{
  "type": "Domain",
  "indicator": "sample.py",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/sample.py",
    "alexa": "http://www.alexa.com/siteinfo/sample.py",
    "indicator": "sample.py",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3390782637,
      "indicator": "sample.py",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "6a0eac9ae62f3f9f50ca0d18",
          "name": "test/recall VirusTotal report                    for App_20250512084741811.apk",
          "description": "May 12,2025",
          "modified": "2026-05-21T07:00:40.184000",
          "created": "2026-05-21T06:56:26.458000",
          "tags": [
            "file type",
            "ascii"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1406",
              "name": "Obfuscated Files or Information",
              "display_name": "T1406 - Obfuscated Files or Information"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 4,
            "FileHash-MD5": 101,
            "FileHash-SHA1": 99,
            "FileHash-SHA256": 799,
            "domain": 187,
            "URL": 142,
            "hostname": 24
          },
          "indicator_count": 1356,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 65,
          "modified_text": "10 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0eac9bd286b53466d6e28f",
          "name": "test/recall VirusTotal report                    for App_20250512084741811.apk",
          "description": "May 12,2025",
          "modified": "2026-05-21T06:56:27.437000",
          "created": "2026-05-21T06:56:27.437000",
          "tags": [
            "file type",
            "ascii"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1406",
              "name": "Obfuscated Files or Information",
              "display_name": "T1406 - Obfuscated Files or Information"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 4,
            "FileHash-MD5": 38,
            "FileHash-SHA1": 37,
            "FileHash-SHA256": 741,
            "domain": 187,
            "URL": 142,
            "hostname": 24
          },
          "indicator_count": 1173,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 65,
          "modified_text": "10 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0e9725b323ae1350c36488",
          "name": "no comment",
          "description": "",
          "modified": "2026-05-21T06:52:08.577000",
          "created": "2026-05-21T05:24:53.947000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 366,
            "FileHash-SHA1": 366,
            "FileHash-SHA256": 5078,
            "IPv4": 44,
            "URL": 2414,
            "domain": 1305,
            "hostname": 366,
            "CIDR": 1,
            "email": 2,
            "Mutex": 1
          },
          "indicator_count": 9943,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "10 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d3522448a6a2faaa9fd792",
          "name": "VirusTotal report\n                    for download.js",
          "description": "><<< full report on Sigma, a new generation of malware, has been published on the website of the University of South Africa's Security Research Centre (Sarac), based in the capital, Pretoria.\u20ac>> united states. Beyond Theory. e p o a e . Epoch",
          "modified": "2026-05-06T06:03:26.437000",
