            "url add",
            "http",
            "files domain",
            "files related",
            "pulses none",
            "related tags",
            "present sep",
            "present oct",
            "flag",
            "analysis tip",
            "click",
            "windir",
            "openurl c",
            "prefetch2",
            "analysis",
            "tor analysis",
            "dns requests",
            "date",
            "domain address",
            "dynadot inc",
            "name server",
            "contacted hosts",
            "process details",
            "network traffic",
            "ck id",
            "show technique",
            "mitre att",
            "ck matrix",
            "t1566",
            "submitted url",
            "t1204",
            "learn",
            "name tactics",
            "informative",
            "adversaries",
            "command",
            "spawns",
            "access att",
            "t1566 phishing",
            "pattern match",
            "show process",
            "t1071",
            "t1057",
            "general",
            "path",
            "brian sabey",
            "christopher p ahmann",
            "quasi",
            "foundry",
            "helix",
            "remote attacks",
            "hit men",
            "sreredrum",
            "pleh"
          ],
          "references": [
            "apple.com \u2022 getsupport.apple.com \u2022",
            "https://www.idvd.eu/?cid=oas-japac-domains-applestore.com.cn/90.i.lolik.anyciona.patrolita.casse.897866 \u2022 oas-japac-domains-applestore.com.cn",
            "http://beelinerouter.net/",
            "Tulach - 114.114.114.114",
            "http://foundry2-lbl.dvr.dn2.n-helix.com",
            "foundry.com \u2022 helix. com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Worm:Win32/Fadok!rfn",
              "display_name": "Worm:Win32/Fadok!rfn",
              "target": "/malware/Worm:Win32/Fadok!rfn"
            },
            {
              "id": "VirTool:Win32/Injector.gen!BQ",
              "display_name": "VirTool:Win32/Injector.gen!BQ",
              "target": "/malware/VirTool:Win32/Injector.gen!BQ"
            },
            {
              "id": "Mydoom",
              "display_name": "Mydoom",
              "target": null
            },
            {
              "id": "Win.Spyware.88778-2",
              "display_name": "Win.Spyware.88778-2",
              "target": null
            },
            {
              "id": "Win.Malware.Delf-10008156-0",
              "display_name": "Win.Malware.Delf-10008156-0",
              "target": null
            },
            {
              "id": "Trojan.MyDoom/Muldrop",
              "display_name": "Trojan.MyDoom/Muldrop",
              "target": null
            },
            {
              "id": "VirTool:Win32/Obfuscator",
              "display_name": "VirTool:Win32/Obfuscator",
              "target": "/malware/VirTool:Win32/Obfuscator"
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1578",
              "name": "Modify Cloud Compute Infrastructure",
              "display_name": "T1578 - Modify Cloud Compute Infrastructure"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1410",
              "name": "Network Traffic Capture or Redirection",
              "display_name": "T1410 - Network Traffic Capture or Redirection"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "TA0037",
              "name": "Command and Control",
              "display_name": "TA0037 - Command and Control"
            },
            {
              "id": "T1584.003",
              "name": "Virtual Private Server",
              "display_name": "T1584.003 - Virtual Private Server"
            },
            {
              "id": "T1583.002",
              "name": "DNS Server",
              "display_name": "T1583.002 - DNS Server"
            },
            {
              "id": "T1408",
              "name": "Disguise Root/Jailbreak Indicators",
              "display_name": "T1408 - Disguise Root/Jailbreak Indicators"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1147",
              "name": "Hidden Users",
              "display_name": "T1147 - Hidden Users"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 422,
            "FileHash-SHA1": 316,
            "FileHash-SHA256": 1950,
            "domain": 899,
            "URL": 6117,
            "email": 21,
            "hostname": 2037,
            "SSLCertFingerprint": 2,
            "CVE": 1
          },
          "indicator_count": 11765,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "148 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "688c8526be7a4df33863b5c5",
          "name": "VirusTotal - Shiz.ivr",
          "description": "*Win.Trojan.Shiz.ivr\n*PWS:Win32/Simda.D\n*virtool #injection#infostealer #network #cnc #block_not #virustotal_google #cnc #checking #procmem_yara\n#injection_inter_process\n#injection_create_remote_thread\n#antidebug_windows\n#multiple_useragents\n#network_fake_useragent\n#persistence_autorun\n#cape_detected_threat\n#antiav_detectfile\n#modify_proxy\n#deletes_self\n#infostealer_cookies\n#injection_createremotethread\n#suricata_alert\n~ vashti",
          "modified": "2025-08-31T08:01:04.297000",
          "created": "2025-08-01T09:13:10.510000",
          "tags": [
            "dynamicloader",
            "unknown",
            "msie",
            "windows nt",
            "slcc2",
            "media center",
            "suspicious",
            "search",
            "high",
            "show",
            "copy",
            "possible",
            "write",
            "internal",
            "malware",
            "push",
            "local",
            "next",
            "contacted",
            "domains",
            "pulses",
            "related tags",
            "file type",
            "date april",
            "pm size",
            "sha1 sha256",
            "imphash pehash",
            "virustotal api",
            "bq jul",
            "united",
            "trojan",
            "backdoor",
            "virtool",
            "cnc beacon",
            "entries",
            "path max",
            "passive dns",
            "next associated",
            "cookie",
            "twitter",
            "body",
            "date",
            "medium",
            "simda",
            "global"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 10303,
            "hostname": 1413,
            "FileHash-SHA256": 1868,
            "domain": 1877,
            "FileHash-MD5": 357,
            "FileHash-SHA1": 348,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 16168,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 149,
          "modified_text": "273 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "5daf09a6d16f1e2c5c594c22",
          "name": "Simda - Malware Domain Feed V2",
          "description": "Command and Control domains for malware known as Simda. These domains are extracted from malware sandbox reports using                             a Machine Learning model trained on a corpus of good and bad domains.",
          "modified": "2025-07-15T21:13:57.066000",
          "created": "2019-10-22T13:52:38.770000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 33,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "otxrobottwo",
            "id": "78495",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_78495/resized/80/avatar_ba5a8acdbd.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 209,
            "hostname": 5
          },
          "indicator_count": 214,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1085,
          "modified_text": "320 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6786a59af06fee17c8decf9d",
          "name": "netcfg",
          "description": "000ceafd276003f46d06828bb0459b3ccdc2b44013a313b69d6270a224199034",
          "modified": "2025-05-31T02:36:52.299000",
          "created": "2025-01-14T17:57:46.687000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 222,
            "domain": 216,
            "hostname": 4,
            "FileHash-SHA256": 1
          },
          "indicator_count": 443,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 182,
          "modified_text": "365 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67fb185eb96e9791cf24ced4",
          "name": "Shiz/Packy",
          "description": "",
          "modified": "2025-05-13T01:03:15.390000",
          "created": "2025-04-13T01:50:22.707000",
          "tags": [],
          "references": [
            "https://www.virustotal.com/graph/gf9fb2090ae8e450dadda45c0596ab774ed1984e89aab4679bc3fc02096e22fa3"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 26,
            "URL": 191,
            "domain": 344,
            "hostname": 2
          },
          "indicator_count": 563,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 182,
          "modified_text": "383 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "678349edca4868e4cf8b298b",
          "name": "tfdbpg",
          "description": "0000121f09166c3e1e001b833301977f3f9461f756b46818e1acf377edb2454f",
          "modified": "2025-01-12T04:49:49.365000",
          "created": "2025-01-12T04:49:49.365000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 237,
            "domain": 228,
            "hostname": 8,
            "FileHash-SHA256": 1
          },
          "indicator_count": 474,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 182,
          "modified_text": "504 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d34c91868744aa1449fef2",
          "name": "Locky: File Deletion targeting incriminating archived files.",
          "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T12:41:52.846000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 57,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "802 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d3c31230455f6d8da3a9f0",
          "name": "Locky: File Deletion targeting incriminating archived files II",
          "description": "",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T21:07:30.887000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65d34c8a64436a7aee2e25a1",
          "export_count": 73,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Enqrypted",
            "id": "272105",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_272105/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 62,
          "modified_text": "802 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d3acf32e1088e76165a307",
          "name": "Locky: File Deletion targeting incriminating archived files.",
          "description": "",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T19:33:07.504000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65d34c91868744aa1449fef2",
          "export_count": 64,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 234,
          "modified_text": "802 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d34c8a64436a7aee2e25a1",
          "name": "Locky: File Deletion targeting incriminating archived files.",
          "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T12:41:46.707000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 65,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "802 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "659ab33e614882a4a7451ca8",
