{
  "type": "Domain",
  "indicator": "silknet.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/silknet.com",
    "alexa": "http://www.alexa.com/siteinfo/silknet.com",
    "indicator": "silknet.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2894092586,
      "indicator": "silknet.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 8,
      "pulses": [
        {
          "id": "69d4db11500ea6dcbc2afd10",
          "name": "ZETALYTICS.COM PT2 CREATED 2 YEARS AGO by StreamMiningEx Public TLP:  Green clone",
          "description": "",
          "modified": "2026-04-07T10:23:13.255000",
          "created": "2026-04-07T10:23:13.255000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65707f425121331bce0945cd",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 547,
            "FileHash-SHA256": 932,
            "URL": 1267,
            "domain": 140
          },
          "indicator_count": 2886,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "6 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707f76ee99af9f915b8264",
          "name": "uod-kre.derby.ac.uk vt-json 25-2-2022.txt",
          "description": "",
          "modified": "2023-12-06T14:04:38.247000",
          "created": "2023-12-06T14:04:38.247000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 728,
            "domain": 142,
            "hostname": 501,
            "URL": 1244
          },
          "indicator_count": 2615,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "859 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707f425121331bce0945cd",
          "name": "ZETALYTICS.COM PT2",
          "description": "",
          "modified": "2023-12-06T14:03:46.820000",
          "created": "2023-12-06T14:03:46.820000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 547,
            "FileHash-SHA256": 932,
            "URL": 1267,
            "domain": 140
          },
          "indicator_count": 2886,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "859 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707ea9c0f2231d524c00ae",
          "name": "www.zetalytics.com",
          "description": "",
          "modified": "2023-12-06T14:01:12.637000",
          "created": "2023-12-06T14:01:12.637000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 632,
            "URL": 747,
            "hostname": 368,
            "domain": 116,
            "email": 1,
            "FileHash-SHA1": 2
          },
          "indicator_count": 1866,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "859 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "624de148f4e941487497de0b",
          "name": "WordPress backdoor for distributing code snippets (As known as NDSW)",
          "description": "They are known as NDSX or NDSW. This malicious code for WordPress has the appearance of a complete server-client program. For example, 'blue.php' is a server-side script that sends another script to a website visitor. Multiple infected websites receive this script over XHR and run it.",
          "modified": "2022-05-07T00:03:18.570000",
          "created": "2022-04-06T18:51:52.034000",
          "tags": [
            "elevator",
            "techa",
            "8bcsqrj",
            "dysta",
            "hostn",
            "13190bmfkjr",
            "ec24 mltipla",
            "mechanical",
            "indonesia",
            "lift indoesia",
            "279520ybredf",
            "tostr",
            "rando",
            "locat",
            "909073jmbtro",
            "open",
            "72xbooph",
            "lc20lb mbeuo",
            "dkv0md",
            "oo0x6b",
            "plano",
            "head office",
            "steel plart",
            "main road",
            "near vh",
            "mais",
            "log data",
            "site",
            "please note",
            "september",
            "hello rankmath",
            "rank math",
            "ip address",
            "domain name",
            "subnet",
            "httpclient",
            "ndsx",
            "sms marketing",
            "dnew httpclient",
            "analysis",
            "bukuip",
            "herbals",
            "js malware",
            "javascript code",
            "php file",
            "wordpress",
            "report https",
            "overview",
            "process",
            "tree",
            "yara",
            "document",
            "window",
            "page",
            "february",
            "links",
            "search",
            "baskerville",
            "topic",
            "switchedfrom",
            "html",
            "sandbox",
            "tools",
            "twitter",
            "malware",
            "footer",
            "\u2019m",