          "created": "2026-04-06T06:26:44.786000",
          "tags": [
            "mitre attack",
            "network info",
            "file type",
            "sigma",
            "program",
            "t1055 process",
            "overview",
            "dropped info",
            "processes extra",
            "overview zenbox",
            "malicious",
            "next",
            "in a",
            "create",
            "manager",
            "docker",
            "5 dev",
            "k8s configmap",
            "profiles",
            "etcd",
            "get https",
            "https",
            "refresh",
            "cookie",
            "ascii text",
            "crlf line",
            "text text",
            "ms windows",
            "vista event",
            "windows event",
            "thumbprint",
            "windows sandbox",
            "calls process",
            "pe file",
            "drops pe",
            "sample",
            "pe32",
            "spawns",
            "aslr",
            "persistence",
            "info",
            "creates",
            "performs dns",
            "default",
            "shell folders",
            "folders",
            "parent pid",
            "full path",
            "command line",
            "inprocserver32",
            "registry keys",
            "k netsvcs",
            "nothing",
            "mensaje",
            "wps office",
            "extra info",
            "drops",
            "defense evasion",
            "binary",
            "window"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/026281c7651d49c77c597d1843578b4578deac3fb8c10be3977371f140b54690_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456178&Signature=veZ5ILWvDbljstqg4NlX%2Bxs8GT3FFuOKYzQc%2B27Rfrzrxz9KINRfg5iEd%2FTD%2FJh0%2Bq%2BUFppfHwGwnnMNhD99MoqLrX735IHzqHRH3Y%2BhrlHexlMj6uTX%2FhuA91WtmQoFu8u8NtWjsAldaYDAJjFHT7HCenKy%2BmD%2FVHzSvfzxaf4d%2FZtoqDdCpPzDigdhx%2BpKQUOSIw0wEDklMmjQ8OQnKdK9RXK5duMVg%2Fwd7u7HVHNa",
            "https://vtbehaviour.commondatastorage.googleapis.com/026281c7651d49c77c597d1843578b4578deac3fb8c10be3977371f140b54690_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456268&Signature=r6fOkWGbwBX8z6YDvUFYQnPc8efKUXVyW0Ma97Qze1Gg5yigm12abg4Ohbydi7izPRODvv6sVLGy9Uj3%2FKSBJY3SoMgbLkj5YofXLKyp40m%2B32vj%2Boml5b0R%2FYrwd7rcA8dzMAuMKZpQ04wgR%2BiSh772Z%2BZ34H2CYZZnjpJoUC49ip8c4%2FUDETK%2BrFZMZqerVs2ONWDAzCMzN%2BvpWHlLkuAH7n2fTCOTvtO43TMqTzE5",
            "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456681&Signature=Mcrv0JEeKTzfxc7JwD4u6K1dNY8liXAX1tF2i91bXpymU0E%2FlRM95joj0ZuMk2A82ekHHzgKJbSxrkjVIutcPfV%2FYWPOj1or9HVjXg4Jq6QJb7fmWG5%2BqUxcfMqz8D7UN8v0FFVTc%2F%2FP3Sv3PpE3%2FKIhPcdMc1SodC9krYB%2Bbdj1obcveSDLlBtXgl9wP%2B7SuYub12drNzeyC9UKw%2FX0n7vZpU3JLAiYznAMTB",
            "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456701&Signature=t3Xqew0bsV61nmgncFTOCX%2FtqVKoAMgUft1dTGFLOFu7%2Fw4fbqeYn3laYdKEN6S%2BK7DF5nDi%2BN6pZq%2Be%2FsOZjAHgy821VBDeXqJaq6BdPAlT6fXrqDPaTghd9A00rdfDtOXh6Zy%2Bl5f16NPFVSl8FRZqU6GLhD%2B%2BSo%2FIP1XbQBHhcyOPh7nfc%2F8BxsyypNTadLDWEEJqVPSKFTVYwIagyVlTMD59xYMUtP8L2Ogdm9mJICbv",
            "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456734&Signature=Twrc6n%2BEyYc3IkPf4BD0CucGYLqOW4lxcGi2ZNxHRk7tNezVNxxouYRnGIr3OFeByvpf87X6oDI2BVrHR8er8NmM4CFpWpyRrf7xJh%2FZ6Vca48ROgTEWVHlnjgW0jVMzSe9TZOnN3zpmnpw37X95of0%2BzE6e4Fpl96po0RZcvPRC0G%2BqbKKwb%2FhIAspbkpn76RKrHyf%2FCb8aZ21ec7FwUJa%2BAZ%2FolkR0TdqCHOXyBcBQQ5",
