{
  "type": "Domain",
  "indicator": "renviox.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/renviox.com",
    "alexa": "http://www.alexa.com/siteinfo/renviox.com",
    "indicator": "renviox.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4161444505,
      "indicator": "renviox.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 50,
      "pulses": [
        {
          "id": "691b8869e00b107fa20d9482",
          "name": "ThreatFix",
          "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
          "modified": "2026-01-23T11:01:07.175000",
          "created": "2025-11-17T20:41:11.797000",
          "tags": [
            "",
            "ransomware",
            "malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "",
              "display_name": "",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "zlepos384",
            "id": "103244",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8010,
            "FileHash-SHA1": 7922,
            "FileHash-SHA256": 8893,
            "URL": 57004,
            "domain": 36018,
            "hostname": 96473
          },
          "indicator_count": 214320,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "131 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693fb32fdcfa1b3ba2565caa",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-15",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 49 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-14T07:02:35.106000",
          "created": "2025-12-15T07:05:19.762000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 21,
            "domain": 3,
            "hostname": 1
          },
          "indicator_count": 25,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "140 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e45938d431f40d5e0fe1a",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-14",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 144 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-13T05:03:31.755000",
          "created": "2025-12-14T05:05:23.154000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 76,
            "domain": 9,
            "hostname": 6
          },
          "indicator_count": 91,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e0d4b455894d98940e5b2",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-14",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 141 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-13T01:02:59.421000",
          "created": "2025-12-14T01:05:15.004000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 75,
            "domain": 9,
            "hostname": 6
          },
          "indicator_count": 90,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dff42b301040a8b4afc64",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-14",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 143 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-13T00:05:56.401000",
          "created": "2025-12-14T00:05:22.280000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 75,
            "domain": 9,
            "hostname": 6
          },
          "indicator_count": 90,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693de31c8d706fb0a8d9cbbf",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-13",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 161 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-12T22:01:57.329000",
          "created": "2025-12-13T22:05:16.726000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 76,
            "hostname": 7,
            "domain": 9
          },
          "indicator_count": 92,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dd50b82d3a9426de10a97",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-13",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 161 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-12T21:02:35.560000",
          "created": "2025-12-13T21:05:15.469000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 76,
            "hostname": 7,
            "domain": 9
          },
          "indicator_count": 92,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693d9231a92379c4e37949e0",
          "name": "OSINT Volley 2025-12-13 - ClearFake/Aisuru/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(152), Aisuru(41), Cobalt Strike(37), Meterpreter(33), Unknown malware(23). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T16:03:53.969000",
          "created": "2025-12-13T16:20:01.261000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "aisuru",
            "cobalt-strike"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 85,
            "URL": 11,
            "domain": 13
          },
          "indicator_count": 109,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693d8422e079dd46dcd68980",
          "name": "OSINT Volley 2025-12-13 - ClearFake/Aisuru/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(153), Aisuru(51), Cobalt Strike(38), Meterpreter(38), Unknown malware(21). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T15:02:22.678000",
          "created": "2025-12-13T15:20:02.560000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "aisuru",
            "cobalt-strike"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 82,
            "URL": 11,
            "domain": 13
          },
          "indicator_count": 106,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693d76115e0849d991c72ec3",
          "name": "OSINT Volley 2025-12-13 - ClearFake/Aisuru/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(150), Aisuru(71), Cobalt Strike(38), Meterpreter(38), Unknown malware(22). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T14:04:47.432000",
          "created": "2025-12-13T14:20:01.853000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "aisuru",
            "cobalt-strike"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 75,
            "domain": 13,
            "URL": 9
          },
          "indicator_count": 97,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693d680102ccfc5e72ed6ec4",