          "name": "Simda | Sabey Data Center | https://nsa.gov1.info/utah-data-center/",
          "description": "SIMDA is a family of backdoors capable of stealing information such as user names, passwords, and certificates. It steals information via its keylogging and HTML injection routines. \nReference: TrendMicro\n\nMALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda\nWin32.Trojan-Spy.Shiz.b\nParody named 'not the Whitehouse' -https://whois.domaintools.com/gov1.info\nM.Brian Sabey \nTargets Tsara Brashears",
          "modified": "2024-02-06T14:00:04.985000",
          "created": "2024-01-07T14:20:46.936000",
          "tags": [
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls https",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "redacted for",
            "privacy tech",
            "privacy admin",
            "date",
            "server",
            "country",
            "organization",
            "postal code",
            "stateprovince",
            "code",
            "whois record",
            "ssl certificate",
            "historical ssl",
            "whois whois",
            "september",
            "redline stealer",
            "whois",
            "threat roundup",
            "bangladesh",
            "communicating",
            "prynt stealer",
            "banker",
            "keylogger",
            "dtrack",
            "prynt",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "jpeg image",
            "jfif",
            "ascii text",
            "united",
            "appdata",
            "file",
            "indicator",
            "et tor",
            "known tor",
            "class",
            "unknown",
            "general",
            "hybrid",
            "local",
            "win64",
            "click",
            "twitter",
            "strings",
            "generator",
            "critical",
            "error",
            "trident",
            "cascade",
            "darpa",
            "registrar",
            "rdds service",
            "record",
            "registrant",
            "admin",
            "tech contact",
            "whois service",
            "form",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "headers nel",
            "contentencoding",
            "gmt connection",
            "search",
            "for privacy",
            "status",
            "showing",
            "passive dns",
            "urls",
            "ionos se",
            "creation date",
            "next",
            "aaaa",
            "pulse pulses",
            "files",
            "united kingdom",
            "whitelisted",
            "worm",
            "gmt contenttype",
            "scan endpoints",
            "all octoseek",
            "ipv4",
            "body",
            "http",
            "unique",
            "screenshot",
            "url http",
            "ip address",
            "internet se",
            "emails",
            "name servers",
            "dnssec",
            "as63949 linode",
            "all search",
            "otx octoseek",
            "related nids",
            "reverse dns",
            "netherlands asn",
            "contacted",
            "resolutions",
            "referrer",
            "mirai malware",
            "urls http",
            "parent referrer",
            "certificate",
            "record value",
            "entries",
            "dynamicloader",
            "yara rule",
            "high",
            "sinkhole cookie",
            "et trojan",
            "medium",
            "yara detections",
            "virtool",
            "value snkz",
            "less see",
            "possible",
            "august",
            "copy",
            "expiro",
            "public folder",
            "pictures",
            "videos",
            "music",
            "anomalous file",
            "media player",
            "url https",
            "delete c",
            "ms windows",
            "pe32",
            "intel",
            "windows nt",
            "wow64",
            "khtml",
            "gecko",
            "query",
            "write",
            "malware",
            "template",
            "findwindowa",
            "ollydbg",
            "regsetvalueexa",
            "regdword",
            "high process",
            "x8bxe5",
            "regbinary",
            "injection t1055",
            "t1055",
            "zeppelin",
            "win32",
            "internal",
            "malware beacon",
            "a checkin",
            "create c",
            "read c",
            "write c",
            "msie",
            "suspicious",
            "slcc2",
            "media center",
            "as20940",
            "as2914 ntt",
            "as16625 akamai",
            "a domains",
            "cdata",
            "script",
            "as8068",
            "mtb oct",
            "location canada",
            "trojanspy",
            "xpire.info",
            "searchmeup",
            "cname",
            "as35994 akamai",
            "as14061",
            "as9009 m247",
            "samples",
            "as25577 ide",
            "hostnames",
            "show",
            "info compiler",
            "products",
            "vs2008 sp1",
            "vs2008",
            "vs2010",
            "header target",
            "machine intel",
            "utc entry",
            "point",
            "sections",
            "info",
            "hashes c2ae",
            "zenbox",
            "detections file",
            "name",
            "html",
            "win32 exe",
            "javascript",
            "contacted ip",
            "ip detections",
            "gandi sas",
            "godaddy online",
            "cayman",
            "dynadot",
            "domains",
            "psiusa",
            "domain robot",
            "dynadot inc",
            "net technology",
            "tsara brashears",
            "apple phone",
            "unlocker",
            "shell code",
            "simda",
            "amazon 02",
            "metro",
            "infected",
            "qakbot"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [
            {
              "id": "Prynt",
              "display_name": "Prynt",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Xpire.info",
              "display_name": "Xpire.info",
              "target": null
            },
            {
              "id": "Searchmeup",
              "display_name": "Searchmeup",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 31,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2129,
            "FileHash-SHA1": 1459,
            "FileHash-SHA256": 5050,
            "URL": 7341,
            "domain": 3041,
            "hostname": 3214,
            "email": 12,
            "CVE": 1
          },
          "indicator_count": 22247,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "845 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "659ab3389d6c91dc01801fe5",
          "name": "Simda | Sabey Data Center | https://nsa.gov1.info/utah-data-center/",
          "description": "SIMDA is a family of backdoors capable of stealing information such as user names, passwords, and certificates. It steals information via its keylogging and HTML injection routines. \nReference: TrendMicro\n\nMALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda\nWin32.Trojan-Spy.Shiz.b\nParody named 'not the Whitehouse' -https://whois.domaintools.com/gov1.info\nM.Brian Sabey \nTargets Tsara Brashears",
          "modified": "2024-02-06T14:00:04.985000",
          "created": "2024-01-07T14:20:40.610000",
          "tags": [
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls https",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "redacted for",
            "privacy tech",
            "privacy admin",
            "date",
            "server",
            "country",
            "organization",
            "postal code",
            "stateprovince",
            "code",
            "whois record",
            "ssl certificate",
            "historical ssl",
            "whois whois",
            "september",
            "redline stealer",
            "whois",
            "threat roundup",
            "bangladesh",
            "communicating",
            "prynt stealer",
            "banker",
            "keylogger",
            "dtrack",
            "prynt",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "jpeg image",
            "jfif",
            "ascii text",
            "united",
            "appdata",
            "file",
            "indicator",
            "et tor",
            "known tor",
            "class",
            "unknown",
            "general",
            "hybrid",
            "local",
            "win64",
            "click",
            "twitter",
            "strings",
            "generator",
            "critical",
            "error",
            "trident",
            "cascade",
            "darpa",
            "registrar",
            "rdds service",
            "record",
            "registrant",
            "admin",
            "tech contact",
            "whois service",
            "form",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "headers nel",
            "contentencoding",
            "gmt connection",
            "search",
            "for privacy",
            "status",
            "showing",
            "passive dns",
            "urls",
            "ionos se",
            "creation date",
            "next",
            "aaaa",
            "pulse pulses",
            "files",
            "united kingdom",
            "whitelisted",
            "worm",
            "gmt contenttype",
            "scan endpoints",
            "all octoseek",
            "ipv4",
            "body",
            "http",
            "unique",
            "screenshot",
            "url http",
            "ip address",
            "internet se",
            "emails",
            "name servers",
            "dnssec",
            "as63949 linode",
            "all search",
            "otx octoseek",
            "related nids",
            "reverse dns",
            "netherlands asn",
            "contacted",
            "resolutions",
            "referrer",
            "mirai malware",
            "urls http",
            "parent referrer",
            "certificate",
            "record value",
            "entries",
            "dynamicloader",
            "yara rule",
            "high",
            "sinkhole cookie",
            "et trojan",
            "medium",
            "yara detections",
            "virtool",
            "value snkz",
            "less see",
            "possible",
            "august",
            "copy",
            "expiro",
            "public folder",
            "pictures",
            "videos",
            "music",
            "anomalous file",
            "media player",
            "url https",
            "delete c",
            "ms windows",
            "pe32",
            "intel",
            "windows nt",
            "wow64",
            "khtml",
            "gecko",
            "query",