            "https://vtbehaviour.commondatastorage.googleapis.com/0000fd39c79ba7e0b6f7ed3a181308cb8ac141672370d8f2f2e2f5faba8f93eb_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456766&Signature=fhEgpRoSszxXiIBuHWVEId9w1CwC9EnIKxPCKHEQMqEzppF90L%2B%2FlxW%2FywCNH6CMqGY1o9mJvTVmLXyypm1kzfmWsyA80dWPTGIRRYKfqvQ3Nng8wj93UHAEQuxrv4kfCNpUBBjn1WDnmQhRTooluOfdTIrQ10pjymrCYCKxOAFwm5bbvSKJ0%2BtX3rYiPf3fD%2BRRO9heg7G6MndwBJE2WMOzyy6vo8lgQCLwHAh4rCiDobnbPC8XTy6osE1J",
            "https://vtbehaviour.commondatastorage.googleapis.com/0000fd39c79ba7e0b6f7ed3a181308cb8ac141672370d8f2f2e2f5faba8f93eb_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456802&Signature=imED1VqYi14phTIENcdipBYjA%2BPgkL01TfJ1OydtY11LRS0lWv7THCPLLrLTkqq5ZoqxfCHCpuGqhWbabkW%2FSywvmyfhLD8TAvNRo0A%2Fdc27m6nC815oX%2BMHPVKhiTkshZH2KFL5rPe%2FQN81hxksJ07blNlH%2FGB6mG4fnRkg4rmqjT0QFA0yYvzH0bBAtM5ZmMRpoIg7zab6oVeuUuqroFECb2%2Fl3KcRdgZm2RQcf%2BvoJW",
            "https://vtbehaviour.commondatastorage.googleapis.com/0002815bed9019ec43e804f3eb7436b82b133ae60fce110cbbadae8ed8be5b3e_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456853&Signature=ohh65FvVsmXmQYu%2BJk1T4eXJGcdQGvMivSh5TmeHZLoDT%2ByKeGjHrEPJLhUqlYbxRx8n2cI91TyF9CGdex%2F461K5YKhHcc1nzbCf%2BHknI5sKA%2FMDvRrmPb0DYDVnExub3GBqS92stLwDSfSKYmbg3%2Bewiypp3nNLEzgg1XFvXV%2Bu%2Bk%2F4EG8y495NBtU%2F5%2Fh3oLc%2F0NDQfdQWmwE%2FuiC9lWax%2FmZm7V2%2Bap03q3xN",
            "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456905&Signature=RYIw5qZjecwIW0t7r5f%2BW29otPot2E4%2FAtLi37l8zcqFvx5%2B%2F9fgG%2B1Ay2Srf3y63cFKycTp%2BPmZvlwpImAkOOt4%2FBgJ7020dTOz%2FLOWUt6aeKt5xvjqwwkju5zlpLraECdTpENMPV436aJoAh1I2kbPY6oHixcY%2BW1t1E4XcpCMLPlEQOgQmoVly6vDIA4BFHjHbrRd%2FpgtZExPke2Y%2FXgggLW75UrBbd",
            "https://vtbehaviour.commondatastorage.googleapis.com/0000fd39c79ba7e0b6f7ed3a181308cb8ac141672370d8f2f2e2f5faba8f93eb_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456942&Signature=CyFvPFvbJhEdaWGF5he4cjzXT2%2FgvcmLJtVWaxv%2BNDzHPqLCNte56ZKxxP6mxUJPRZOpew0513JF50Ks8VL3kYoD566k1EAY27gm%2FdAS2N7xeaKV%2FdmihrhDfLdb2wqlXciSx3fb9Kf4z4T%2F4Kf9%2FSGh6lka0UFtlvIBzlq2OGtr0n6YEpVNHQG6L7jGn4adPJ1P8Zxb0ozprtOGnCXztODTwURwVPyD9asMhojWns2L1ssNl0rH0GQAAY"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA1": 30,
            "FileHash-SHA256": 143,
            "URL": 103,
            "domain": 19,
            "hostname": 130,
            "email": 2
          },
          "indicator_count": 453,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "25 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62221d71474b323d486dc3f2",
          "name": "WTF 2022",
          "description": "",
          "modified": "2022-04-03T00:00:55.161000",
          "created": "2022-03-04T14:08:49.518000",
          "tags": [],
          "references": [
            "WTF.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 587,
            "URL": 668,
            "hostname": 613,
            "domain": 1320,
            "FileHash-MD5": 59,
            "FileHash-SHA1": 2
          },