          "name": "OSINT Volley 2025-12-13 - ClearFake/Aisuru/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(150), Aisuru(71), Unknown malware(44), Cobalt Strike(38), Meterpreter(38). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T13:00:29.343000",
          "created": "2025-12-13T13:20:01.498000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "aisuru",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 74,
            "domain": 13,
            "URL": 9
          },
          "indicator_count": 96,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693d5a06ed604ec9d77635e1",
          "name": "OSINT Volley 2025-12-13 - ClearFake/Aisuru/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(150), Aisuru(71), Unknown malware(44), Cobalt Strike(38), Meterpreter(38). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T12:05:39.496000",
          "created": "2025-12-13T12:20:22.896000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "aisuru",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 74,
            "domain": 13,
            "URL": 9
          },
          "indicator_count": 96,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693d4be10ef63bebfe99e4e1",
          "name": "OSINT Volley 2025-12-13 - ClearFake/Unknown malware/Aisuru",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(150), Unknown malware(80), Aisuru(71), Cobalt Strike(57), Meterpreter(40). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T11:00:54.864000",
          "created": "2025-12-13T11:20:01.857000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "unknown-malware",
            "aisuru"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 58,
            "URL": 9,
            "domain": 8
          },
          "indicator_count": 75,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693d3dd277be93a93b200637",
          "name": "OSINT Volley 2025-12-13 - ClearFake/Aisuru/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(150), Aisuru(71), Unknown malware(70), Cobalt Strike(41), Meterpreter(40). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T10:06:05.243000",
          "created": "2025-12-13T10:20:02.237000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "aisuru",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 77,
            "URL": 8,
            "domain": 8
          },
          "indicator_count": 93,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693d2fc1aaaa44abc8893362",
          "name": "OSINT Volley 2025-12-13 - ClearFake/Unknown malware/Aisuru",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(151), Unknown malware(70), Aisuru(61), Cobalt Strike(42), Meterpreter(40). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T09:03:25.097000",
          "created": "2025-12-13T09:20:01.504000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "unknown-malware",
            "aisuru"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 86,
            "domain": 8,
            "URL": 7
          },
          "indicator_count": 101,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693d13a1ff6db6c57cc9eb0b",
          "name": "OSINT Volley 2025-12-13 - AsyncRAT/Unknown Stealer/ClearFake",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: AsyncRAT(248), Unknown Stealer(196), ClearFake(150), Unknown malware(139), XWorm(124). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T07:04:39.303000",
          "created": "2025-12-13T07:20:01.854000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "asyncrat",
            "unknown-stealer",
            "clearfake"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 83,
            "domain": 4,
            "URL": 4
          },
          "indicator_count": 91,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693d05914058890a49c6de4b",
          "name": "OSINT Volley 2025-12-13 - AsyncRAT/Unknown Stealer/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: AsyncRAT(249), Unknown Stealer(200), Unknown malware(156), ClearFake(149), XWorm(127). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T06:02:21.809000",
          "created": "2025-12-13T06:20:01.684000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "asyncrat",
            "unknown-stealer",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 77,
            "domain": 4,
            "URL": 4
          },
          "indicator_count": 85,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693cf7811aff39ecc6555de4",
          "name": "OSINT Volley 2025-12-13 - AsyncRAT/Unknown Stealer/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: AsyncRAT(252), Unknown Stealer(200), Unknown malware(156), ClearFake(149), XWorm(128). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T05:01:10.183000",
          "created": "2025-12-13T05:20:01.850000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "asyncrat",
            "unknown-stealer",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 70,
            "domain": 4,
            "URL": 4
          },
          "indicator_count": 78,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ce971aeb2292183ac92f8",
          "name": "OSINT Volley 2025-12-13 - AsyncRAT/Unknown Stealer/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: AsyncRAT(252), Unknown Stealer(200), Unknown malware(156), ClearFake(150), XWorm(128). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T04:01:51.726000",
          "created": "2025-12-13T04:20:01.410000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "asyncrat",
            "unknown-stealer",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 66,
            "domain": 4,
            "URL": 4
          },
          "indicator_count": 74,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693cdb61f197537c75074686",
          "name": "OSINT Volley 2025-12-13 - AsyncRAT/Unknown Stealer/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: AsyncRAT(252), Unknown Stealer(200), Unknown malware(155), ClearFake(150), XWorm(128). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T03:00:26.732000",