            "write",
            "malware",
            "template",
            "findwindowa",
            "ollydbg",
            "regsetvalueexa",
            "regdword",
            "high process",
            "x8bxe5",
            "regbinary",
            "injection t1055",
            "t1055",
            "zeppelin",
            "win32",
            "internal",
            "malware beacon",
            "a checkin",
            "create c",
            "read c",
            "write c",
            "msie",
            "suspicious",
            "slcc2",
            "media center",
            "as20940",
            "as2914 ntt",
            "as16625 akamai",
            "a domains",
            "cdata",
            "script",
            "as8068",
            "mtb oct",
            "location canada",
            "trojanspy",
            "xpire.info",
            "searchmeup",
            "cname",
            "as35994 akamai",
            "as14061",
            "as9009 m247",
            "samples",
            "as25577 ide",
            "hostnames",
            "show",
            "info compiler",
            "products",
            "vs2008 sp1",
            "vs2008",
            "vs2010",
            "header target",
            "machine intel",
            "utc entry",
            "point",
            "sections",
            "info",
            "hashes c2ae",
            "zenbox",
            "detections file",
            "name",
            "html",
            "win32 exe",
            "javascript",
            "contacted ip",
            "ip detections",
            "gandi sas",
            "godaddy online",
            "cayman",
            "dynadot",
            "domains",
            "psiusa",
            "domain robot",
            "dynadot inc",
            "net technology",
            "tsara brashears",
            "apple phone",
            "unlocker",
            "shell code",
            "simda",
            "amazon 02",
            "metro",
            "infected",
            "qakbot"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [
            {
              "id": "Prynt",
              "display_name": "Prynt",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Xpire.info",
              "display_name": "Xpire.info",
              "target": null
            },
            {
              "id": "Searchmeup",
              "display_name": "Searchmeup",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 30,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2129,
            "FileHash-SHA1": 1459,
            "FileHash-SHA256": 5050,
            "URL": 7341,
            "domain": 3041,
            "hostname": 3214,
            "email": 12,
            "CVE": 1
          },
          "indicator_count": 22247,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "845 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "658449d3f6ec1af2f3aace46",
          "name": "Qakbot | Reddit",
          "description": "Qbot URL: https://seedbeej.pk/tin/index.php?QBOT.zip Qbot zip found in Reddit Honeypot link: https://www.reddit.com/user backdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork with many capabilities, attack methods and demands. An unsuspecting victim always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware  malvertizing, fraud services, leads to full control of badly compromised digital profile.",
          "modified": "2024-01-20T02:02:19.559000",
          "created": "2023-12-21T14:21:07.435000",
          "tags": [
            "ssl certificate",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "threat",
            "paste",
            "blacklist https",
            "qakbot",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "ascii text",
            "pattern match",
            "file",
            "windows nt",
            "appdata",
            "indicator",
            "crlf line",
            "unicode text",
            "jpeg image",
            "mitre att",
            "hybrid",
            "general",
            "local",
            "error",
            "click",
            "strings",
            "microsoft",
            "threat analyzer",
            "urls https",
            "no data",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "heur",
            "malware site",
            "malicious site",
            "safe site",
            "malware",
            "html",
            "phishing site",
            "site top",
            "riskware",
            "unsafe",
            "artemis",
            "quasar rat",
            "downldr",
            "agent",
            "presenoker",
            "applicunwnt",
            "crack",
            "cve201711882",
            "win64",
            "iframe",
            "quasar",
            "trojanspy",
            "exit",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "traffic",
            "anonymizer",
            "brasil",
            "phishing three",
            "united",
            "phishing bank",
            "virustotal",
            "tech",
            "bank",
            "maltiverse",
            "hidelink",
            "samples",
            "spyware",
            "injector",
            "mon jan",
            "tld count",
            "wed dec",
            "download",
            "first",
            "team",
            "simda",
            "bambernek",
            "simda simda",
            "infy",
            "alexa",
            "gregory",
            "cyber threat",
            "phishing",
            "engineering",
            "covid19",
            "telefonica co",
            "malicious",
            "zbot",
            "zeus",
            "betabot",
            "suppobox",
            "citadel",
            "pony",
            "kraken",
            "redline stealer",
            "ransomware",
            "vawtrak",
            "athena",
            "neutrino",
            "alina",
            "andromeda",
            "dexter",
            "unknown",
            "keylogger",
            "hawkeye",
            "phase",
            "jackpos",
            "plasma",
            "spyeye",
            "spitmo",
            "slingshot",
            "ramnit",
            "emotet",
            "pykspa",
            "virut",
            "installcore",
            "dorkbot",
            "bondat",
            "union",
            "vskimmer",
            "xtrat",
            "solar",
            "grandcrab",
            "nymaim",
            "matsnu",
            "cutwail",
            "cobalt strike",
            "hydra",
            "tinba",
            "nsis",
            "memscan",
            "deepscan",
            "runescape",
            "backdoor",
            "reddit",
            "tulach",
            "password stealer",
            "active threat",
            "apple",
            "pinkslipbot",
            "icloud",
            "free",
            "apple"
          ],
          "references": [
            "https://seedbeej.pk/tin/index.php?QBOT.zip.  [Qbot zip]",
            "https://tulach.cc/  [Botnet phishing]",
            "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
            "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
            "198.54.115.46            [exploit_source]",
            "gadyniw.com          [command_and_control]",
            "gahyqah.com          [command_and_control]",
            "galyqaz.com            [command_and_control]",
            "lyvyxor.com             [command_and_control]",
            "puzylyp.com           [command_and_control]",
            "malicious.high.ml   [dropper]",
            "https://www.reddit.com/user [honeypot]",
            "beacons.bcp.gvt.com   [tracking]",
            "https://www.norad.mil/   [tracking]",
            "www.norad.mil   [tracking]",
            "www.apple.com  [API property call]",
            "https://www.apple.com/qtactivex/qtplugin.cab   [https://www.icloud.com .cab]",
            "yesporn.fun",
            "http://114.114.114.114:90/p/cdbdd4a09a64909694281aec503746fd/mobile_index.html?MTE0LjExNC4xMTQuMTE0L2xvZ2luP2hhc19vcmlfdXJp [Tulach | Malicious]",
            "114.114.114.114  [Tulach | Virus Network IP]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Quasar",
              "display_name": "Quasar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Gregory",
              "display_name": "Gregory",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Matsnu",
              "display_name": "Matsnu",
              "target": null
            },
            {
              "id": "Vawtrak",
              "display_name": "Vawtrak",
              "target": null
            },
            {
              "id": "XRat",
              "display_name": "XRat",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "vSkimmer",
              "display_name": "vSkimmer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "SpyEye",
              "display_name": "SpyEye",
              "target": null
            },
            {
              "id": "Spitmo",
              "display_name": "Spitmo",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "DorkBot",
              "display_name": "DorkBot",
              "target": null
            },
            {
              "id": "Slingshot",
              "display_name": "Slingshot",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Plasma RAT",
              "display_name": "Plasma RAT",
              "target": null
            },
            {
              "id": "Neutrino",
              "display_name": "Neutrino",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "GrandCrab",
              "display_name": "GrandCrab",
              "target": null
            },
            {
              "id": "Andromeda",
              "display_name": "Andromeda",
              "target": null
            },
            {
              "id": "Alinaos",
              "display_name": "Alinaos",
              "target": null
            },
            {
              "id": "HawkEye",
              "display_name": "HawkEye",
              "target": null
            },
            {
              "id": "Kraken",
              "display_name": "Kraken",
              "target": null
            },
            {
              "id": "Infy",
              "display_name": "Infy",
              "target": null
            },
            {
              "id": "Dexter",
              "display_name": "Dexter",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "ASCII",
              "display_name": "ASCII",
              "target": null
            },
            {
              "id": "Athena",
              "display_name": "Athena",
              "target": null
            },
            {
              "id": "Bambernek",
              "display_name": "Bambernek",
              "target": null
            },
            {
              "id": "BetaBot",
              "display_name": "BetaBot",
              "target": null
            },
            {
              "id": "COVID19",
              "display_name": "COVID19",
              "target": null
            },
            {
              "id": "Citadel",
              "display_name": "Citadel",
              "target": null
            },
            {
              "id": "Bondat",
              "display_name": "Bondat",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Hydra",