            "tonytellez",
            "post",
            "switched",
            "themes patterns",
            "get involved",
            "theme author",
            "anders norn",
            "anlino",
            "example",
            "parseint",
            "push",
            "shift",
            "154602bdagrg",
            "screen"
          ],
          "references": [
            "https://www.fortiguard.com/encyclopedia/virus/10043970",
            "https://notes.budakkuala.com/wordpress/wordpress-site-hacked-implanted-and-injected-with-backdoor-script-backdoor-php-webshell/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada",
            "Korea, Republic of",
            "United States of America",
            "Brazil",
            "Sri Lanka",
            "Kenya",
            "Papua New Guinea",
            "Panama"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "catswords",
            "id": "154952",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 40,
            "domain": 27,
            "hostname": 11,
            "email": 1,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 15,
          "modified_text": "1438 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "621af03a6ee00e5d4bfc2b0a",
          "name": "uod-kre.derby.ac.uk vt-json 25-2-2022.txt",
          "description": "",
          "modified": "2022-03-29T00:03:34.773000",
          "created": "2022-02-27T03:30:02.697000",
          "tags": [
            "jisc",
            "uk gov",
            "bad dns",
            "host",
            "sept",
            "radore veri"
          ],
          "references": [
            "uod-kre.derby.ac.uk vt-json 25-2-2022.txt",
            "https://www.virustotal.com/graph/gb27eb06127474621947c14e51f723e3057046c2ec5ca4372a9270c8eae21c8d8"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1470",
              "name": "Obtain Device Cloud Backups",
              "display_name": "T1470 - Obtain Device Cloud Backups"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1011",
              "name": "Exfiltration Over Other Network Medium",
              "display_name": "T1011 - Exfiltration Over Other Network Medium"
            },
            {
              "id": "T1195",
              "name": "Supply Chain Compromise",
              "display_name": "T1195 - Supply Chain Compromise"
            },
            {
              "id": "T1611",
              "name": "Escape to Host",
              "display_name": "T1611 - Escape to Host"
            },
            {
              "id": "T1503",
              "name": "Credentials from Web Browsers",
              "display_name": "T1503 - Credentials from Web Browsers"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1099",
              "name": "Timestomp",
              "display_name": "T1099 - Timestomp"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1244,
            "hostname": 501,
            "domain": 142,
            "FileHash-SHA256": 728
          },
          "indicator_count": 2615,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 392,
          "modified_text": "1477 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6219004f53e3ae2316efea12",
          "name": "ZETALYTICS.COM PT2",
          "description": "",
          "modified": "2022-03-27T00:00:39.057000",
          "created": "2022-02-25T16:14:07.302000",
          "tags": [
            "ssl certificate",
            "whois",
            "whois record"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "China"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 547,
            "URL": 1267,
            "domain": 140,
            "FileHash-SHA256": 932
          },
          "indicator_count": 2886,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1479 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6211eaee20bc9b0534df6133",
          "name": "www.zetalytics.com",
          "description": "",
          "modified": "2022-03-24T00:00:00.271000",
          "created": "2022-02-20T07:17:02.872000",
          "tags": [
            "ssl certificate",
            "whois record",
            "whois",
            "key identifier",
            "x509v3 subject",
            "v3 serial",
            "number",
            "issuer",
            "cus cngo",
            "daddy secure",
            "g2 lscottsdale",
            "ouhttp",
            "validity",
            "info",
            "date",
            "tucows domains",
            "server",
            "algorithm",
            "iana id",
            "registrar url",
            "status",
            "registrar whois",
            "rank value",
            "ingestion time",
            "statvoo",
            "utc alexa",
            "utc cisco",
            "umbrella",
