{
  "type": "Domain",
  "indicator": "smalladjustment.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/smalladjustment.com",
    "alexa": "http://www.alexa.com/siteinfo/smalladjustment.com",
    "indicator": "smalladjustment.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2813427031,
      "indicator": "smalladjustment.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "65709bdfec2ebd8b9c05c15d",
          "name": "Threat Intel Report - W22-2023",
          "description": "",
          "modified": "2023-12-06T16:05:51.194000",
          "created": "2023-12-06T16:05:51.194000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 147,
            "FileHash-MD5": 78,
            "FileHash-SHA1": 73,
            "domain": 111,
            "hostname": 29,
            "URL": 121
          },
          "indicator_count": 559,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657096d09b7c50c7e3eea12f",
          "name": "IOCs_2023.02.06_22.46",
          "description": "",
          "modified": "2023-12-06T15:44:16.274000",
          "created": "2023-12-06T15:44:16.274000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 957,
            "FileHash-MD5": 196,
            "FileHash-SHA1": 196,
            "domain": 159,
            "hostname": 222,
            "URL": 3
          },
          "indicator_count": 1733,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64747c916cd830d76839022d",
          "name": "Threat Intel Report - W22-2023",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2023-06-28T10:02:59.787000",
          "created": "2023-05-29T10:21:05.570000",
          "tags": [
            "korean lazarus",
            "espionage",
            "lazarus",
            "buhti",
            "qbot",
            "stealthy bandit",
            "cosmicenergy",
            "babuk",
            "moneybird",
            "kimsuky",
            "windows",
            "microsoft",
            "cvss",
            "cvss base",
            "bandit stealer",
            "google cloud",
            "cloud sql",
            "lockbit",
            "qbot malware",
            "augusta",
            "malware",
            "service",
            "korean",
            "hashes domains",
            "amadey amadey",
            "ddos",
            "vidar vidar",
            "december",
            "arkei",
            "vidar",
            "remcos remcos",
            "wcry",
            "wanacryptor",
            "japan",
            "ip address",
            "blacklist host",
            "ip country",
            "latest spambot",
            "visit",
            "activity",
            "brazil",
            "canada",
            "singapore",
            "qakbot",
            "privateloader",
            "date",
            "malware url",
            "tags",
            "coinminer",
            "smake loader",
            "sha1 file",
            "name submit"
          ],
          "references": [
            "http://sanddroid.xjtu.edu.cn/",
            "http://jevereg.amnpardaz.com/"
          ],
          "public": 1,
          "adversary": "Korean Lazarus",
          "targeted_countries": [
            "Ukraine",
            "United States of America",
            "Georgia"
          ],
          "malware_families": [
            {
              "id": "Kimsuky",
              "display_name": "Kimsuky",
              "target": null
            },
            {
              "id": "Moneybird",
              "display_name": "Moneybird",
              "target": null
            },
            {
              "id": "Babuk",
              "display_name": "Babuk",
              "target": null
            },
            {
              "id": "COSMICENERGY",
              "display_name": "COSMICENERGY",
              "target": null
            },
            {
              "id": "Stealthy Bandit",
              "display_name": "Stealthy Bandit",
              "target": null
            },
            {
              "id": "QBot",
              "display_name": "QBot",
              "target": null
            },
            {
              "id": "Buhti",
              "display_name": "Buhti",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1123",
              "name": "Audio Capture",
              "display_name": "T1123 - Audio Capture"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 78,
            "FileHash-SHA1": 73,
            "FileHash-SHA256": 147,
            "URL": 121,
            "domain": 111,
            "hostname": 29
          },
          "indicator_count": 559,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "1067 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e1755ffb32d12b0fc3ff42",
          "name": "IOCs_2023.02.06_22.46",
          "description": "Hashes are used to identify people using the same IP address as the address on a specific address, but they can now be traced to a different address in the UK and Ireland, as well as from the US.",
          "modified": "2023-03-08T21:16:31.886000",
          "created": "2023-02-06T21:47:11.561000",
          "tags": [
            "emotet",
            "wannacry",
            "wannycry",
            "trickbot",
            "qbot",
            "cobalt strike",
            "flawedammyy",
            "systembc",
            "hashes",
            "domains",
            "wcry",
            "microsoft",
            "iocs ip",
            "emotet malware",
            "fake net",
            "cobaltstrike",
            "first",
            "eternalblue",
            "desktop",
            "trojan",
            "agent tesla",
            "malware",
            "fallout"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "SystemBC",
              "display_name": "SystemBC",
              "target": null
            },
            {
              "id": "FlawedAmmyy",
              "display_name": "FlawedAmmyy",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Qbot",
              "display_name": "Qbot",
              "target": null
            },
            {
              "id": "Trickbot",
              "display_name": "Trickbot",
              "target": null
            },
            {
              "id": "WannyCry",
              "display_name": "WannyCry",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1080",
              "name": "Taint Shared Content",
              "display_name": "T1080 - Taint Shared Content"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlessandroFiori",
            "id": "91912",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_91912/resized/80/avatar_2b1b2b88b6.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 196,
            "FileHash-SHA1": 196,
            "FileHash-SHA256": 957,
            "URL": 3,
            "domain": 159,
            "hostname": 222
          },
          "indicator_count": 1733,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 419,