          "indicator_count": 3249,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1519 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456681&Signature=Mcrv0JEeKTzfxc7JwD4u6K1dNY8liXAX1tF2i91bXpymU0E%2FlRM95joj0ZuMk2A82ekHHzgKJbSxrkjVIutcPfV%2FYWPOj1or9HVjXg4Jq6QJb7fmWG5%2BqUxcfMqz8D7UN8v0FFVTc%2F%2FP3Sv3PpE3%2FKIhPcdMc1SodC9krYB%2Bbdj1obcveSDLlBtXgl9wP%2B7SuYub12drNzeyC9UKw%2FX0n7vZpU3JLAiYznAMTB",
        "https://vtbehaviour.commondatastorage.googleapis.com/0002815bed9019ec43e804f3eb7436b82b133ae60fce110cbbadae8ed8be5b3e_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456853&Signature=ohh65FvVsmXmQYu%2BJk1T4eXJGcdQGvMivSh5TmeHZLoDT%2ByKeGjHrEPJLhUqlYbxRx8n2cI91TyF9CGdex%2F461K5YKhHcc1nzbCf%2BHknI5sKA%2FMDvRrmPb0DYDVnExub3GBqS92stLwDSfSKYmbg3%2Bewiypp3nNLEzgg1XFvXV%2Bu%2Bk%2F4EG8y495NBtU%2F5%2Fh3oLc%2F0NDQfdQWmwE%2FuiC9lWax%2FmZm7V2%2Bap03q3xN",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456701&Signature=t3Xqew0bsV61nmgncFTOCX%2FtqVKoAMgUft1dTGFLOFu7%2Fw4fbqeYn3laYdKEN6S%2BK7DF5nDi%2BN6pZq%2Be%2FsOZjAHgy821VBDeXqJaq6BdPAlT6fXrqDPaTghd9A00rdfDtOXh6Zy%2Bl5f16NPFVSl8FRZqU6GLhD%2B%2BSo%2FIP1XbQBHhcyOPh7nfc%2F8BxsyypNTadLDWEEJqVPSKFTVYwIagyVlTMD59xYMUtP8L2Ogdm9mJICbv",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000fd39c79ba7e0b6f7ed3a181308cb8ac141672370d8f2f2e2f5faba8f93eb_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456766&Signature=fhEgpRoSszxXiIBuHWVEId9w1CwC9EnIKxPCKHEQMqEzppF90L%2B%2FlxW%2FywCNH6CMqGY1o9mJvTVmLXyypm1kzfmWsyA80dWPTGIRRYKfqvQ3Nng8wj93UHAEQuxrv4kfCNpUBBjn1WDnmQhRTooluOfdTIrQ10pjymrCYCKxOAFwm5bbvSKJ0%2BtX3rYiPf3fD%2BRRO9heg7G6MndwBJE2WMOzyy6vo8lgQCLwHAh4rCiDobnbPC8XTy6osE1J",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456905&Signature=RYIw5qZjecwIW0t7r5f%2BW29otPot2E4%2FAtLi37l8zcqFvx5%2B%2F9fgG%2B1Ay2Srf3y63cFKycTp%2BPmZvlwpImAkOOt4%2FBgJ7020dTOz%2FLOWUt6aeKt5xvjqwwkju5zlpLraECdTpENMPV436aJoAh1I2kbPY6oHixcY%2BW1t1E4XcpCMLPlEQOgQmoVly6vDIA4BFHjHbrRd%2FpgtZExPke2Y%2FXgggLW75UrBbd",
        "https://vtbehaviour.commondatastorage.googleapis.com/026281c7651d49c77c597d1843578b4578deac3fb8c10be3977371f140b54690_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456268&Signature=r6fOkWGbwBX8z6YDvUFYQnPc8efKUXVyW0Ma97Qze1Gg5yigm12abg4Ohbydi7izPRODvv6sVLGy9Uj3%2FKSBJY3SoMgbLkj5YofXLKyp40m%2B32vj%2Boml5b0R%2FYrwd7rcA8dzMAuMKZpQ04wgR%2BiSh772Z%2BZ34H2CYZZnjpJoUC49ip8c4%2FUDETK%2BrFZMZqerVs2ONWDAzCMzN%2BvpWHlLkuAH7n2fTCOTvtO43TMqTzE5",
        "https://vtbehaviour.commondatastorage.googleapis.com/026281c7651d49c77c597d1843578b4578deac3fb8c10be3977371f140b54690_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456178&Signature=veZ5ILWvDbljstqg4NlX%2Bxs8GT3FFuOKYzQc%2B27Rfrzrxz9KINRfg5iEd%2FTD%2FJh0%2Bq%2BUFppfHwGwnnMNhD99MoqLrX735IHzqHRH3Y%2BhrlHexlMj6uTX%2FhuA91WtmQoFu8u8NtWjsAldaYDAJjFHT7HCenKy%2BmD%2FVHzSvfzxaf4d%2FZtoqDdCpPzDigdhx%2BpKQUOSIw0wEDklMmjQ8OQnKdK9RXK5duMVg%2Fwd7u7HVHNa",
        "WTF.pdf",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000fd39c79ba7e0b6f7ed3a181308cb8ac141672370d8f2f2e2f5faba8f93eb_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456942&Signature=CyFvPFvbJhEdaWGF5he4cjzXT2%2FgvcmLJtVWaxv%2BNDzHPqLCNte56ZKxxP6mxUJPRZOpew0513JF50Ks8VL3kYoD566k1EAY27gm%2FdAS2N7xeaKV%2FdmihrhDfLdb2wqlXciSx3fb9Kf4z4T%2F4Kf9%2FSGh6lka0UFtlvIBzlq2OGtr0n6YEpVNHQG6L7jGn4adPJ1P8Zxb0ozprtOGnCXztODTwURwVPyD9asMhojWns2L1ssNl0rH0GQAAY",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456734&Signature=Twrc6n%2BEyYc3IkPf4BD0CucGYLqOW4lxcGi2ZNxHRk7tNezVNxxouYRnGIr