            "submission",
            "history first",
            "analysis",
            "utc http",
            "response final",
            "url https",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "tools",
            "Ransomware",
            "POSSIBLE ETERNAL BLUE"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "China",
            "Australia",
            "Belgium"
          ],
          "malware_families": [
            {
              "id": "TEL:NoPowShell!msil",
              "display_name": "TEL:NoPowShell!msil",
              "target": null
            },
            {
              "id": "PWS:Win32/QQPass.GP",
              "display_name": "PWS:Win32/QQPass.GP",
              "target": "/malware/PWS:Win32/QQPass.GP"
            },
            {
              "id": "Win.Malware.Razy-6783523-0",
              "display_name": "Win.Malware.Razy-6783523-0",
              "target": null
            },
            {
              "id": "Win.Trojan.Pasta-827",
              "display_name": "Win.Trojan.Pasta-827",
              "target": null
            },
            {
              "id": "Ransom:Win32/Wannaren.A",
              "display_name": "Ransom:Win32/Wannaren.A",
              "target": "/malware/Ransom:Win32/Wannaren.A"
            },
            {
              "id": "Win.Malware.Zusy-6840460-0",
              "display_name": "Win.Malware.Zusy-6840460-0",
              "target": null
            },
            {
              "id": "Win.Trojan.Agent-1201096",
              "display_name": "Win.Trojan.Agent-1201096",
              "target": null
            },
            {
              "id": "Win32:Dropper-GUP\\ [Drp]",
              "display_name": "Win32:Dropper-GUP\\ [Drp]",
              "target": null
            },
            {
              "id": "Worm:Win32/Macoute",
              "display_name": "Worm:Win32/Macoute",
              "target": "/malware/Worm:Win32/Macoute"
            },
            {
              "id": "Win32:Sobig-H\\ [Wrm]",
              "display_name": "Win32:Sobig-H\\ [Wrm]",
              "target": null
            },
            {
              "id": "Win.Worm.Sobig-5",
              "display_name": "Win.Worm.Sobig-5",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Berbew",
              "display_name": "Backdoor:Win32/Berbew",
              "target": "/malware/Backdoor:Win32/Berbew"
            },
            {
              "id": "Win.Trojan.Crypted-30",
              "display_name": "Win.Trojan.Crypted-30",
              "target": null
            },
            {
              "id": "#VirTool:Win32/Obfuscator.ADB",
              "display_name": "#VirTool:Win32/Obfuscator.ADB",
              "target": "/malware/#VirTool:Win32/Obfuscator.ADB"
            },
            {
              "id": "Win.Trojan.Kazy-6878",
              "display_name": "Win.Trojan.Kazy-6878",
              "target": null
            },
            {
              "id": "Win32:VB-FBX",
              "display_name": "Win32:VB-FBX",
              "target": null
            },
            {
              "id": "Win.Worm.Pajetbin-6726648-0",
              "display_name": "Win.Worm.Pajetbin-6726648-0",
              "target": null
            },
            {
              "id": "Trojan:Win32/Vindor.B",
              "display_name": "Trojan:Win32/Vindor.B",
              "target": "/malware/Trojan:Win32/Vindor.B"
            },
            {
              "id": "MSIL:BrowseFox-FC\\ [Adw]",
              "display_name": "MSIL:BrowseFox-FC\\ [Adw]",
              "target": null
            },
            {
              "id": "Win.Ransomware.Teslacrypt-7082109-1",
              "display_name": "Win.Ransomware.Teslacrypt-7082109-1",
              "target": null
            },
            {
              "id": "ALF:HSTR:Trojan:Win32/Injector.YY!bit",
              "display_name": "ALF:HSTR:Trojan:Win32/Injector.YY!bit",
              "target": null
            },
            {
              "id": "Win32:Papras-AX\\ [Trj]",
              "display_name": "Win32:Papras-AX\\ [Trj]",
              "target": null
            },
            {
              "id": "ALF:HSTR:MITM:UtilAds",
              "display_name": "ALF:HSTR:MITM:UtilAds",
              "target": null
            },
            {
              "id": "Win.Malware.Autoit-6753917-0",
              "display_name": "Win.Malware.Autoit-6753917-0",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 368,
            "URL": 747,
            "domain": 116,
            "FileHash-SHA256": 632,
            "email": 1,
            "FileHash-SHA1": 2
          },
          "indicator_count": 1866,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 409,