              "display_name": "Hydra",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Pinkslipbot",
              "display_name": "Pinkslipbot",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 124,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8736,
            "FileHash-MD5": 953,
            "FileHash-SHA1": 489,
            "FileHash-SHA256": 3566,
            "domain": 1516,
            "hostname": 2221,
            "CVE": 6
          },
          "indicator_count": 17487,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "862 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6583e3acc7f464d48a3503d1",
          "name": "Qkbot | Reddit",
          "description": "Qbot URL:  https://seedbeej.pk/tin/index.php?QBOT.zip found in Reddit Honeypot link: https://www.reddit.com/user\nbackdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork  with many capabilities, attack methods and demands.  An unsuspecting victim  always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware, malvertizing, fraud services, full control of badly compromised digital profiles which have been discovered.",
          "modified": "2024-01-20T02:02:19.559000",
          "created": "2023-12-21T07:05:16.695000",
          "tags": [
            "ssl certificate",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "threat",
            "paste",
            "blacklist https",
            "qakbot",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "ascii text",
            "pattern match",
            "file",
            "windows nt",
            "appdata",
            "indicator",
            "crlf line",
            "unicode text",
            "jpeg image",
            "mitre att",
            "hybrid",
            "general",
            "local",
            "error",
            "click",
            "strings",
            "microsoft",
            "threat analyzer",
            "urls https",
            "no data",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "heur",
            "malware site",
            "malicious site",
            "safe site",
            "malware",
            "html",
            "phishing site",
            "site top",
            "riskware",
            "unsafe",
            "artemis",
            "quasar rat",
            "downldr",
            "agent",
            "presenoker",
            "applicunwnt",
            "crack",
            "cve201711882",
            "win64",
            "iframe",
            "quasar",
            "trojanspy",
            "exit",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "traffic",
            "anonymizer",
            "brasil",
            "phishing three",
            "united",
            "phishing bank",
            "virustotal",
            "tech",
            "bank",
            "maltiverse",
            "hidelink",
            "samples",
            "spyware",
            "injector",
            "mon jan",
            "tld count",
            "wed dec",
            "download",
            "first",
            "team",
            "simda",
            "bambernek",
            "simda simda",
            "infy",
            "alexa",
            "gregory",
            "cyber threat",
            "phishing",
            "engineering",
            "covid19",
            "telefonica co",
            "malicious",
            "zbot",
            "zeus",
            "betabot",
            "suppobox",
            "citadel",
            "pony",
            "kraken",
            "redline stealer",
            "ransomware",
            "vawtrak",
            "athena",
            "neutrino",
            "alina",
            "andromeda",
            "dexter",
            "unknown",
            "keylogger",
            "hawkeye",
            "phase",
            "jackpos",
            "plasma",
            "spyeye",
            "spitmo",
            "slingshot",
            "ramnit",
            "emotet",
            "pykspa",
            "virut",
            "installcore",
            "dorkbot",
            "bondat",
            "union",
            "vskimmer",
            "xtrat",
            "solar",
            "grandcrab",
            "nymaim",
            "matsnu",
            "cutwail",
            "cobalt strike",
            "hydra",
            "tinba",
            "nsis",
            "memscan",
            "deepscan",
            "runescape",
            "backdoor",
            "reddit",
            "tulach"
          ],
          "references": [
            "https://seedbeej.pk/tin/index.php?QBOT.zip",
            "https://tulach.cc/ [phishing, exploits, malware spreader]",
            "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
            "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
            "198.54.115.46            [exploit_source]",
            "gadyniw.com          [command_and_control]",
            "gahyqah.com          [command_and_control]",
            "galyqaz.com            [command_and_control]",
            "lyvyxor.com             [command_and_control]",
            "puzylyp.com           [command_and_control]",
            "malicious.high.ml   [dropper]",
            "https://www.reddit.com/user"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Quasar",
              "display_name": "Quasar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Gregory",
              "display_name": "Gregory",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Matsnu",
              "display_name": "Matsnu",
              "target": null
            },
            {
              "id": "Vawtrak",
              "display_name": "Vawtrak",
              "target": null
            },
            {
              "id": "XRat",
              "display_name": "XRat",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "vSkimmer",
              "display_name": "vSkimmer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "SpyEye",
              "display_name": "SpyEye",
              "target": null
            },
            {
              "id": "Spitmo",
              "display_name": "Spitmo",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "DorkBot",
              "display_name": "DorkBot",
              "target": null
            },
            {
              "id": "Slingshot",
              "display_name": "Slingshot",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Plasma RAT",
              "display_name": "Plasma RAT",
              "target": null
            },
            {
              "id": "Neutrino",
              "display_name": "Neutrino",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "GrandCrab",
              "display_name": "GrandCrab",
              "target": null
            },
            {
              "id": "Andromeda",
              "display_name": "Andromeda",
              "target": null
            },
            {
              "id": "Alinaos",
              "display_name": "Alinaos",
              "target": null
            },
            {
              "id": "HawkEye",
              "display_name": "HawkEye",
              "target": null
            },
            {
              "id": "Kraken",
              "display_name": "Kraken",
              "target": null
            },
            {
              "id": "Infy",
              "display_name": "Infy",
              "target": null
            },
            {
              "id": "Dexter",
              "display_name": "Dexter",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "ASCII",
              "display_name": "ASCII",
              "target": null
            },
            {
              "id": "Athena",
              "display_name": "Athena",
              "target": null
            },
            {
              "id": "Bambernek",
              "display_name": "Bambernek",
              "target": null
            },
            {
              "id": "BetaBot",
              "display_name": "BetaBot",
              "target": null
            },
            {
              "id": "COVID19",
              "display_name": "COVID19",
              "target": null
            },
            {
              "id": "Citadel",
              "display_name": "Citadel",
              "target": null
            },
            {
              "id": "Bondat",
              "display_name": "Bondat",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Hydra",
              "display_name": "Hydra",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 101,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8343,
            "FileHash-MD5": 953,
            "FileHash-SHA1": 489,
            "FileHash-SHA256": 3565,
            "domain": 1494,
            "hostname": 2218,
            "CVE": 6
          },
          "indicator_count": 17068,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "862 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6583e3a2d1432cbf9054d26d",
          "name": "Qkbot | Reddit",
          "description": "Qbot URL:  https://seedbeej.pk/tin/index.php?QBOT.zip found in Reddit Honeypot link: https://www.reddit.com/user\nbackdoor second stage developed for distribution as a password stealer. Qbot, seemingly common; is a large botnetwork  with many capabilities, attack methods and demands.  An unsuspecting victim  always be in botnetwork. Qbot encompasses many other bot networks, trojans, network rats, spyware, malvertizing, fraud services, full control of badly compromised digital profiles which have been discovered.",
          "modified": "2024-01-20T02:02:19.559000",
          "created": "2023-12-21T07:05:06.936000",
          "tags": [
            "ssl certificate",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "threat",
            "paste",
            "blacklist https",
            "qakbot",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "ascii text",
            "pattern match",
            "file",
            "windows nt",
            "appdata",
            "indicator",
            "crlf line",
            "unicode text",
            "jpeg image",
            "mitre att",
            "hybrid",
            "general",
            "local",
            "error",
            "click",
            "strings",
            "microsoft",
            "threat analyzer",
            "urls https",
            "no data",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "heur",
            "malware site",
            "malicious site",
            "safe site",
            "malware",
            "html",
            "phishing site",
            "site top",
            "riskware",
            "unsafe",
            "artemis",
            "quasar rat",
            "downldr",
            "agent",
            "presenoker",
            "applicunwnt",
            "crack",
            "cve201711882",
            "win64",
            "iframe",
            "quasar",
            "trojanspy",
            "exit",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "traffic",
            "anonymizer",
            "brasil",
            "phishing three",
            "united",
            "phishing bank",
            "virustotal",
            "tech",
            "bank",
            "maltiverse",
            "hidelink",
            "samples",
            "spyware",
            "injector",
            "mon jan",