3OFeByvpf87X6oDI2BVrHR8er8NmM4CFpWpyRrf7xJh%2FZ6Vca48ROgTEWVHlnjgW0jVMzSe9TZOnN3zpmnpw37X95of0%2BzE6e4Fpl96po0RZcvPRC0G%2BqbKKwb%2FhIAspbkpn76RKrHyf%2FCb8aZ21ec7FwUJa%2BAZ%2FolkR0TdqCHOXyBcBQQ5",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000fd39c79ba7e0b6f7ed3a181308cb8ac141672370d8f2f2e2f5faba8f93eb_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456802&Signature=imED1VqYi14phTIENcdipBYjA%2BPgkL01TfJ1OydtY11LRS0lWv7THCPLLrLTkqq5ZoqxfCHCpuGqhWbabkW%2FSywvmyfhLD8TAvNRo0A%2Fdc27m6nC815oX%2BMHPVKhiTkshZH2KFL5rPe%2FQN81hxksJ07blNlH%2FGB6mG4fnRkg4rmqjT0QFA0yYvzH0bBAtM5ZmMRpoIg7zab6oVeuUuqroFECb2%2Fl3KcRdgZm2RQcf%2BvoJW"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "6a0eac9ae62f3f9f50ca0d18",
      "name": "test/recall VirusTotal report                    for App_20250512084741811.apk",
      "description": "May 12,2025",
      "modified": "2026-05-21T07:00:40.184000",
      "created": "2026-05-21T06:56:26.458000",
      "tags": [
        "file type",
        "ascii"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1406",
          "name": "Obfuscated Files or Information",
          "display_name": "T1406 - Obfuscated Files or Information"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 4,
        "FileHash-MD5": 101,
        "FileHash-SHA1": 99,
        "FileHash-SHA256": 799,
        "domain": 187,
        "URL": 142,
        "hostname": 24
      },
      "indicator_count": 1356,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 65,
      "modified_text": "10 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a0eac9bd286b53466d6e28f",
      "name": "test/recall VirusTotal report                    for App_20250512084741811.apk",
      "description": "May 12,2025",
      "modified": "2026-05-21T06:56:27.437000",
      "created": "2026-05-21T06:56:27.437000",
      "tags": [
        "file type",
        "ascii"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1406",
          "name": "Obfuscated Files or Information",
          "display_name": "T1406 - Obfuscated Files or Information"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 4,
        "FileHash-MD5": 38,
        "FileHash-SHA1": 37,
        "FileHash-SHA256": 741,
        "domain": 187,
        "URL": 142,
        "hostname": 24
      },
      "indicator_count": 1173,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 65,
      "modified_text": "10 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a0e9725b323ae1350c36488",
      "name": "no comment",
      "description": "",
      "modified": "2026-05-21T06:52:08.577000",
      "created": "2026-05-21T05:24:53.947000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 366,
        "FileHash-SHA1": 366,
        "FileHash-SHA256": 5078,
        "IPv4": 44,
        "URL": 2414,
        "domain": 1305,
        "hostname": 366,
        "CIDR": 1,
        "email": 2,
        "Mutex": 1
      },
      "indicator_count": 9943,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "10 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d3522448a6a2faaa9fd792",
      "name": "VirusTotal report\n                    for download.js",
      "description": "><<< full report on Sigma, a new generation of malware, has been published on the website of the University of South Africa's Security Research Centre (Sarac), based in the capital, Pretoria.\u20ac>> united states. Beyond Theory. e p o a e . Epoch",