          "created": "2025-12-13T03:20:01.946000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "asyncrat",
            "unknown-stealer",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 74,
            "domain": 4,
            "URL": 15
          },
          "indicator_count": 93,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693cbf414ea67637c115a24c",
          "name": "OSINT Volley 2025-12-13 - AsyncRAT/Unknown Stealer/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: AsyncRAT(252), Unknown Stealer(200), Unknown malware(155), ClearFake(150), XWorm(129). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T01:03:27.174000",
          "created": "2025-12-13T01:20:01.423000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "asyncrat",
            "unknown-stealer",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 69,
            "domain": 5,
            "URL": 16
          },
          "indicator_count": 90,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693cb13258dc88a884539aa8",
          "name": "OSINT Volley 2025-12-13 - AsyncRAT/Unknown Stealer/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: AsyncRAT(252), Unknown Stealer(200), Unknown malware(155), ClearFake(151), XWorm(128). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T00:02:51.635000",
          "created": "2025-12-13T00:20:02.368000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "asyncrat",
            "unknown-stealer",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 66,
            "domain": 5,
            "URL": 19
          },
          "indicator_count": 90,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ca3210d9a86b447994f55",
          "name": "OSINT Volley 2025-12-12 - AsyncRAT/Unknown Stealer/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: AsyncRAT(252), Unknown Stealer(200), Unknown malware(155), ClearFake(151), XWorm(128). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-11T23:02:58.492000",
          "created": "2025-12-12T23:20:01.534000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "asyncrat",
            "unknown-stealer",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 72,
            "domain": 5,
            "URL": 19
          },
          "indicator_count": 96,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693c87018b5a66fff06e2bee",
          "name": "OSINT Volley 2025-12-12 - AsyncRAT/Unknown Stealer/ClearFake",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: AsyncRAT(255), Unknown Stealer(199), ClearFake(150), Unknown malware(143), XWorm(127). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-11T21:01:39.704000",
          "created": "2025-12-12T21:20:01.519000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "asyncrat",
            "unknown-stealer",
            "clearfake"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 66,
            "domain": 4,
            "URL": 19
          },
          "indicator_count": 89,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e12a3a27b470af6bc3ead",
          "name": "Malware Filter - Phishing List - 13-12-2025",
          "description": "",
          "modified": "2025-12-14T01:28:03.931000",
          "created": "2025-12-14T01:28:03.931000",
          "tags": [],
          "references": [
            "https://malware-filter.gitlab.io/malware-filter/phishing-filter-domains.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 213,
            "domain": 119
          },
          "indicator_count": 332,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1626,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693df2568eb5203a8d7a15f3",
          "name": "PreCog Sweep - 2025-12-13 23h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T23:10:14.009000",
          "created": "2025-12-13T23:10:14.009000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 104,
            "domain": 9,
            "URL": 10
          },
          "indicator_count": 123,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693deffdf6814f5597cb8a13",
          "name": "PreCog Sweep - 2025-12-13 23h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T23:00:13.942000",
          "created": "2025-12-13T23:00:13.942000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693deda6c55851a539efee79",
          "name": "PreCog Sweep - 2025-12-13 22h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T22:50:14.464000",
          "created": "2025-12-13T22:50:14.464000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693deb4ee8ee261652dc5533",
          "name": "PreCog Sweep - 2025-12-13 22h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T22:40:14.315000",
          "created": "2025-12-13T22:40:14.315000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693de8f698ba09dc3770a5f9",
          "name": "PreCog Sweep - 2025-12-13 22h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T22:30:14.241000",
          "created": "2025-12-13T22:30:14.241000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693de69d1b70ee34fb7ccff0",
          "name": "PreCog Sweep - 2025-12-13 22h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T22:20:13.854000",
          "created": "2025-12-13T22:20:13.854000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693de445c6b2ab79050efa16",
          "name": "PreCog Sweep - 2025-12-13 22h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T22:10:13.928000",
          "created": "2025-12-13T22:10:13.928000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693de1f00193794ae9235789",
          "name": "PreCog Sweep - 2025-12-13 22h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T22:00:16.069000",
          "created": "2025-12-13T22:00:16.069000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ddf96092bc9436510fc74",
          "name": "PreCog Sweep - 2025-12-13 21h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T21:50:14.172000",
          "created": "2025-12-13T21:50:14.172000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ddd3dd344ad28418f7d55",