            "tld count",
            "wed dec",
            "download",
            "first",
            "team",
            "simda",
            "bambernek",
            "simda simda",
            "infy",
            "alexa",
            "gregory",
            "cyber threat",
            "phishing",
            "engineering",
            "covid19",
            "telefonica co",
            "malicious",
            "zbot",
            "zeus",
            "betabot",
            "suppobox",
            "citadel",
            "pony",
            "kraken",
            "redline stealer",
            "ransomware",
            "vawtrak",
            "athena",
            "neutrino",
            "alina",
            "andromeda",
            "dexter",
            "unknown",
            "keylogger",
            "hawkeye",
            "phase",
            "jackpos",
            "plasma",
            "spyeye",
            "spitmo",
            "slingshot",
            "ramnit",
            "emotet",
            "pykspa",
            "virut",
            "installcore",
            "dorkbot",
            "bondat",
            "union",
            "vskimmer",
            "xtrat",
            "solar",
            "grandcrab",
            "nymaim",
            "matsnu",
            "cutwail",
            "cobalt strike",
            "hydra",
            "tinba",
            "nsis",
            "memscan",
            "deepscan",
            "runescape",
            "backdoor",
            "reddit",
            "tulach"
          ],
          "references": [
            "https://seedbeej.pk/tin/index.php?QBOT.zip",
            "https://tulach.cc/ [phishing, exploits, malware spreader]",
            "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
            "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
            "198.54.115.46            [exploit_source]",
            "gadyniw.com          [command_and_control]",
            "gahyqah.com          [command_and_control]",
            "galyqaz.com            [command_and_control]",
            "lyvyxor.com             [command_and_control]",
            "puzylyp.com           [command_and_control]",
            "malicious.high.ml   [dropper]",
            "https://www.reddit.com/user"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Quasar",
              "display_name": "Quasar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Gregory",
              "display_name": "Gregory",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Matsnu",
              "display_name": "Matsnu",
              "target": null
            },
            {
              "id": "Vawtrak",
              "display_name": "Vawtrak",
              "target": null
            },
            {
              "id": "XRat",
              "display_name": "XRat",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "vSkimmer",
              "display_name": "vSkimmer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "SpyEye",
              "display_name": "SpyEye",
              "target": null
            },
            {
              "id": "Spitmo",
              "display_name": "Spitmo",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "DorkBot",
              "display_name": "DorkBot",
              "target": null
            },
            {
              "id": "Slingshot",
              "display_name": "Slingshot",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Plasma RAT",
              "display_name": "Plasma RAT",
              "target": null
            },
            {
              "id": "Neutrino",
              "display_name": "Neutrino",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "NSIS",
              "display_name": "NSIS",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            },
            {
              "id": "GrandCrab",
              "display_name": "GrandCrab",
              "target": null
            },
            {
              "id": "Andromeda",
              "display_name": "Andromeda",
              "target": null
            },
            {
              "id": "Alinaos",
              "display_name": "Alinaos",
              "target": null
            },
            {
              "id": "HawkEye",
              "display_name": "HawkEye",
              "target": null
            },
            {
              "id": "Kraken",
              "display_name": "Kraken",
              "target": null
            },
            {
              "id": "Infy",
              "display_name": "Infy",
              "target": null
            },
            {
              "id": "Dexter",
              "display_name": "Dexter",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "ASCII",
              "display_name": "ASCII",
              "target": null
            },
            {
              "id": "Athena",
              "display_name": "Athena",
              "target": null
            },
            {
              "id": "Bambernek",
              "display_name": "Bambernek",
              "target": null
            },
            {
              "id": "BetaBot",
              "display_name": "BetaBot",
              "target": null
            },
            {
              "id": "COVID19",
              "display_name": "COVID19",
              "target": null
            },
            {
              "id": "Citadel",
              "display_name": "Citadel",
              "target": null
            },
            {
              "id": "Bondat",
              "display_name": "Bondat",
              "target": null
            },
            {
              "id": "HideLink",
              "display_name": "HideLink",
              "target": null
            },
            {
              "id": "Hydra",
              "display_name": "Hydra",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 98,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8343,
            "FileHash-MD5": 953,
            "FileHash-SHA1": 489,
            "FileHash-SHA256": 3565,
            "domain": 1494,
            "hostname": 2218,
            "CVE": 6
          },
          "indicator_count": 17068,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "862 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a7b4eb565273001e2e08",
          "name": "Ireland Netsky | Relay Router | Misc Attack on LTL Fright Outage",
          "description": "",
          "modified": "2023-12-06T16:56:20.491000",
          "created": "2023-12-06T16:56:20.491000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1353,
            "CVE": 8,
            "FileHash-SHA256": 3611,
            "domain": 795,
            "URL": 2831,
            "FileHash-MD5": 663,
            "FileHash-SHA1": 398
          },
          "indicator_count": 9659,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f1a8f35a050560dcd3b00",
          "name": "Ireland Netsky | Relay Router | Misc Attack on LTL Fright Outage",
          "description": "",
          "modified": "2023-11-03T02:03:00.398000",
          "created": "2023-10-30T02:53:03.811000",
          "tags": [
            "united",
            "smtp service",
            "firehol",
            "pony",
            "s1us",
            "s1de",
            "spammer",
            "proxy",
            "ireland netsky",
            "anonymizer",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "alexa top",
            "alexa",
            "detection list",
            "blacklist",
            "malicious url",
            "blacklist http",
            "linkid252669",
            "noname057",
            "url summary",
            "summary",
            "sample",
            "samples",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "misc activity",
            "et policy",
            "tor ssl",
            "Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49",
            "cyber criminal",
            "FireHOL",
            "Suricata Alert",
            "HTML document, ASCII text",
            "mail spammer",
            "malware site",
            "heur",
            "malware",
            "adware",
            "malicious site",
            "phishing site",
            "artemis",
            "unsafe",
            "exploit",
            "iframe",
            "fakealert",
            "opencandy",
            "riskware",
            "genkryptik",
            "nircmd",
            "swrort",
            "downldr",
            "crack",
            "tiggre",
            "presenoker",
            "filetour",
            "cleaner",
            "conduit",
            "wacatac",
            "coinminer",
            "dropper",
            "cobalt strike",
            "acint",
            "systweak",
            "behav",
            "agent",
            "phishing",
            "maltiverse",
            "trojanspy",
            "webtoolbar",
            "phishing",
            "exploit-source"
          ],
          "references": [
            "-Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49DD/",
            "https://www.hybrid-analysis.com/sample/fa1f15bd4c0cd287fe04f324d3363a8b5a295b57cb22d9ea0f3d6973eb442d17/651c94c00b17fb9324040f7c"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "Trojan:Win32/Tiggre",
              "display_name": "Trojan:Win32/Tiggre",
              "target": "/malware/Trojan:Win32/Tiggre"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Ireland Netsky",
              "display_name": "Ireland Netsky",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1147",
              "name": "Hidden Users",
              "display_name": "T1147 - Hidden Users"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [
            "Transportation",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "651cd4a6af63714f51c8d721",
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 795,
            "FileHash-MD5": 663,
            "hostname": 1353,
            "URL": 2831,
            "FileHash-SHA1": 398,
            "FileHash-SHA256": 3611,
            "CVE": 8
          },
          "indicator_count": 9659,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "940 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "651cd4a6af63714f51c8d721",
          "name": "Ireland Netsky | Relay Router | Misc Attack on LTL Fright Outage",
          "description": "Cobalt Strike , FireHol anonymization,  IT Attack, Suricata Alert, MITRE. Appears to be a complete cyber attack against a well known LTL Fright lines IT system.",
          "modified": "2023-11-03T02:03:00.398000",
          "created": "2023-10-04T02:57:42.183000",
          "tags": [
            "united",
            "smtp service",
            "firehol",
            "pony",
            "s1us",
            "s1de",
            "spammer",
            "proxy",
            "ireland netsky",
            "anonymizer",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "alexa top",
            "alexa",
            "detection list",
            "blacklist",
            "malicious url",
            "blacklist http",
            "linkid252669",
            "noname057",
            "url summary",
            "summary",
            "sample",
            "samples",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "misc activity",
            "et policy",
            "tor ssl",
            "Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49",
