{
  "type": "Domain",
  "indicator": "sendgrid-overview.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/sendgrid-overview.com",
    "alexa": "http://www.alexa.com/siteinfo/sendgrid-overview.com",
    "indicator": "sendgrid-overview.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4003000856,
      "indicator": "sendgrid-overview.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "672cf9acd2742762e7b47903",
          "name": "Unmasking Phishing: Strategies for identifying 0ktapus domains and beyond",
          "description": "This analysis examines phishing tactics used by threat actors, particularly focusing on the 0ktapus group. It outlines techniques for investigating phishing campaigns by pivoting between landing pages, using 0ktapus as a case study. The methods discussed include application fingerprinting, network profiling, and domain registration analysis. The research reveals various DOM templates used by 0ktapus over time and provides insights into their infrastructure and tactics. The article also offers recommendations for prevention and detection of phishing attacks, emphasizing the importance of MFA, SSO, and continuous vigilance in cybersecurity practices.",
          "modified": "2024-12-07T17:02:12.819000",
          "created": "2024-11-07T17:32:28.717000",
          "tags": [
            "social engineering",
            "phishing",
            "identity theft"
          ],
          "references": [
            "https://www.wiz.io/blog/unmasking-phishing-strategies-for-identifying-0ktapus-domains"
          ],
          "public": 1,
          "adversary": "Scattered Spider",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1589",
              "name": "Gather Victim Identity Information",
              "display_name": "T1589 - Gather Victim Identity Information"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1586",
              "name": "Compromise Accounts",
              "display_name": "T1586 - Compromise Accounts"
            },
            {
              "id": "T1608",
              "name": "Stage Capabilities",
              "display_name": "T1608 - Stage Capabilities"
            },
            {
              "id": "T1591",
              "name": "Gather Victim Org Information",
              "display_name": "T1591 - Gather Victim Org Information"
            },
            {
              "id": "T1606",
              "name": "Forge Web Credentials",
              "display_name": "T1606 - Forge Web Credentials"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1585",
              "name": "Establish Accounts",
              "display_name": "T1585 - Establish Accounts"
            }
          ],
          "industries": [
            "Technology",
            "Finance",
            "Telecommunications"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 59,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 37,
            "domain": 148,
            "hostname": 34
          },
          "indicator_count": 223,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386509,
          "modified_text": "539 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6730a9ee1810d8a08d34860b",
          "name": "Oktapus\u2019s Advanced Phishing Operations",
          "description": "",
          "modified": "2024-12-10T12:04:32.246000",
          "created": "2024-11-10T12:41:18.807000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 15,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 34,
            "domain": 128,
            "hostname": 30
          },
          "indicator_count": 222,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 502,
          "modified_text": "536 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.wiz.io/blog/unmasking-phishing-strategies-for-identifying-0ktapus-domains"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "Scattered Spider"
          ],
          "malware_families": [],
          "industries": [
            "Telecommunications",
            "Finance",
            "Technology"
          ]
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "672cf9acd2742762e7b47903",
      "name": "Unmasking Phishing: Strategies for identifying 0ktapus domains and beyond",
      "description": "This analysis examines phishing tactics used by threat actors, particularly focusing on the 0ktapus group. It outlines techniques for investigating phishing campaigns by pivoting between landing pages, using 0ktapus as a case study. The methods discussed include application fingerprinting, network profiling, and domain registration analysis. The research reveals various DOM templates used by 0ktapus over time and provides insights into their infrastructure and tactics. The article also offers recommendations for prevention and detection of phishing attacks, emphasizing the importance of MFA, SSO, and continuous vigilance in cybersecurity practices.",
      "modified": "2024-12-07T17:02:12.819000",
      "created": "2024-11-07T17:32:28.717000",
      "tags": [
        "social engineering",
        "phishing",
        "identity theft"
      ],
      "references": [
        "https://www.wiz.io/blog/unmasking-phishing-strategies-for-identifying-0ktapus-domains"
      ],
      "public": 1,
      "adversary": "Scattered Spider",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1589",
          "name": "Gather Victim Identity Information",
          "display_name": "T1589 - Gather Victim Identity Information"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1586",
          "name": "Compromise Accounts",
          "display_name": "T1586 - Compromise Accounts"
        },
        {
          "id": "T1608",
          "name": "Stage Capabilities",
          "display_name": "T1608 - Stage Capabilities"
        },
        {
          "id": "T1591",
          "name": "Gather Victim Org Information",
          "display_name": "T1591 - Gather Victim Org Information"
        },
        {
          "id": "T1606",
          "name": "Forge Web Credentials",
          "display_name": "T1606 - Forge Web Credentials"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1585",
          "name": "Establish Accounts",
          "display_name": "T1585 - Establish Accounts"
        }
      ],
      "industries": [
        "Technology",
        "Finance",
        "Telecommunications"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 59,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2,
        "FileHash-SHA1": 2,
        "FileHash-SHA256": 37,
        "domain": 148,
        "hostname": 34
      },
      "indicator_count": 223,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386509,
      "modified_text": "539 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6730a9ee1810d8a08d34860b",
      "name": "Oktapus\u2019s Advanced Phishing Operations",
      "description": "",
      "modified": "2024-12-10T12:04:32.246000",
      "created": "2024-11-10T12:41:18.807000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "cryptocti",
        "id": "110256",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 15,
        "FileHash-SHA1": 15,
        "FileHash-SHA256": 34,
        "domain": 128,
        "hostname": 30
      },
      "indicator_count": 222,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 502,
      "modified_text": "536 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "sendgrid-overview.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "sendgrid-overview.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780223365.3070908
}