{
  "type": "Domain",
  "indicator": "servupdate.net",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/servupdate.net",
    "alexa": "http://www.alexa.com/siteinfo/servupdate.net",
    "indicator": "servupdate.net",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4285301380,
      "indicator": "servupdate.net",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "69f296e6f8d22e6594cd87c2",
          "name": "dfhbdfhbfth",
          "description": "",
          "modified": "2026-05-29T23:35:16.304000",
          "created": "2026-04-29T23:40:22.053000",
          "tags": [
            "eio4"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "harshandc123",
            "id": "378589",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 95,
            "FileHash-MD5": 47,
            "FileHash-SHA1": 42,
            "FileHash-SHA256": 149,
            "URL": 1251,
            "hostname": 783
          },
          "indicator_count": 2367,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 16,
          "modified_text": "1 day ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f29701e8ef05a0558464d1",
          "name": "dfhbdfhbfth",
          "description": "",
          "modified": "2026-05-29T23:35:16.304000",
          "created": "2026-04-29T23:40:49.785000",
          "tags": [
            "eio4"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "harshandc123",
            "id": "378589",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 95,
            "FileHash-MD5": 47,
            "FileHash-SHA1": 42,
            "FileHash-SHA256": 149,
            "URL": 1251,
            "hostname": 783
          },
          "indicator_count": 2367,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 15,
          "modified_text": "1 day ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a05c0a13c66d638dc13240a",
          "name": "Werewolf Clusters Exploit Telegram and Starlink Themes for Malware Delivery",
          "description": "",
          "modified": "2026-05-14T12:31:29.431000",
          "created": "2026-05-14T12:31:29.431000",
          "tags": [
            "eio4"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "vijayrajesh1052",
            "id": "366175",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 6,
            "FileHash-MD5": 14,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 14,
            "IPv4": 1,
            "domain": 12
          },
          "indicator_count": 61,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 16,
          "modified_text": "16 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69c963c1231ba8bf66289206",
          "name": "Triune Evil: Werewolves Attack Law Enforcement Officers",
          "description": "In February 2026, a cyber espionage operation was uncovered involving three distinct clusters\u2014Paper Werewolf, Versatile Werewolf, and Eagle Werewolf\u2014engaged in distributing malware designed to exploit interest in Starlink services and drone control applications. The clusters operated autonomously, crafting malware delivery methods that exploited timely news topics as a lure for targeted attacks. Paper Werewolf utilized compromised Telegram accounts to further facilitate its operations, while Versatile Werewolf employed generative AI-developed tools to expedite their malware development processes. Eagle Werewolf was noted for infiltrating Telegram channels to disseminate its malicious payloads.",
          "modified": "2026-04-28T17:01:55.604000",
          "created": "2026-03-29T17:39:13.531000",
          "tags": [
            "werewolf",
            "eagle werewolf",
            "temp",
            "powershell",
            "starlink",
            "echogather",
            "rust",
            "aquilarat",
            "starter",
            "debug",
            "sliver",
            "telegram",
            "phishing",
            "false",
            "nsis",
            "error",
            "main",
            "sysupdate",
            "winlog",
            "bypass",
            "execution",
            "capture",
            "service",
            "team",
            "cookie"
          ],
          "references": [
            "https://bi.zone/expertise/blog/triedinoe-zlo-oborotni-atakuyut-sotrudnikov-silovykh-struktur/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 50,
            "URL": 27,
            "domain": 24,
            "hostname": 1
          },
          "indicator_count": 105,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 542,
          "modified_text": "32 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://bi.zone/expertise/blog/triedinoe-zlo-oborotni-atakuyut-sotrudnikov-silovykh-struktur/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "69f296e6f8d22e6594cd87c2",
      "name": "dfhbdfhbfth",
      "description": "",
      "modified": "2026-05-29T23:35:16.304000",
      "created": "2026-04-29T23:40:22.053000",
      "tags": [
        "eio4"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "harshandc123",
        "id": "378589",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 95,
        "FileHash-MD5": 47,
        "FileHash-SHA1": 42,
        "FileHash-SHA256": 149,
        "URL": 1251,
        "hostname": 783
      },
      "indicator_count": 2367,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 16,
      "modified_text": "1 day ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f29701e8ef05a0558464d1",
      "name": "dfhbdfhbfth",
      "description": "",
      "modified": "2026-05-29T23:35:16.304000",
      "created": "2026-04-29T23:40:49.785000",
      "tags": [
        "eio4"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "harshandc123",
        "id": "378589",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 95,
        "FileHash-MD5": 47,
        "FileHash-SHA1": 42,
        "FileHash-SHA256": 149,
        "URL": 1251,
        "hostname": 783
      },
      "indicator_count": 2367,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 15,
      "modified_text": "1 day ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a05c0a13c66d638dc13240a",
      "name": "Werewolf Clusters Exploit Telegram and Starlink Themes for Malware Delivery",
      "description": "",
      "modified": "2026-05-14T12:31:29.431000",
      "created": "2026-05-14T12:31:29.431000",
      "tags": [
        "eio4"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "vijayrajesh1052",
        "id": "366175",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 6,
        "FileHash-MD5": 14,
        "FileHash-SHA1": 14,
        "FileHash-SHA256": 14,
        "IPv4": 1,
        "domain": 12
      },
      "indicator_count": 61,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 16,
      "modified_text": "16 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69c963c1231ba8bf66289206",
      "name": "Triune Evil: Werewolves Attack Law Enforcement Officers",
      "description": "In February 2026, a cyber espionage operation was uncovered involving three distinct clusters\u2014Paper Werewolf, Versatile Werewolf, and Eagle Werewolf\u2014engaged in distributing malware designed to exploit interest in Starlink services and drone control applications. The clusters operated autonomously, crafting malware delivery methods that exploited timely news topics as a lure for targeted attacks. Paper Werewolf utilized compromised Telegram accounts to further facilitate its operations, while Versatile Werewolf employed generative AI-developed tools to expedite their malware development processes. Eagle Werewolf was noted for infiltrating Telegram channels to disseminate its malicious payloads.",
      "modified": "2026-04-28T17:01:55.604000",
      "created": "2026-03-29T17:39:13.531000",
      "tags": [
        "werewolf",
        "eagle werewolf",
        "temp",
        "powershell",
        "starlink",
        "echogather",
        "rust",
        "aquilarat",
        "starter",
        "debug",
        "sliver",
        "telegram",
        "phishing",
        "false",
        "nsis",
        "error",
        "main",
        "sysupdate",
        "winlog",
        "bypass",
        "execution",
        "capture",
        "service",
        "team",
        "cookie"
      ],
      "references": [
        "https://bi.zone/expertise/blog/triedinoe-zlo-oborotni-atakuyut-sotrudnikov-silovykh-struktur/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 50,
        "URL": 27,
        "domain": 24,
        "hostname": 1
      },
      "indicator_count": 105,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 542,
      "modified_text": "32 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "servupdate.net",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "servupdate.net",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780203401.2744265
}