          "modified_text": "1482 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.fortiguard.com/encyclopedia/virus/10043970",
        "https://www.virustotal.com/graph/gb27eb06127474621947c14e51f723e3057046c2ec5ca4372a9270c8eae21c8d8",
        "uod-kre.derby.ac.uk vt-json 25-2-2022.txt",
        "https://notes.budakkuala.com/wordpress/wordpress-site-hacked-implanted-and-injected-with-backdoor-script-backdoor-php-webshell/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Worm:win32/macoute",
            "Win32:papras-ax\\ [trj]",
            "Win.worm.sobig-5",
            "Win.malware.zusy-6840460-0",
            "Win.worm.pajetbin-6726648-0",
            "Win32:dropper-gup\\ [drp]",
            "Win32:vb-fbx",
            "Trojan:win32/vindor.b",
            "Win.malware.autoit-6753917-0",
            "Msil:browsefox-fc\\ [adw]",
            "Alf:hstr:trojan:win32/injector.yy!bit",
            "Alf:hstr:mitm:utilads",
            "Win.trojan.pasta-827",
            "Backdoor:win32/berbew",
            "Pws:win32/qqpass.gp",
            "Tel:nopowshell!msil",
            "#virtool:win32/obfuscator.adb",
            "Win.trojan.kazy-6878",
            "Win.trojan.agent-1201096",
            "Win32:sobig-h\\ [wrm]",
            "Ransom:win32/wannaren.a",
            "Win.malware.razy-6783523-0",
            "Win.ransomware.teslacrypt-7082109-1",
            "Win.trojan.crypted-30"
          ],
          "industries": [
            "Technology"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 8,
  "pulses": [
    {
      "id": "69d4db11500ea6dcbc2afd10",
      "name": "ZETALYTICS.COM PT2 CREATED 2 YEARS AGO by StreamMiningEx Public TLP:  Green clone",
      "description": "",
      "modified": "2026-04-07T10:23:13.255000",
      "created": "2026-04-07T10:23:13.255000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65707f425121331bce0945cd",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 547,
        "FileHash-SHA256": 932,
        "URL": 1267,
        "domain": 140
      },
      "indicator_count": 2886,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 44,
      "modified_text": "6 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707f76ee99af9f915b8264",
      "name": "uod-kre.derby.ac.uk vt-json 25-2-2022.txt",
      "description": "",
      "modified": "2023-12-06T14:04:38.247000",
      "created": "2023-12-06T14:04:38.247000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 728,
        "domain": 142,
        "hostname": 501,
        "URL": 1244
      },
      "indicator_count": 2615,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "859 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707f425121331bce0945cd",
      "name": "ZETALYTICS.COM PT2",
      "description": "",
      "modified": "2023-12-06T14:03:46.820000",
      "created": "2023-12-06T14:03:46.820000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 547,
        "FileHash-SHA256": 932,
        "URL": 1267,
        "domain": 140
      },
      "indicator_count": 2886,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "859 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707ea9c0f2231d524c00ae",
      "name": "www.zetalytics.com",
      "description": "",
      "modified": "2023-12-06T14:01:12.637000",
      "created": "2023-12-06T14:01:12.637000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 632,
        "URL": 747,
        "hostname": 368,
        "domain": 116,
        "email": 1,
        "FileHash-SHA1": 2
      },
      "indicator_count": 1866,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "859 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "624de148f4e941487497de0b",
      "name": "WordPress backdoor for distributing code snippets (As known as NDSW)",
      "description": "They are known as NDSX or NDSW. This malicious code for WordPress has the appearance of a complete server-client program. For example, 'blue.php' is a server-side script that sends another script to a website visitor. Multiple infected websites receive this script over XHR and run it.",
      "modified": "2022-05-07T00:03:18.570000",
      "created": "2022-04-06T18:51:52.034000",
      "tags": [
        "elevator",
        "techa",
        "8bcsqrj",
        "dysta",
        "hostn",
        "13190bmfkjr",
        "ec24 mltipla",
        "mechanical",
        "indonesia",
        "lift indoesia",
        "279520ybredf",
        "tostr",
        "rando",
        "locat",
        "909073jmbtro",
        "open",
        "72xbooph",
        "lc20lb mbeuo",
        "dkv0md",
        "oo0x6b",
        "plano",
        "head office",
        "steel plart",
        "main road",
        "near vh",
        "mais",
        "log data",
        "site",
        "please note",
        "september",
        "hello rankmath",
        "rank math",