            "cyber criminal",
            "FireHOL",
            "Suricata Alert",
            "HTML document, ASCII text",
            "mail spammer",
            "malware site",
            "heur",
            "malware",
            "adware",
            "malicious site",
            "phishing site",
            "artemis",
            "unsafe",
            "exploit",
            "iframe",
            "fakealert",
            "opencandy",
            "riskware",
            "genkryptik",
            "nircmd",
            "swrort",
            "downldr",
            "crack",
            "tiggre",
            "presenoker",
            "filetour",
            "cleaner",
            "conduit",
            "wacatac",
            "coinminer",
            "dropper",
            "cobalt strike",
            "acint",
            "systweak",
            "behav",
            "agent",
            "phishing",
            "maltiverse",
            "trojanspy",
            "webtoolbar",
            "phishing",
            "exploit-source"
          ],
          "references": [
            "-Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49DD/",
            "https://www.hybrid-analysis.com/sample/fa1f15bd4c0cd287fe04f324d3363a8b5a295b57cb22d9ea0f3d6973eb442d17/651c94c00b17fb9324040f7c"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "Trojan:Win32/Tiggre",
              "display_name": "Trojan:Win32/Tiggre",
              "target": "/malware/Trojan:Win32/Tiggre"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Ireland Netsky",
              "display_name": "Ireland Netsky",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1147",
              "name": "Hidden Users",
              "display_name": "T1147 - Hidden Users"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [
            "Transportation",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 795,
            "FileHash-MD5": 663,
            "hostname": 1353,
            "URL": 2831,
            "FileHash-SHA1": 398,
            "FileHash-SHA256": 3611,
            "CVE": 8
          },
          "indicator_count": 9659,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "940 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://tulach.cc/  [Botnet phishing]",
        "https://www.virustotal.com/gui/url/000c01d40db51f156933c624f23e776cb2c1fd60b8f1840b13b9622886a8e918/community",
        "www.apple.com  [API property call]",
        "https://www.virustotal.com/graph/gf9fb2090ae8e450dadda45c0596ab774ed1984e89aab4679bc3fc02096e22fa3",
        "114.114.114.114  [Tulach | Virus Network IP]",
        "https://seedbeej.pk/tin/index.php?QBOT.zip",
        "https://www.apple.com/qtactivex/qtplugin.cab   [https://www.icloud.com .cab]",
        "https://www.idvd.eu/?cid=oas-japac-domains-applestore.com.cn/90.i.lolik.anyciona.patrolita.casse.897866 \u2022 oas-japac-domains-applestore.com.cn",
        "yesporn.fun",
        "beacons.bcp.gvt.com   [tracking]",
        "www.norad.mil   [tracking]",
        "http://114.114.114.114:90/p/cdbdd4a09a64909694281aec503746fd/mobile_index.html?MTE0LjExNC4xMTQuMTE0L2xvZ2luP2hhc19vcmlfdXJp [Tulach | Malicious]",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "galyqaz.com            [command_and_control]",
        "http://beelinerouter.net/",
        "gahyqah.com          [command_and_control]",
        "foundry.com \u2022 helix. com",
        "-Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49DD/",
        "http://foundry2-lbl.dvr.dn2.n-helix.com",
        "https://www.hybrid-analysis.com/sample/fa1f15bd4c0cd287fe04f324d3363a8b5a295b57cb22d9ea0f3d6973eb442d17/651c94c00b17fb9324040f7c",
        "gadyniw.com          [command_and_control]",
        "redhatdelete.com",
        "IDS Detections: Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "apple.com \u2022 getsupport.apple.com \u2022",
        "https://seedbeej.pk/tin/index.php?QBOT.zip.  [Qbot zip]",
        "Antivirus Detections: Win.Ransomware.Wanna-9769986-0 ,  Ransom:Win32/WannaCrypt.H",
        "DNS Lookup) Possible ETERNALBLUE Probe MS17-010 (MSF style) Possible ETERNALBLUE Probe MS17-010 (Generic Flags) ETERNALBLUE Probe Vulnerable System Response MS17-010 Possible ETERNALBLUE MS17-010 Heap Spray More Yara Detections WannaCry_Ransomware ,  Win32_Ransomware_WannaCry ,  Wanna_Cry_Ransomware_Generic ,  MS17_010_WanaCry_worm ,  stack_string More Alerts 25 Alerts suspicious_iocontrol_codes persistence_autorun persistence_autorun_tasks stealth_file suricata_alert antivm_generic_disk anomalous_deletefil",
        "Tulach - 114.114.114.114",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "https://www.reddit.com/user [honeypot]",
        "Domains Contacted: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com \u2022\u2019survey-smiles.com",
        "w32.virut.cf \u2022 win32.virut.am \u2022 virut.cf \u2022 http://w32.virut.cf \u2022http://w32.virut.cf/ \u2022 https://w32.virut.cf",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695",
        "https://www.hybrid-analysis.com/sample/a8decf589e5ec26f1e994a3923fc245db98f681f951d2bb8e1fcce1d8fef5293",
        "lyvyxor.com             [command_and_control]",
        "https://tulach.cc/ [phishing, exploits, malware spreader]",
        "https://www.reddit.com/user",
        "malicious.high.ml   [dropper]",
        "https://www.norad.mil/   [tracking]",
        "https://aws.hirecar.net/",
        "puzylyp.com           [command_and_control]",
        "198.54.115.46            [exploit_source]",
        "pandacookie2018.xyz"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Redline stealer",
            "Mirai",
            "Ireland netsky",
            "Ransom:win32/wannacrypt.a!rsm",
            "Spyeye",
            "Dexter",
            "Backdoor:win32/small.ir",
            "Quasar",
            "Win.malware.delf-10008156-0",
            "Dorkbot",
            "Grandcrab",
            "Mitre attack",
            "Suppobox",
            "Athena",
            "Virut",
            "Artemis",
            "Bambernek",
            "Win.spyware.88778-2",
            "Virtool:win32/obfuscator",
            "Bondat",
            "Zeus",
            "Ascii",
            "Matsnu",
            "Alf:e5.spikeaex.rhh_pid",
            "Hydra",
            "Vawtrak",
            "Pinkslipbot",
            "Trojan-ransom.win32.blocker.jgb checkin",
            "Maltiverse",
            "Andromeda",
            "Citadel",
            "Xrat",
            "Win.trojan.agent-31853",
            "Infy",
            "Covid19",
            "Hawkeye",
            "Trojan.mydoom/muldrop",
            "Ramnit",
            "Nsis",
            "Win.ransomware.wanna-9769986-0",
            "Rostpay",
            "Plasma rat",
            "Searchmeup",
            "Gregory",
            "Slingshot",
            "Virtool",
            "Hidelink",
            "Betabot",
            "Opencandy",
            "Mydoom",
            "Chaos (elf)",
            "Nymaim",
            "Installcore",
            "Virtool:win32/injector.gen!bq",
            "Pykspa",
            "Cobalt strike",
            "Zbot",
            "Emotet",
            "Spitmo",
            "Worm:win32/fadok!rfn",
            "Vskimmer",
            "Trojanspy",
            "Prynt",
            "Tulach",
            "Pony",
            "Qakbot",
            "Alinaos",
            "Xpire.info",
            "Kraken",
            "Neutrino",
            "Solar",
            "Win.ransomware.locky-7766366-0",
            "Ransom:win32/wannacrypt.h",
            "Trojandropper:win32/gamehack",
            "Trojan:win32/tiggre",
            "Simda",
            "Webtoolbar",
            "Cutwail"
          ],
          "industries": [
            "Transportation",
            "Government",
            "Legal",
            "Technology"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 21,
  "pulses": [
    {
      "id": "6953775a0aed71947ca3f90e",
      "name": "Ransom WannaCrypt- Hackers masquerade as a law firm | Social Engineering |",
      "description": "Hackers , likely Colorado State employees masquerading as legal, entities, social\nengineering, financial exchanges involved. Fraud. Dangerous enterprise. Found in an \u2018alleged \u2018 Plaintiff Law Firms malicious link discovered in old print out, also seen in earlier pulse. [OTX generated description: Adversaries may be able to evade detection and network filtering by blending in with existing traffic, as well as using web protocols, in order to avoid detection/network filtering. and other measures.]",
      "modified": "2026-01-29T06:09:08.504000",
      "created": "2025-12-30T06:55:22.105000",
      "tags": [
        "united",
        "urls",
        "moved",
        "files",
        "ip address",
        "gmt content",
        "x adblock",
        "encrypt",
        "backdoor",
        "bq dec",
        "virtool",
        "ipv4 add",
        "ascii text",
        "pattern match",
        "ck id",
        "mitre att",
        "meta",
        "general",
        "local",
        "path",
        "click",
        "strings",
        "unknown",
        "simplified",
        "etpro trojan",
        "possible virut",
        "dga nxdomain",
        "responses",
        "virus",
        "medium",
        "virustotal",
        "vipre",
        "baidu",
        "vitro",
        "drweb",
        "mcafee",
        "panda",
        "malware",
        "write",
        "dynamicloader",
        "msie",
        "windows nt",
        "slcc2",
        "media center",
        "yara rule",
        "simda",
        "internal",
        "learn",
        "name tactics",
        "suspicious",
        "informative",
        "command",
        "spawns",
        "defense evasion",
        "t1480 execution",
        "discovery att",
        "ck matrix",
        "network traffic",
        "t1071",
        "t1057",
        "hybrid",
        "yara detections",
        "composite",
        "av detections",
        "ids detections",
        "alerts",
        "analysis date",
        "file score",
        "none related",
        "passive dns",
        "hosting",
        "reverse dns",
        "location united",
        "title",
        "ences s",
        "data upload",
        "extraction",
        "status",
        "hostname add",
        "url analysis",
        "push",
        "present sep",
        "present may",
        "present jul",
        "present jan",
        "win32small dec",
        "ransom",
        "write c",
        "show",
        "search",
        "high",
        "et exploit",
        "probe ms17010",
        "eternal blue",
        "englewood colorado",
        "wannacry",
        "wannacrypt",
        "ransom",
        "wanna"
      ],
      "references": [
        "https://aws.hirecar.net/",
        "w32.virut.cf \u2022 win32.virut.am \u2022 virut.cf \u2022 http://w32.virut.cf \u2022http://w32.virut.cf/ \u2022 https://w32.virut.cf",
        "pandacookie2018.xyz",
        "Antivirus Detections: Win.Ransomware.Wanna-9769986-0 ,  Ransom:Win32/WannaCrypt.H",
        "IDS Detections: Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS",