          "modified_text": "1179 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://sanddroid.xjtu.edu.cn/",
        "http://jevereg.amnpardaz.com/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Korean Lazarus"
          ],
          "malware_families": [
            "Wannycry",
            "Cobalt strike",
            "Emotet",
            "Systembc",
            "Babuk",
            "Flawedammyy",
            "Trickbot",
            "Buhti",
            "Agent tesla",
            "Kimsuky",
            "Stealthy bandit",
            "Cosmicenergy",
            "Moneybird",
            "Wannacry",
            "Qbot"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "65709bdfec2ebd8b9c05c15d",
      "name": "Threat Intel Report - W22-2023",
      "description": "",
      "modified": "2023-12-06T16:05:51.194000",
      "created": "2023-12-06T16:05:51.194000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 147,
        "FileHash-MD5": 78,
        "FileHash-SHA1": 73,
        "domain": 111,
        "hostname": 29,
        "URL": 121
      },
      "indicator_count": 559,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "657096d09b7c50c7e3eea12f",
      "name": "IOCs_2023.02.06_22.46",
      "description": "",
      "modified": "2023-12-06T15:44:16.274000",
      "created": "2023-12-06T15:44:16.274000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 957,
        "FileHash-MD5": 196,
        "FileHash-SHA1": 196,
        "domain": 159,
        "hostname": 222,
        "URL": 3
      },
      "indicator_count": 1733,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "64747c916cd830d76839022d",
      "name": "Threat Intel Report - W22-2023",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2023-06-28T10:02:59.787000",
      "created": "2023-05-29T10:21:05.570000",
      "tags": [
        "korean lazarus",
        "espionage",
        "lazarus",
        "buhti",
        "qbot",
        "stealthy bandit",
        "cosmicenergy",
        "babuk",
        "moneybird",
        "kimsuky",
        "windows",
        "microsoft",
        "cvss",
        "cvss base",
        "bandit stealer",
        "google cloud",
        "cloud sql",
        "lockbit",
        "qbot malware",
        "augusta",
        "malware",
        "service",
        "korean",
        "hashes domains",
        "amadey amadey",
        "ddos",
        "vidar vidar",
        "december",
        "arkei",
        "vidar",
        "remcos remcos",
        "wcry",
        "wanacryptor",
        "japan",
        "ip address",
        "blacklist host",
        "ip country",
        "latest spambot",
        "visit",
        "activity",
        "brazil",
        "canada",
        "singapore",
        "qakbot",
        "privateloader",
        "date",
        "malware url",
        "tags",
        "coinminer",
        "smake loader",
        "sha1 file",
        "name submit"
      ],
      "references": [
        "http://sanddroid.xjtu.edu.cn/",
        "http://jevereg.amnpardaz.com/"
      ],
      "public": 1,
      "adversary": "Korean Lazarus",
      "targeted_countries": [
        "Ukraine",
        "United States of America",
        "Georgia"
      ],
      "malware_families": [
        {
          "id": "Kimsuky",
          "display_name": "Kimsuky",
          "target": null
        },
        {
          "id": "Moneybird",
          "display_name": "Moneybird",
          "target": null
        },
        {
          "id": "Babuk",
          "display_name": "Babuk",
          "target": null
        },
        {
          "id": "COSMICENERGY",
          "display_name": "COSMICENERGY",
          "target": null
        },
        {
          "id": "Stealthy Bandit",
          "display_name": "Stealthy Bandit",
          "target": null
        },
        {
          "id": "QBot",
          "display_name": "QBot",
          "target": null
        },
        {
          "id": "Buhti",
          "display_name": "Buhti",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1123",
          "name": "Audio Capture",
          "display_name": "T1123 - Audio Capture"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 24,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 78,
        "FileHash-SHA1": 73,
        "FileHash-SHA256": 147,
        "URL": 121,
        "domain": 111,
        "hostname": 29
      },
      "indicator_count": 559,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "1067 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63e1755ffb32d12b0fc3ff42",
      "name": "IOCs_2023.02.06_22.46",
      "description": "Hashes are used to identify people using the same IP address as the address on a specific address, but they can now be traced to a different address in the UK and Ireland, as well as from the US.",
      "modified": "2023-03-08T21:16:31.886000",
      "created": "2023-02-06T21:47:11.561000",
      "tags": [
        "emotet",
        "wannacry",
        "wannycry",
        "trickbot",
        "qbot",
        "cobalt strike",
        "flawedammyy",
        "systembc",
        "hashes",
        "domains",
        "wcry",
        "microsoft",
        "iocs ip",
        "emotet malware",
        "fake net",
        "cobaltstrike",
        "first",
        "eternalblue",
        "desktop",
        "trojan",
        "agent tesla",
        "malware",
        "fallout"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "SystemBC",
          "display_name": "SystemBC",
          "target": null
        },
        {
          "id": "FlawedAmmyy",
          "display_name": "FlawedAmmyy",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Qbot",
          "display_name": "Qbot",
          "target": null
        },
        {
          "id": "Trickbot",
          "display_name": "Trickbot",
          "target": null
        },
        {
          "id": "WannyCry",
          "display_name": "WannyCry",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1080",
          "name": "Taint Shared Content",
          "display_name": "T1080 - Taint Shared Content"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1490",
          "name": "Inhibit System Recovery",
          "display_name": "T1490 - Inhibit System Recovery"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlessandroFiori",
        "id": "91912",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_91912/resized/80/avatar_2b1b2b88b6.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 196,
        "FileHash-SHA1": 196,
        "FileHash-SHA256": 957,
        "URL": 3,
        "domain": 159,
        "hostname": 222
      },
      "indicator_count": 1733,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 419,
      "modified_text": "1179 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "smalladjustment.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "smalladjustment.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780207064.228787
}