        "ip address",
        "domain name",
        "subnet",
        "httpclient",
        "ndsx",
        "sms marketing",
        "dnew httpclient",
        "analysis",
        "bukuip",
        "herbals",
        "js malware",
        "javascript code",
        "php file",
        "wordpress",
        "report https",
        "overview",
        "process",
        "tree",
        "yara",
        "document",
        "window",
        "page",
        "february",
        "links",
        "search",
        "baskerville",
        "topic",
        "switchedfrom",
        "html",
        "sandbox",
        "tools",
        "twitter",
        "malware",
        "footer",
        "\u2019m",
        "tonytellez",
        "post",
        "switched",
        "themes patterns",
        "get involved",
        "theme author",
        "anders norn",
        "anlino",
        "example",
        "parseint",
        "push",
        "shift",
        "154602bdagrg",
        "screen"
      ],
      "references": [
        "https://www.fortiguard.com/encyclopedia/virus/10043970",
        "https://notes.budakkuala.com/wordpress/wordpress-site-hacked-implanted-and-injected-with-backdoor-script-backdoor-php-webshell/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada",
        "Korea, Republic of",
        "United States of America",
        "Brazil",
        "Sri Lanka",
        "Kenya",
        "Papua New Guinea",
        "Panama"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "catswords",
        "id": "154952",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 40,
        "domain": 27,
        "hostname": 11,
        "email": 1,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 1
      },
      "indicator_count": 82,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 15,
      "modified_text": "1438 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "621af03a6ee00e5d4bfc2b0a",
      "name": "uod-kre.derby.ac.uk vt-json 25-2-2022.txt",
      "description": "",
      "modified": "2022-03-29T00:03:34.773000",
      "created": "2022-02-27T03:30:02.697000",
      "tags": [
        "jisc",
        "uk gov",
        "bad dns",
        "host",
        "sept",
        "radore veri"
      ],
      "references": [
        "uod-kre.derby.ac.uk vt-json 25-2-2022.txt",
        "https://www.virustotal.com/graph/gb27eb06127474621947c14e51f723e3057046c2ec5ca4372a9270c8eae21c8d8"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1470",
          "name": "Obtain Device Cloud Backups",
          "display_name": "T1470 - Obtain Device Cloud Backups"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1011",
          "name": "Exfiltration Over Other Network Medium",
          "display_name": "T1011 - Exfiltration Over Other Network Medium"
        },
        {
          "id": "T1195",
          "name": "Supply Chain Compromise",
          "display_name": "T1195 - Supply Chain Compromise"
        },
        {
          "id": "T1611",
          "name": "Escape to Host",
          "display_name": "T1611 - Escape to Host"
        },
        {
          "id": "T1503",
          "name": "Credentials from Web Browsers",
          "display_name": "T1503 - Credentials from Web Browsers"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1099",
          "name": "Timestomp",
          "display_name": "T1099 - Timestomp"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1244,
        "hostname": 501,
        "domain": 142,
        "FileHash-SHA256": 728
      },
      "indicator_count": 2615,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 392,
      "modified_text": "1477 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6219004f53e3ae2316efea12",
      "name": "ZETALYTICS.COM PT2",
      "description": "",
      "modified": "2022-03-27T00:00:39.057000",
      "created": "2022-02-25T16:14:07.302000",
      "tags": [
        "ssl certificate",
        "whois",
        "whois record"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "China"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 547,
        "URL": 1267,
        "domain": 140,
        "FileHash-SHA256": 932
      },
      "indicator_count": 2886,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 407,
      "modified_text": "1479 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6211eaee20bc9b0534df6133",
      "name": "www.zetalytics.com",
      "description": "",
      "modified": "2022-03-24T00:00:00.271000",
      "created": "2022-02-20T07:17:02.872000",
      "tags": [
        "ssl certificate",
        "whois record",
        "whois",
        "key identifier",
        "x509v3 subject",
        "v3 serial",
        "number",
        "issuer",
        "cus cngo",
        "daddy secure",
        "g2 lscottsdale",