        "DNS Lookup) Possible ETERNALBLUE Probe MS17-010 (MSF style) Possible ETERNALBLUE Probe MS17-010 (Generic Flags) ETERNALBLUE Probe Vulnerable System Response MS17-010 Possible ETERNALBLUE MS17-010 Heap Spray More Yara Detections WannaCry_Ransomware ,  Win32_Ransomware_WannaCry ,  Wanna_Cry_Ransomware_Generic ,  MS17_010_WanaCry_worm ,  stack_string More Alerts 25 Alerts suspicious_iocontrol_codes persistence_autorun persistence_autorun_tasks stealth_file suricata_alert antivm_generic_disk anomalous_deletefil",
        "Domains Contacted: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com \u2022\u2019survey-smiles.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Backdoor:Win32/Small.IR",
          "display_name": "Backdoor:Win32/Small.IR",
          "target": "/malware/Backdoor:Win32/Small.IR"
        },
        {
          "id": "Win.Trojan.Agent-31853",
          "display_name": "Win.Trojan.Agent-31853",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "Win.Ransomware.Wanna-9769986-0",
          "display_name": "Win.Ransomware.Wanna-9769986-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt.H",
          "display_name": "Ransom:Win32/WannaCrypt.H",
          "target": "/malware/Ransom:Win32/WannaCrypt.H"
        },
        {
          "id": "Virtool:Win32/Injector.gen!BQ",
          "display_name": "Virtool:Win32/Injector.gen!BQ",
          "target": "/malware/Virtool:Win32/Injector.gen!BQ"
        }
      ],
      "attack_ids": [
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        }
      ],
      "industries": [
        "Government",
        "Technology",
        "Legal"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 8605,
        "domain": 1228,
        "email": 2,
        "hostname": 1981,
        "FileHash-SHA256": 1617,
        "FileHash-SHA1": 184,
        "FileHash-MD5": 206,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 13825,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "122 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68705b9e13e074fa3c778902",
      "name": "check",
      "description": "",
      "modified": "2026-01-23T01:10:39.457000",
      "created": "2025-07-11T00:32:30.277000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 421,
        "FileHash-MD5": 25,
        "FileHash-SHA1": 22,
        "FileHash-SHA256": 133,
        "domain": 270,
        "hostname": 35
      },
      "indicator_count": 906,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 182,
      "modified_text": "128 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "688d5bab9ce44c4321064457",
      "name": "xloader",
      "description": "",
      "modified": "2026-01-12T23:06:55.682000",
      "created": "2025-08-02T00:28:27.331000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 388,
        "FileHash-MD5": 83,
        "FileHash-SHA1": 45,
        "FileHash-SHA256": 308,
        "domain": 392,
        "hostname": 107
      },
      "indicator_count": 1323,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 182,
      "modified_text": "139 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69312c4db6fe7eb34abd179d",
      "name": "BeeLineRouter.Net \u2022 Apple \u2022 Worms \u2022 Ransom \u2022 SpyWare",
      "description": "Direct- remotely accesses iOS devices. Same threat actors. Further research warranted.| \n\n#theyswarm #apple #worms #spyware #ransom #quasi",
      "modified": "2026-01-03T05:02:11.376000",
      "created": "2025-12-04T06:38:05.504000",
      "tags": [
        "worm",
        "readme.exe",
        "foto.pif",
        "z1nic.exe",
        "dynamicloader",
        "high",
        "windows",
        "checks",
        "named pipe",
        "http traffic",
        "ids detections",
        "yara detections",
        "alerts",
        "launch",
        "defense evasion",
        "ta0005",
        "files",
        "msie",
        "next dropped",
        "process name",
        "pe32",
        "intel",
        "ms windows",
        "unknown",
        "united",
        "tlsv1",
        "as14618",
        "top source",
        "top destination",
        "port",
        "destination",
        "source source",
        "matches rule",
        "hidden file",
        "extension",
        "connection",
        "http vary",
        "tulach",
        "url https",
        "indicator role",
        "active related",
        "ipv4",
        "url http",
        "macintosh",
        "intel mac",
        "os x",
        "search",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "bq dec",
        "virtool",
        "win32mydoom dec",
        "trojan",
        "win32cve dec",
        "avast avg",
        "mtb dec",
        "crlf line",
        "unicode text",
        "utf8",
        "ee fc",
        "ff d5",
        "yara rule",
        "ascii text",
        "f0 ff",
        "eb e1",
        "write",
        "malware",
        "suspicious",
        "observed dns",
        "query",
        "exploits",
        "sid name",
        "malware cve",
        "exif data",
        "show",
        "value exe",
        "next",
        "all ipv4",
        "pulse pulses",
        "passive dns",
        "urls",
        "reverse dns",
        "location united",
        "america flag",
        "ashburn",
        "status",
        "name servers",
        "ip address",
        "showing",
        "domain",
        "files ip",
        "windows nt",
        "slcc2",
        "media center",
        "medium",
        "simda",
        "internal",
        "local",
        "write c",
        "domain add",
        "ip whois",
        "registrar",
        "hostname",
        "present jul",
        "unknown ns",
        "present dec",
        "music",
        "servers",
        "hostname add",
        "pulse submit",
        "url analysis",
        "aaaa",
        "backdoor",
        "entries",
        "found",
        "next associated",
        "gmt connection",
        "control",
        "content type",
        "twitter",
        "certificate",
        "redirect date",
        "cache",
        "record value",
        "emails",
        "win32",
        "mtb may",
        "invalid url",
        "ransom",
        "trojanspy",
        "msil",
        "akamai",
        "expiration date",
        "body html",
        "present nov",
        "url add",
        "http",
        "files domain",
        "files related",
        "pulses none",
        "related tags",
        "present sep",
        "present oct",
        "flag",
        "analysis tip",
        "click",
        "windir",
        "openurl c",
        "prefetch2",
        "analysis",
        "tor analysis",
        "dns requests",
        "date",
        "domain address",
        "dynadot inc",
        "name server",
        "contacted hosts",
        "process details",
        "network traffic",
        "ck id",
        "show technique",
        "mitre att",
        "ck matrix",
        "t1566",
        "submitted url",
        "t1204",
        "learn",
        "name tactics",
        "informative",
        "adversaries",
        "command",
        "spawns",
        "access att",
        "t1566 phishing",
        "pattern match",
        "show process",
        "t1071",
        "t1057",
        "general",
        "path",
        "brian sabey",
        "christopher p ahmann",
        "quasi",
        "foundry",
        "helix",
        "remote attacks",
        "hit men",
        "sreredrum",
        "pleh"
      ],
      "references": [
        "apple.com \u2022 getsupport.apple.com \u2022",
        "https://www.idvd.eu/?cid=oas-japac-domains-applestore.com.cn/90.i.lolik.anyciona.patrolita.casse.897866 \u2022 oas-japac-domains-applestore.com.cn",
        "http://beelinerouter.net/",
        "Tulach - 114.114.114.114",
        "http://foundry2-lbl.dvr.dn2.n-helix.com",
        "foundry.com \u2022 helix. com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Worm:Win32/Fadok!rfn",
          "display_name": "Worm:Win32/Fadok!rfn",
          "target": "/malware/Worm:Win32/Fadok!rfn"
        },
        {
          "id": "VirTool:Win32/Injector.gen!BQ",
          "display_name": "VirTool:Win32/Injector.gen!BQ",
          "target": "/malware/VirTool:Win32/Injector.gen!BQ"
        },
        {
          "id": "Mydoom",
          "display_name": "Mydoom",
          "target": null
        },
        {
          "id": "Win.Spyware.88778-2",
          "display_name": "Win.Spyware.88778-2",
          "target": null
        },
        {
          "id": "Win.Malware.Delf-10008156-0",
          "display_name": "Win.Malware.Delf-10008156-0",
          "target": null
        },
        {
          "id": "Trojan.MyDoom/Muldrop",
          "display_name": "Trojan.MyDoom/Muldrop",
          "target": null
        },
        {
          "id": "VirTool:Win32/Obfuscator",
          "display_name": "VirTool:Win32/Obfuscator",
          "target": "/malware/VirTool:Win32/Obfuscator"
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1578",
          "name": "Modify Cloud Compute Infrastructure",
          "display_name": "T1578 - Modify Cloud Compute Infrastructure"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1410",
          "name": "Network Traffic Capture or Redirection",
          "display_name": "T1410 - Network Traffic Capture or Redirection"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1110",
          "name": "Brute Force",
          "display_name": "T1110 - Brute Force"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "TA0037",
          "name": "Command and Control",
          "display_name": "TA0037 - Command and Control"
        },
        {
          "id": "T1584.003",
          "name": "Virtual Private Server",
          "display_name": "T1584.003 - Virtual Private Server"
        },
        {
          "id": "T1583.002",
          "name": "DNS Server",
          "display_name": "T1583.002 - DNS Server"
        },
        {
          "id": "T1408",
          "name": "Disguise Root/Jailbreak Indicators",
          "display_name": "T1408 - Disguise Root/Jailbreak Indicators"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1147",
          "name": "Hidden Users",
          "display_name": "T1147 - Hidden Users"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 422,
        "FileHash-SHA1": 316,
        "FileHash-SHA256": 1950,
        "domain": 899,
        "URL": 6117,
        "email": 21,
        "hostname": 2037,
        "SSLCertFingerprint": 2,
        "CVE": 1
      },
      "indicator_count": 11765,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "148 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "688c8526be7a4df33863b5c5",
      "name": "VirusTotal - Shiz.ivr",
      "description": "*Win.Trojan.Shiz.ivr\n*PWS:Win32/Simda.D\n*virtool #injection#infostealer #network #cnc #block_not #virustotal_google #cnc #checking #procmem_yara\n#injection_inter_process\n#injection_create_remote_thread\n#antidebug_windows\n#multiple_useragents\n#network_fake_useragent\n#persistence_autorun\n#cape_detected_threat\n#antiav_detectfile\n#modify_proxy\n#deletes_self\n#infostealer_cookies\n#injection_createremotethread\n#suricata_alert\n~ vashti",
      "modified": "2025-08-31T08:01:04.297000",
      "created": "2025-08-01T09:13:10.510000",
      "tags": [
        "dynamicloader",
        "unknown",
        "msie",
        "windows nt",
        "slcc2",
        "media center",
        "suspicious",
        "search",
        "high",
        "show",
        "copy",
        "possible",
        "write",
