{
  "type": "Domain",
  "indicator": "rubyfalls.shop",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/rubyfalls.shop",
    "alexa": "http://www.alexa.com/siteinfo/rubyfalls.shop",
    "indicator": "rubyfalls.shop",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4036775868,
      "indicator": "rubyfalls.shop",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "6839003a3028827e1ebbfb1a",
          "name": "Tracking LummaC2 Infrastructure with Cats",
          "description": "The US Department of Justice and Microsoft disrupted LummaC2 infostealing-malware through domain seizures, taking down over 2,300 associated domains. The FBI and CISA released an advisory detailing LummaC2's tactics and indicators of compromise, including 114 domains. Analysis of these domains revealed common registration patterns, such as using Eastern European names and specific mail server hostnames. Notably, several domains featured an 'About Cats' landing page, with 58 additional domains sharing this characteristic and having high risk scores. These domains are suspected of distributing LummaC2 and other malware strains. Despite the takedown efforts, 41 of these domains remain active, highlighting the need for continued vigilance against LummaC2 infrastructure.",
          "modified": "2025-07-09T08:05:10.295000",
          "created": "2025-05-30T00:47:54.159000",
          "tags": [
            "domain seizures",
            "threat intelligence",
            "lummac2",
            "infrastructure tracking",
            "risk scoring",
            "infostealing malware",
            "cat-themed domains",
            "malware distribution"
          ],
          "references": [
            "https://www.domaintools.com/resources/blog/tracking-lummac2-infrastructure-with-cats"
          ],
          "public": 1,
          "adversary": "LummaC2",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "LummaC2",
              "display_name": "LummaC2",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1589",
              "name": "Gather Victim Identity Information",
              "display_name": "T1589 - Gather Victim Identity Information"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1102.001",
              "name": "Dead Drop Resolver",
              "display_name": "T1102.001 - Dead Drop Resolver"
            },
            {
              "id": "T1584.001",
              "name": "Domains",
              "display_name": "T1584.001 - Domains"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 62,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 20,
            "FileHash-SHA1": 63,
            "domain": 47
          },
          "indicator_count": 130,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386754,
          "modified_text": "327 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "683d4350bde5afe49b274f13",
          "name": "Tracking LummaC2 Infrastructure with Cats",
          "description": "",
          "modified": "2025-06-29T00:01:54.552000",
          "created": "2025-06-02T06:23:12.204000",
          "tags": [
            "domain seizures",
            "threat intelligence",
            "lummac2",
            "infrastructure tracking",
            "risk scoring",
            "infostealing malware",
            "cat-themed domains",
            "malware distribution"
          ],
          "references": [
            "https://www.domaintools.com/resources/blog/tracking-lummac2-infrastructure-with-cats"
          ],
          "public": 1,
          "adversary": "LummaC2",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "LummaC2",
              "display_name": "LummaC2",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1589",
              "name": "Gather Victim Identity Information",
              "display_name": "T1589 - Gather Victim Identity Information"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1102.001",
              "name": "Dead Drop Resolver",
              "display_name": "T1102.001 - Dead Drop Resolver"
            },
            {
              "id": "T1584.001",
              "name": "Domains",
              "display_name": "T1584.001 - Domains"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6839003a3028827e1ebbfb1a",
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 20,
            "FileHash-SHA1": 63,
            "URL": 1,
            "domain": 53,
            "hostname": 5
          },
          "indicator_count": 142,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 278,
          "modified_text": "337 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "683e8e4f37d4c4661d8afce4",
          "name": "IOC - Tracking LummaC2 Infrastructure with Cats",
          "description": "",
          "modified": "2025-06-29T00:01:54.552000",
          "created": "2025-06-03T05:55:27.051000",
          "tags": [
            "domain seizures",
            "threat intelligence",
            "lummac2",
            "infrastructure tracking",
            "risk scoring",
            "infostealing malware",
            "cat-themed domains",
            "malware distribution"
          ],
          "references": [
            "https://www.domaintools.com/resources/blog/tracking-lummac2-infrastructure-with-cats"
          ],
          "public": 1,
          "adversary": "LummaC2",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "LummaC2",
              "display_name": "LummaC2",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1589",
              "name": "Gather Victim Identity Information",
              "display_name": "T1589 - Gather Victim Identity Information"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1102.001",
              "name": "Dead Drop Resolver",
              "display_name": "T1102.001 - Dead Drop Resolver"
            },