        "ouhttp",
        "validity",
        "info",
        "date",
        "tucows domains",
        "server",
        "algorithm",
        "iana id",
        "registrar url",
        "status",
        "registrar whois",
        "rank value",
        "ingestion time",
        "statvoo",
        "utc alexa",
        "utc cisco",
        "umbrella",
        "submission",
        "history first",
        "analysis",
        "utc http",
        "response final",
        "url https",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "tools",
        "Ransomware",
        "POSSIBLE ETERNAL BLUE"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "China",
        "Australia",
        "Belgium"
      ],
      "malware_families": [
        {
          "id": "TEL:NoPowShell!msil",
          "display_name": "TEL:NoPowShell!msil",
          "target": null
        },
        {
          "id": "PWS:Win32/QQPass.GP",
          "display_name": "PWS:Win32/QQPass.GP",
          "target": "/malware/PWS:Win32/QQPass.GP"
        },
        {
          "id": "Win.Malware.Razy-6783523-0",
          "display_name": "Win.Malware.Razy-6783523-0",
          "target": null
        },
        {
          "id": "Win.Trojan.Pasta-827",
          "display_name": "Win.Trojan.Pasta-827",
          "target": null
        },
        {
          "id": "Ransom:Win32/Wannaren.A",
          "display_name": "Ransom:Win32/Wannaren.A",
          "target": "/malware/Ransom:Win32/Wannaren.A"
        },
        {
          "id": "Win.Malware.Zusy-6840460-0",
          "display_name": "Win.Malware.Zusy-6840460-0",
          "target": null
        },
        {
          "id": "Win.Trojan.Agent-1201096",
          "display_name": "Win.Trojan.Agent-1201096",
          "target": null
        },
        {
          "id": "Win32:Dropper-GUP\\ [Drp]",
          "display_name": "Win32:Dropper-GUP\\ [Drp]",
          "target": null
        },
        {
          "id": "Worm:Win32/Macoute",
          "display_name": "Worm:Win32/Macoute",
          "target": "/malware/Worm:Win32/Macoute"
        },
        {
          "id": "Win32:Sobig-H\\ [Wrm]",
          "display_name": "Win32:Sobig-H\\ [Wrm]",
          "target": null
        },
        {
          "id": "Win.Worm.Sobig-5",
          "display_name": "Win.Worm.Sobig-5",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Berbew",
          "display_name": "Backdoor:Win32/Berbew",
          "target": "/malware/Backdoor:Win32/Berbew"
        },
        {
          "id": "Win.Trojan.Crypted-30",
          "display_name": "Win.Trojan.Crypted-30",
          "target": null
        },
        {
          "id": "#VirTool:Win32/Obfuscator.ADB",
          "display_name": "#VirTool:Win32/Obfuscator.ADB",
          "target": "/malware/#VirTool:Win32/Obfuscator.ADB"
        },
        {
          "id": "Win.Trojan.Kazy-6878",
          "display_name": "Win.Trojan.Kazy-6878",
          "target": null
        },
        {
          "id": "Win32:VB-FBX",
          "display_name": "Win32:VB-FBX",
          "target": null
        },
        {
          "id": "Win.Worm.Pajetbin-6726648-0",
          "display_name": "Win.Worm.Pajetbin-6726648-0",
          "target": null
        },
        {
          "id": "Trojan:Win32/Vindor.B",
          "display_name": "Trojan:Win32/Vindor.B",
          "target": "/malware/Trojan:Win32/Vindor.B"
        },
        {
          "id": "MSIL:BrowseFox-FC\\ [Adw]",
          "display_name": "MSIL:BrowseFox-FC\\ [Adw]",
          "target": null
        },
        {
          "id": "Win.Ransomware.Teslacrypt-7082109-1",
          "display_name": "Win.Ransomware.Teslacrypt-7082109-1",
          "target": null
        },
        {
          "id": "ALF:HSTR:Trojan:Win32/Injector.YY!bit",
          "display_name": "ALF:HSTR:Trojan:Win32/Injector.YY!bit",
          "target": null
        },
        {
          "id": "Win32:Papras-AX\\ [Trj]",
          "display_name": "Win32:Papras-AX\\ [Trj]",
          "target": null
        },
        {
          "id": "ALF:HSTR:MITM:UtilAds",
          "display_name": "ALF:HSTR:MITM:UtilAds",
          "target": null
        },
        {
          "id": "Win.Malware.Autoit-6753917-0",
          "display_name": "Win.Malware.Autoit-6753917-0",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 368,
        "URL": 747,
        "domain": 116,
        "FileHash-SHA256": 632,
        "email": 1,
        "FileHash-SHA1": 2
      },
      "indicator_count": 1866,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 409,
      "modified_text": "1482 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "silknet.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "silknet.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776136988.046174
}