        "internal",
        "malware",
        "push",
        "local",
        "next",
        "contacted",
        "domains",
        "pulses",
        "related tags",
        "file type",
        "date april",
        "pm size",
        "sha1 sha256",
        "imphash pehash",
        "virustotal api",
        "bq jul",
        "united",
        "trojan",
        "backdoor",
        "virtool",
        "cnc beacon",
        "entries",
        "path max",
        "passive dns",
        "next associated",
        "cookie",
        "twitter",
        "body",
        "date",
        "medium",
        "simda",
        "global"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 10303,
        "hostname": 1413,
        "FileHash-SHA256": 1868,
        "domain": 1877,
        "FileHash-MD5": 357,
        "FileHash-SHA1": 348,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 16168,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 149,
      "modified_text": "273 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "5daf09a6d16f1e2c5c594c22",
      "name": "Simda - Malware Domain Feed V2",
      "description": "Command and Control domains for malware known as Simda. These domains are extracted from malware sandbox reports using                             a Machine Learning model trained on a corpus of good and bad domains.",
      "modified": "2025-07-15T21:13:57.066000",
      "created": "2019-10-22T13:52:38.770000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 33,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "otxrobottwo",
        "id": "78495",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_78495/resized/80/avatar_ba5a8acdbd.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 209,
        "hostname": 5
      },
      "indicator_count": 214,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1085,
      "modified_text": "320 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6786a59af06fee17c8decf9d",
      "name": "netcfg",
      "description": "000ceafd276003f46d06828bb0459b3ccdc2b44013a313b69d6270a224199034",
      "modified": "2025-05-31T02:36:52.299000",
      "created": "2025-01-14T17:57:46.687000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 222,
        "domain": 216,
        "hostname": 4,
        "FileHash-SHA256": 1
      },
      "indicator_count": 443,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 182,
      "modified_text": "365 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67fb185eb96e9791cf24ced4",
      "name": "Shiz/Packy",
      "description": "",
      "modified": "2025-05-13T01:03:15.390000",
      "created": "2025-04-13T01:50:22.707000",
      "tags": [],
      "references": [
        "https://www.virustotal.com/graph/gf9fb2090ae8e450dadda45c0596ab774ed1984e89aab4679bc3fc02096e22fa3"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 26,
        "URL": 191,
        "domain": 344,
        "hostname": 2
      },
      "indicator_count": 563,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 182,
      "modified_text": "383 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "678349edca4868e4cf8b298b",
      "name": "tfdbpg",
      "description": "0000121f09166c3e1e001b833301977f3f9461f756b46818e1acf377edb2454f",
      "modified": "2025-01-12T04:49:49.365000",
      "created": "2025-01-12T04:49:49.365000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 237,
        "domain": 228,
        "hostname": 8,
        "FileHash-SHA256": 1
      },
      "indicator_count": 474,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 182,
      "modified_text": "504 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65d34c91868744aa1449fef2",
      "name": "Locky: File Deletion targeting incriminating archived files.",
      "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
      "modified": "2024-03-20T12:00:39.809000",
      "created": "2024-02-19T12:41:52.846000",
      "tags": [
        "it consultant",
        "uk collection",
        "dns intel",
        "ips collection",
        "suspicous ip",
        "whois file",
        "cname",
        "record type",
        "ttl value",
        "algorithm",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "whois lookup",
        "region create",
        "domain",
        "name server",
        "registrant name",
        "technical city",
        "region update",
        "united",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "ck id",
        "cookie",
        "meta",
        "february",
        "hybrid",
        "general",
        "click",
        "strings",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "dns replication",
        "code",
        "namecheap",
        "registrar abuse",
        "namecheap inc",
        "privacy service",
        "withheld",
        "privacy",
        "dnssec",
        "email",
        "first",
        "bodis",
        "unknown",
        "creation date",
        "search",
        "emails",
        "as397240",
        "date",
        "next",
        "all octoseek",
        "threat roundup",
        "january",
        "june",
        "historical ssl",
        "referrer",
        "contacted",
        "group",
        "execution",
        "phishing",
        "malware",
        "core",
        "malicious",
        "dark power",
        "play ransomware",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 linker",
        "gnu linker",
        "compiler",
        "info header",
        "name md5",
        "overlay",
        "passive dns",
        "entries",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "trojan",
        "location united",
        "query",
        "activity dns",
        "observed dns",
        "msie",
        "high",
        "copy",
        "write",
        "win32",
        "hashes",
        "host interaction",
        "sabey type",
        "hallrender",
        "brian sabey",
        "memory pattern",
        "http requests",
        "http method",
        "get response",
        "dns resolutions",
        "ip traffic",
        "domains",
        "mutex",
        "samplepath",
        "created",
        "shell commands",
        "r processes",
        "tree",
        "analyze",
        "hostnames",
        "url https",
        "samples",
        "hostname",
        "pattern urls",
        "memory",
        "pattern",
        "pattern domains",
        "roundup",
        "formbook",
        "mirai",
        "ben c",
        "injection",
        "server",
        "scan endpoints",
        "show",
        "august",
        "bq feb",
        "chrome",
        "precondition",
        "virtool",
        "downloadmr",
        "body",
        "status",
        "servers",
        "record value",
        "name servers",
        "showing",
        "mailrubar",
        "trojanclicker",
        "slcc2",
        "media center",
        "delete c",
        "malware beacon",
        "suspicious",
        "class",
        "internal",
        "local",
        "encrypt",
        "as15169 google",
        "gmt cache",
        "twitter",
        "rostpay",
        "date hash",
        "avast avg",
        "mtb may",
        "susp",
        "cryp",
        "win32upatre may",
        "mtb showing",
        "lowfi",
        "aaaa",
        "win32pcmega jan",
        "urlshortner dec",
        "urlshortner sep",
        "as133618",
        "nxdomain",
        "as133775 xiamen",
        "germany unknown",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "whois record",
        "ssl certificate",
        "tsara brashears",
        "resolutions",
        "critical risk",
        "apple phone",
        "unlocker",
        "shell code",
        "installer",
        "ursnif",
        "hacktool",
        "emotet",
        "tracker",
        "chaos",
        "ransomexx",
        "xor ddos",
        "xorddos",
        "mitre attack",
        "parent domain",
        "urls url",
        "siblings",
        "metro",
        "communicating",
        "collection",
        "dropped",
        "skynet",
        "youth",
        "com laude",
        "ltd dba",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "akamaias",
        "digitaloceanasn",
        "csc corporate",
        "pt mora",
        "univjos",
        "etisalat misr",
        "acurix networks",
        "pty ltd",
        "beijing baidu",
        "highly targeted",
        "http",
        "network hijacks",
        "redline stealer",
        "whois sslcert",
        "contacted urls",
        "whois whois",
        "september",
        "hidden cobra",
        "threats",
        "kimsuky",
        "service",
        "read c",
        "create c",
        "write c",
        "regsetvalueexa",
        "mozilla",
        "capture",
        "asnone",
        "domain http",
        "request",
        "malware dns",
        "lookup wannacry",
        "default",
        "ransom",
        "push",
        "playgame",
        "command",
        "email document",
        "exploit domain",
        "owner exploit",
        "kit exploit",
        "source file",
        "hacking tools",
        "hunting macro",
        "malware hosting",
        "memory scanning",
        "yara detections",
        "debug",
        "icmp traffic",
        "pdb path",
        "pe section",
        "low software",
        "packing t1045",
        "ransomware",
        "egregor",
        "find",
        "false",
        "psexec",
        "powershell",
        "qakbot",
        "qbot",
        "icedid"
      ],
      "references": [
        "redhatdelete.com",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Australia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "target": null
        },
        {
          "id": "Rostpay",
          "display_name": "Rostpay",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Mitre Attack",
          "display_name": "Mitre Attack",
          "target": null
        },
        {
          "id": "Chaos (ELF)",
          "display_name": "Chaos (ELF)",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/GameHack",
          "display_name": "TrojanDropper:Win32/GameHack",
          "target": "/malware/TrojanDropper:Win32/GameHack"
        },
        {
          "id": "Win.Ransomware.Locky-7766366-0",
          "display_name": "Win.Ransomware.Locky-7766366-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "ALF:E5.SpikeAex.rhh_pid",
          "display_name": "ALF:E5.SpikeAex.rhh_pid",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1107",
          "name": "File Deletion",
          "display_name": "T1107 - File Deletion"
        },
        {
          "id": "T1563",
          "name": "Remote Service Session Hijacking",
          "display_name": "T1563 - Remote Service Session Hijacking"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 57,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1848,
        "FileHash-SHA1": 1783,
        "FileHash-SHA256": 7170,
        "domain": 1649,
        "hostname": 1191,
        "email": 9,
        "URL": 729,
        "CVE": 2,
        "SSLCertFingerprint": 2,
        "CIDR": 1
      },
      "indicator_count": 14384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "802 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "qegynuv.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "qegynuv.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780274723.2071676
}