            {
              "id": "T1584.001",
              "name": "Domains",
              "display_name": "T1584.001 - Domains"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6839003a3028827e1ebbfb1a",
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "celestre",
            "id": "295357",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 20,
            "FileHash-SHA1": 63,
            "URL": 1,
            "domain": 53,
            "hostname": 5
          },
          "indicator_count": 142,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 140,
          "modified_text": "337 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "672f6ed2b564f00b7c5cb13f",
          "name": "Threatfox Recent Additions",
          "description": "",
          "modified": "2025-06-13T19:00:02.811000",
          "created": "2024-11-09T14:16:50.032000",
          "tags": [],
          "references": [
            "",
            "https://threatfox.abuse.ch/export/csv/recent/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 96,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ameermane",
            "id": "77501",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 47587,
            "URL": 18714,
            "FileHash-SHA256": 36311,
            "FileHash-MD5": 1630,
            "FileHash-SHA1": 418,
            "hostname": 18190
          },
          "indicator_count": 122850,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 144,
          "modified_text": "353 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6839daaf46ec1e77510c4bfb",
          "name": "Tracking LummaC2 Infrastructure with Cats\u00a0 - DomainTools | Start Here. Know Now.",
          "description": "US Department of Justice (DOJ) announced the disruption of the LummaC2 infostealing-malware. This was achieved through sweeping domain seizures in coordination with Microsoft, which resulted in the takedown of over 2,300 domains associated with LummaC2 operations. \nDomains down, but adding for tracking and blocking initial compromised sites that lead to these IOCs.",
          "modified": "2025-05-30T16:19:59.214000",
          "created": "2025-05-30T16:19:59.214000",
          "tags": [
            "lummac2",
            "cats",
            "microsoft",
            "iocs",
            "domain seizures",
            "us department",
            "justice",
            "cisa",
            "ttps",
            "patterns"
          ],
          "references": [
            "https://www.domaintools.com/resources/blog/tracking-lummac2-infrastructure-with-cats/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Techronik",
            "id": "114546",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 5,
            "domain": 48
          },
          "indicator_count": 53,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 82,
          "modified_text": "367 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "https://www.domaintools.com/resources/blog/tracking-lummac2-infrastructure-with-cats",
        "https://threatfox.abuse.ch/export/csv/recent/",
        "https://www.domaintools.com/resources/blog/tracking-lummac2-infrastructure-with-cats/"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "LummaC2"
          ],
          "malware_families": [
            "Lummac2"
          ],
          "industries": []
        },
        "other": {
          "adversary": [
            "LummaC2"
          ],
          "malware_families": [
            "Lummac2",
            "Lumma stealer"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "6839003a3028827e1ebbfb1a",
      "name": "Tracking LummaC2 Infrastructure with Cats",
      "description": "The US Department of Justice and Microsoft disrupted LummaC2 infostealing-malware through domain seizures, taking down over 2,300 associated domains. The FBI and CISA released an advisory detailing LummaC2's tactics and indicators of compromise, including 114 domains. Analysis of these domains revealed common registration patterns, such as using Eastern European names and specific mail server hostnames. Notably, several domains featured an 'About Cats' landing page, with 58 additional domains sharing this characteristic and having high risk scores. These domains are suspected of distributing LummaC2 and other malware strains. Despite the takedown efforts, 41 of these domains remain active, highlighting the need for continued vigilance against LummaC2 infrastructure.",
      "modified": "2025-07-09T08:05:10.295000",
      "created": "2025-05-30T00:47:54.159000",
      "tags": [
        "domain seizures",
        "threat intelligence",
        "lummac2",
        "infrastructure tracking",
        "risk scoring",
        "infostealing malware",
        "cat-themed domains",
        "malware distribution"
      ],
      "references": [
        "https://www.domaintools.com/resources/blog/tracking-lummac2-infrastructure-with-cats"
      ],
      "public": 1,
      "adversary": "LummaC2",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "LummaC2",
          "display_name": "LummaC2",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1589",
          "name": "Gather Victim Identity Information",
          "display_name": "T1589 - Gather Victim Identity Information"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1102.001",
          "name": "Dead Drop Resolver",
          "display_name": "T1102.001 - Dead Drop Resolver"
        },
        {
          "id": "T1584.001",
          "name": "Domains",
          "display_name": "T1584.001 - Domains"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 62,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 20,
        "FileHash-SHA1": 63,
        "domain": 47
      },
      "indicator_count": 130,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386754,