      "modified": "2026-05-06T06:03:26.437000",
      "created": "2026-04-06T06:26:44.786000",
      "tags": [
        "mitre attack",
        "network info",
        "file type",
        "sigma",
        "program",
        "t1055 process",
        "overview",
        "dropped info",
        "processes extra",
        "overview zenbox",
        "malicious",
        "next",
        "in a",
        "create",
        "manager",
        "docker",
        "5 dev",
        "k8s configmap",
        "profiles",
        "etcd",
        "get https",
        "https",
        "refresh",
        "cookie",
        "ascii text",
        "crlf line",
        "text text",
        "ms windows",
        "vista event",
        "windows event",
        "thumbprint",
        "windows sandbox",
        "calls process",
        "pe file",
        "drops pe",
        "sample",
        "pe32",
        "spawns",
        "aslr",
        "persistence",
        "info",
        "creates",
        "performs dns",
        "default",
        "shell folders",
        "folders",
        "parent pid",
        "full path",
        "command line",
        "inprocserver32",
        "registry keys",
        "k netsvcs",
        "nothing",
        "mensaje",
        "wps office",
        "extra info",
        "drops",
        "defense evasion",
        "binary",
        "window"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/026281c7651d49c77c597d1843578b4578deac3fb8c10be3977371f140b54690_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456178&Signature=veZ5ILWvDbljstqg4NlX%2Bxs8GT3FFuOKYzQc%2B27Rfrzrxz9KINRfg5iEd%2FTD%2FJh0%2Bq%2BUFppfHwGwnnMNhD99MoqLrX735IHzqHRH3Y%2BhrlHexlMj6uTX%2FhuA91WtmQoFu8u8NtWjsAldaYDAJjFHT7HCenKy%2BmD%2FVHzSvfzxaf4d%2FZtoqDdCpPzDigdhx%2BpKQUOSIw0wEDklMmjQ8OQnKdK9RXK5duMVg%2Fwd7u7HVHNa",
        "https://vtbehaviour.commondatastorage.googleapis.com/026281c7651d49c77c597d1843578b4578deac3fb8c10be3977371f140b54690_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456268&Signature=r6fOkWGbwBX8z6YDvUFYQnPc8efKUXVyW0Ma97Qze1Gg5yigm12abg4Ohbydi7izPRODvv6sVLGy9Uj3%2FKSBJY3SoMgbLkj5YofXLKyp40m%2B32vj%2Boml5b0R%2FYrwd7rcA8dzMAuMKZpQ04wgR%2BiSh772Z%2BZ34H2CYZZnjpJoUC49ip8c4%2FUDETK%2BrFZMZqerVs2ONWDAzCMzN%2BvpWHlLkuAH7n2fTCOTvtO43TMqTzE5",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456681&Signature=Mcrv0JEeKTzfxc7JwD4u6K1dNY8liXAX1tF2i91bXpymU0E%2FlRM95joj0ZuMk2A82ekHHzgKJbSxrkjVIutcPfV%2FYWPOj1or9HVjXg4Jq6QJb7fmWG5%2BqUxcfMqz8D7UN8v0FFVTc%2F%2FP3Sv3PpE3%2FKIhPcdMc1SodC9krYB%2Bbdj1obcveSDLlBtXgl9wP%2B7SuYub12drNzeyC9UKw%2FX0n7vZpU3JLAiYznAMTB",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456701&Signature=t3Xqew0bsV61nmgncFTOCX%2FtqVKoAMgUft1dTGFLOFu7%2Fw4fbqeYn3laYdKEN6S%2BK7DF5nDi%2BN6pZq%2Be%2FsOZjAHgy821VBDeXqJaq6BdPAlT6fXrqDPaTghd9A00rdfDtOXh6Zy%2Bl5f16NPFVSl8FRZqU6GLhD%2B%2BSo%2FIP1XbQBHhcyOPh7nfc%2F8BxsyypNTadLDWEEJqVPSKFTVYwIagyVlTMD59xYMUtP8L2Ogdm9mJICbv",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456734&Signature=Twrc6n%2BEyYc3IkPf4BD0CucGYLqOW4lxcGi2ZNxHRk7tNezVNxxouYRnGIr3OFeByvpf87X6oDI2BVrHR8er8NmM4CFpWpyRrf7xJh%2FZ6Vca48ROgTEWVHlnjgW0jVMzSe9TZOnN3zpmnpw37X95of0%2BzE6e4Fpl96po0RZcvPRC0G%2BqbKKwb%2FhIAspbkpn76RKrHyf%2FCb8aZ21ec7FwUJa%2BAZ%2FolkR0TdqCHOXyBcBQQ5",