          "name": "PreCog Sweep - 2025-12-13 21h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T21:40:13.367000",
          "created": "2025-12-13T21:40:13.367000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ddae62f18da26d6c660c8",
          "name": "PreCog Sweep - 2025-12-13 21h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T21:30:14.340000",
          "created": "2025-12-13T21:30:14.340000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dd88d397503a06f538cde",
          "name": "PreCog Sweep - 2025-12-13 21h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T21:20:13.780000",
          "created": "2025-12-13T21:20:13.780000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dd6360e61dd1c0e135e66",
          "name": "PreCog Sweep - 2025-12-13 21h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T21:10:13.509000",
          "created": "2025-12-13T21:10:13.509000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 107,
            "URL": 13,
            "domain": 14
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dd3df19e4cd8179e09b1b",
          "name": "PreCog Sweep - 2025-12-13 21h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T21:00:15.020000",
          "created": "2025-12-13T21:00:15.020000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 108,
            "domain": 14,
            "URL": 12
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dd186e7deb15f34fc0b2c",
          "name": "PreCog Sweep - 2025-12-13 20h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T20:50:14.107000",
          "created": "2025-12-13T20:50:14.107000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 108,
            "domain": 14,
            "URL": 12
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dcf2e163c03d9de56f2e2",
          "name": "PreCog Sweep - 2025-12-13 20h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T20:40:14.158000",
          "created": "2025-12-13T20:40:14.158000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 108,
            "domain": 14,
            "URL": 12
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dccd5bc4052268d3777ae",
          "name": "PreCog Sweep - 2025-12-13 20h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T20:30:13.912000",
          "created": "2025-12-13T20:30:13.912000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 108,
            "domain": 14,
            "URL": 12
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dca7c608330c0b9e68a8f",
          "name": "PreCog Sweep - 2025-12-13 20h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T20:20:12.629000",
          "created": "2025-12-13T20:20:12.629000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 108,
            "domain": 14,
            "URL": 12
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dc825021c7b2914815a89",
          "name": "PreCog Sweep - 2025-12-13 20h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T20:10:13.430000",
          "created": "2025-12-13T20:10:13.430000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 108,
            "domain": 14,
            "URL": 12
          },
          "indicator_count": 134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dc5ceeda88e3c7030dac2",
          "name": "PreCog Sweep - 2025-12-13 20h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T20:00:14.709000",
          "created": "2025-12-13T20:00:14.709000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 235,
            "URL": 13,
            "domain": 31
          },
          "indicator_count": 279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dc375b6f4472c65185e4c",
          "name": "PreCog Sweep - 2025-12-13 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T19:50:13.888000",
          "created": "2025-12-13T19:50:13.888000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 235,
            "URL": 13,
            "domain": 31
          },
          "indicator_count": 279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dc11d0c6306d8f56bc92c",
          "name": "PreCog Sweep - 2025-12-13 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T19:40:13.782000",
          "created": "2025-12-13T19:40:13.782000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 235,
            "URL": 13,
            "domain": 31
          },
          "indicator_count": 279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dbec5b53c4e1843fc4c19",
          "name": "PreCog Sweep - 2025-12-13 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T19:30:13.848000",
          "created": "2025-12-13T19:30:13.848000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 235,
            "URL": 13,
            "domain": 31
          },
          "indicator_count": 279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dbc6df4cd6957e953cfb4",
          "name": "PreCog Sweep - 2025-12-13 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T19:20:13.456000",
          "created": "2025-12-13T19:20:13.456000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 235,
            "URL": 13,
            "domain": 31
          },
          "indicator_count": 279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dba169f8f16ced9b90e1c",
          "name": "PreCog Sweep - 2025-12-13 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-13T19:10:14.168000",
          "created": "2025-12-13T19:10:14.168000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 235,
            "URL": 13,
            "domain": 31
          },
          "indicator_count": 279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://malware-filter.gitlab.io/malware-filter/phishing-filter-domains.txt",
        "https://github.com/pduggusa/dugganusa-research",
        "https://analytics.dugganusa.com/api/v1/stix/master"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            ""
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 50,
  "pulses": [
    {
      "id": "691b8869e00b107fa20d9482",