      "modified_text": "327 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "683d4350bde5afe49b274f13",
      "name": "Tracking LummaC2 Infrastructure with Cats",
      "description": "",
      "modified": "2025-06-29T00:01:54.552000",
      "created": "2025-06-02T06:23:12.204000",
      "tags": [
        "domain seizures",
        "threat intelligence",
        "lummac2",
        "infrastructure tracking",
        "risk scoring",
        "infostealing malware",
        "cat-themed domains",
        "malware distribution"
      ],
      "references": [
        "https://www.domaintools.com/resources/blog/tracking-lummac2-infrastructure-with-cats"
      ],
      "public": 1,
      "adversary": "LummaC2",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "LummaC2",
          "display_name": "LummaC2",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1589",
          "name": "Gather Victim Identity Information",
          "display_name": "T1589 - Gather Victim Identity Information"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1102.001",
          "name": "Dead Drop Resolver",
          "display_name": "T1102.001 - Dead Drop Resolver"
        },
        {
          "id": "T1584.001",
          "name": "Domains",
          "display_name": "T1584.001 - Domains"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "6839003a3028827e1ebbfb1a",
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Tr1sa111",
        "id": "192483",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 20,
        "FileHash-SHA1": 63,
        "URL": 1,
        "domain": 53,
        "hostname": 5
      },
      "indicator_count": 142,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 278,
      "modified_text": "337 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "683e8e4f37d4c4661d8afce4",
      "name": "IOC - Tracking LummaC2 Infrastructure with Cats",
      "description": "",
      "modified": "2025-06-29T00:01:54.552000",
      "created": "2025-06-03T05:55:27.051000",
      "tags": [
        "domain seizures",
        "threat intelligence",
        "lummac2",
        "infrastructure tracking",
        "risk scoring",
        "infostealing malware",
        "cat-themed domains",
        "malware distribution"
      ],
      "references": [
        "https://www.domaintools.com/resources/blog/tracking-lummac2-infrastructure-with-cats"
      ],
      "public": 1,
      "adversary": "LummaC2",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "LummaC2",
          "display_name": "LummaC2",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1589",
          "name": "Gather Victim Identity Information",
          "display_name": "T1589 - Gather Victim Identity Information"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1102.001",
          "name": "Dead Drop Resolver",
          "display_name": "T1102.001 - Dead Drop Resolver"
        },
        {
          "id": "T1584.001",
          "name": "Domains",
          "display_name": "T1584.001 - Domains"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "6839003a3028827e1ebbfb1a",
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "celestre",
        "id": "295357",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 20,
        "FileHash-SHA1": 63,
        "URL": 1,
        "domain": 53,
        "hostname": 5
      },
      "indicator_count": 142,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 140,
      "modified_text": "337 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "672f6ed2b564f00b7c5cb13f",
      "name": "Threatfox Recent Additions",
      "description": "",
      "modified": "2025-06-13T19:00:02.811000",
      "created": "2024-11-09T14:16:50.032000",
      "tags": [],
      "references": [
        "",
        "https://threatfox.abuse.ch/export/csv/recent/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 96,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "ameermane",
        "id": "77501",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 47587,
        "URL": 18714,
        "FileHash-SHA256": 36311,
        "FileHash-MD5": 1630,
        "FileHash-SHA1": 418,
        "hostname": 18190
      },
      "indicator_count": 122850,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 144,
      "modified_text": "353 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6839daaf46ec1e77510c4bfb",
      "name": "Tracking LummaC2 Infrastructure with Cats\u00a0 - DomainTools | Start Here. Know Now.",
      "description": "US Department of Justice (DOJ) announced the disruption of the LummaC2 infostealing-malware. This was achieved through sweeping domain seizures in coordination with Microsoft, which resulted in the takedown of over 2,300 domains associated with LummaC2 operations. \nDomains down, but adding for tracking and blocking initial compromised sites that lead to these IOCs.",
      "modified": "2025-05-30T16:19:59.214000",
      "created": "2025-05-30T16:19:59.214000",
      "tags": [
        "lummac2",
        "cats",
        "microsoft",
        "iocs",
        "domain seizures",
        "us department",
        "justice",
        "cisa",
        "ttps",
        "patterns"
      ],
      "references": [
        "https://www.domaintools.com/resources/blog/tracking-lummac2-infrastructure-with-cats/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Techronik",
        "id": "114546",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 5,
        "domain": 48
      },
      "indicator_count": 53,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 82,
      "modified_text": "367 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "rubyfalls.shop",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "rubyfalls.shop",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780345493.1746159
}