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000fd39c79ba7e0b6f7ed3a181308cb8ac141672370d8f2f2e2f5faba8f93eb_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456766&Signature=fhEgpRoSszxXiIBuHWVEId9w1CwC9EnIKxPCKHEQMqEzppF90L%2B%2FlxW%2FywCNH6CMqGY1o9mJvTVmLXyypm1kzfmWsyA80dWPTGIRRYKfqvQ3Nng8wj93UHAEQuxrv4kfCNpUBBjn1WDnmQhRTooluOfdTIrQ10pjymrCYCKxOAFwm5bbvSKJ0%2BtX3rYiPf3fD%2BRRO9heg7G6MndwBJE2WMOzyy6vo8lgQCLwHAh4rCiDobnbPC8XTy6osE1J",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000fd39c79ba7e0b6f7ed3a181308cb8ac141672370d8f2f2e2f5faba8f93eb_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456802&Signature=imED1VqYi14phTIENcdipBYjA%2BPgkL01TfJ1OydtY11LRS0lWv7THCPLLrLTkqq5ZoqxfCHCpuGqhWbabkW%2FSywvmyfhLD8TAvNRo0A%2Fdc27m6nC815oX%2BMHPVKhiTkshZH2KFL5rPe%2FQN81hxksJ07blNlH%2FGB6mG4fnRkg4rmqjT0QFA0yYvzH0bBAtM5ZmMRpoIg7zab6oVeuUuqroFECb2%2Fl3KcRdgZm2RQcf%2BvoJW",
        "https://vtbehaviour.commondatastorage.googleapis.com/0002815bed9019ec43e804f3eb7436b82b133ae60fce110cbbadae8ed8be5b3e_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456853&Signature=ohh65FvVsmXmQYu%2BJk1T4eXJGcdQGvMivSh5TmeHZLoDT%2ByKeGjHrEPJLhUqlYbxRx8n2cI91TyF9CGdex%2F461K5YKhHcc1nzbCf%2BHknI5sKA%2FMDvRrmPb0DYDVnExub3GBqS92stLwDSfSKYmbg3%2Bewiypp3nNLEzgg1XFvXV%2Bu%2Bk%2F4EG8y495NBtU%2F5%2Fh3oLc%2F0NDQfdQWmwE%2FuiC9lWax%2FmZm7V2%2Bap03q3xN",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000e8cff55bbade9d37b4ab17e56adba1680091d209830945cc26c9d58d6a9d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456905&Signature=RYIw5qZjecwIW0t7r5f%2BW29otPot2E4%2FAtLi37l8zcqFvx5%2B%2F9fgG%2B1Ay2Srf3y63cFKycTp%2BPmZvlwpImAkOOt4%2FBgJ7020dTOz%2FLOWUt6aeKt5xvjqwwkju5zlpLraECdTpENMPV436aJoAh1I2kbPY6oHixcY%2BW1t1E4XcpCMLPlEQOgQmoVly6vDIA4BFHjHbrRd%2FpgtZExPke2Y%2FXgggLW75UrBbd",
        "https://vtbehaviour.commondatastorage.googleapis.com/0000fd39c79ba7e0b6f7ed3a181308cb8ac141672370d8f2f2e2f5faba8f93eb_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775456942&Signature=CyFvPFvbJhEdaWGF5he4cjzXT2%2FgvcmLJtVWaxv%2BNDzHPqLCNte56ZKxxP6mxUJPRZOpew0513JF50Ks8VL3kYoD566k1EAY27gm%2FdAS2N7xeaKV%2FdmihrhDfLdb2wqlXciSx3fb9Kf4z4T%2F4Kf9%2FSGh6lka0UFtlvIBzlq2OGtr0n6YEpVNHQG6L7jGn4adPJ1P8Zxb0ozprtOGnCXztODTwURwVPyD9asMhojWns2L1ssNl0rH0GQAAY"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 26,
        "FileHash-SHA1": 30,
        "FileHash-SHA256": 143,
        "URL": 103,
        "domain": 19,
        "hostname": 130,
        "email": 2
      },
      "indicator_count": 453,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "25 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62221d71474b323d486dc3f2",
      "name": "WTF 2022",
      "description": "",
      "modified": "2022-04-03T00:00:55.161000",
      "created": "2022-03-04T14:08:49.518000",
      "tags": [],
      "references": [
        "WTF.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 587,
        "URL": 668,
        "hostname": 613,
        "domain": 1320,
        "FileHash-MD5": 59,
        "FileHash-SHA1": 2
      },
      "indicator_count": 3249,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 406,
      "modified_text": "1519 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "sample.py",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "sample.py",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780211384.3520145
}