      "name": "ThreatFix",
      "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
      "modified": "2026-01-23T11:01:07.175000",
      "created": "2025-11-17T20:41:11.797000",
      "tags": [
        "",
        "ransomware",
        "malware"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "",
          "display_name": "",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "zlepos384",
        "id": "103244",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8010,
        "FileHash-SHA1": 7922,
        "FileHash-SHA256": 8893,
        "URL": 57004,
        "domain": 36018,
        "hostname": 96473
      },
      "indicator_count": 214320,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 44,
      "modified_text": "131 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693fb32fdcfa1b3ba2565caa",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-15",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 49 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-14T07:02:35.106000",
      "created": "2025-12-15T07:05:19.762000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 21,
        "domain": 3,
        "hostname": 1
      },
      "indicator_count": 25,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "140 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693e45938d431f40d5e0fe1a",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-14",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 144 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-13T05:03:31.755000",
      "created": "2025-12-14T05:05:23.154000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 76,
        "domain": 9,
        "hostname": 6
      },
      "indicator_count": 91,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "141 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693e0d4b455894d98940e5b2",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-14",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 141 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-13T01:02:59.421000",
      "created": "2025-12-14T01:05:15.004000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 75,
        "domain": 9,
        "hostname": 6
      },
      "indicator_count": 90,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 198,
      "modified_text": "141 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693dff42b301040a8b4afc64",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-14",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 143 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-13T00:05:56.401000",
      "created": "2025-12-14T00:05:22.280000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 75,
        "domain": 9,
        "hostname": 6
      },
      "indicator_count": 90,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "141 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693de31c8d706fb0a8d9cbbf",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-13",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 161 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-12T22:01:57.329000",
      "created": "2025-12-13T22:05:16.726000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 76,
        "hostname": 7,
        "domain": 9
      },
      "indicator_count": 92,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "141 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693dd50b82d3a9426de10a97",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-13",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 161 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-12T21:02:35.560000",
      "created": "2025-12-13T21:05:15.469000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 76,
        "hostname": 7,
        "domain": 9
      },
      "indicator_count": 92,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "141 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693d9231a92379c4e37949e0",
      "name": "OSINT Volley 2025-12-13 - ClearFake/Aisuru/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(152), Aisuru(41), Cobalt Strike(37), Meterpreter(33), Unknown malware(23). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-12T16:03:53.969000",
      "created": "2025-12-13T16:20:01.261000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "aisuru",
        "cobalt-strike"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 85,
        "URL": 11,
        "domain": 13
      },
      "indicator_count": 109,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "142 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693d8422e079dd46dcd68980",
      "name": "OSINT Volley 2025-12-13 - ClearFake/Aisuru/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(153), Aisuru(51), Cobalt Strike(38), Meterpreter(38), Unknown malware(21). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-12T15:02:22.678000",
      "created": "2025-12-13T15:20:02.560000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "aisuru",
        "cobalt-strike"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 82,
        "URL": 11,
        "domain": 13
      },
      "indicator_count": 106,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "142 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693d76115e0849d991c72ec3",
      "name": "OSINT Volley 2025-12-13 - ClearFake/Aisuru/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(150), Aisuru(71), Cobalt Strike(38), Meterpreter(38), Unknown malware(22). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-12T14:04:47.432000",
      "created": "2025-12-13T14:20:01.853000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "aisuru",
        "cobalt-strike"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 75,
        "domain": 13,
        "URL": 9
      },
      "indicator_count": 97,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "142 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "renviox.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "renviox.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780505555.6004045
}