{
  "type": "Domain",
  "indicator": "this.save",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/this.save",
    "alexa": "http://www.alexa.com/siteinfo/this.save",
    "indicator": "this.save",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2982459713,
      "indicator": "this.save",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 11,
      "pulses": [
        {
          "id": "68c954a80675ccc89b0e9b63",
          "name": "Trump #45470 | Palantir container | virus:DOS/Hellspawn + ioS (compromised)",
          "description": "Overt. Trump support campaign text message from #45470. Malicious. Received on a victims hyper compromised iPhone. Attempts to or did take CnC of device. Stutters device, changed App Store , has delete service, device sweep,  shuts down service , halts all pages, denial of service, throttles service, steals\npasswords,  bots , I don\u2019t know if device can be refurbished or research purposes - Palantir DC DGA domains - Trump. Multiple IoC\u2019s , malware with code overlap, it appears to be from a legitimate text for updates #. Visibly affected all aspects of device and software. Commands device shut down. \n[OTX populated: Failed to retrieve suggested indicator for beta-ui, according to the latest results from the Welsh Government's Office for National Statistics (ONS) and the National Data Centre (NDS))",
          "modified": "2025-10-16T12:03:14.279000",
          "created": "2025-09-16T12:14:32.327000",
          "tags": [
            "ttl value",
            "extraction",
            "data upload",
            "failed",
            "extra data",
            "include review",
            "exclude sugges",
            "stop",
            "line",
            "path",
            "polyline",
            "getprocaddress",
            "circle",
            "span",
            "ck id",
            "mitre att",
            "ck matrix",
            "null",
            "error",
            "open",
            "spinner",
            "title",
            "code",
            "iframe",
            "window",
            "void",
            "infinity",
            "crypto",
            "footer",
            "generator",
            "general",
            "format",
            "click",
            "strings",
            "meta",
            "install",
            "encoder",
            "learn",
            "command",
            "name tactics",
            "suspicious",
            "informative",
            "spawns",
            "evasion att",
            "t1480 execution",
            "file defense",
            "adversaries",
            "calls",
            "reads",
            "defense evasion",
            "model",
            "server",
            "registrar abuse",
            "ascio",
            "contact phone",
            "admin city",
            "admin country",
            "admin postal",
            "dnssec",
            "http",
            "ip address",
            "passive dns",
            "related nids",
            "urls",
            "files location",
            "united",
            "flag united",
            "a domains",
            "search",
            "unknown aaaa",
            "certificate",
            "yara detections",
            "av detections",
            "ids detections",
            "alerts",
            "entries elf",
            "filehash",
            "name servers",
            "servers",
            "moved",
            "script script",
            "aaaa",
            "unknown ns",
            "domain add",
            "formbook cnc",
            "checkin",
            "lowfi",
            "mtb jun",
            "github pages",
            "twitter",
            "accept",
            "cryptobit",
            "extra",
            "referen data",
            "trojanproxy",
            "dynamicloader",
            "high",
            "write c",
            "medium",
            "intel",
            "ms windows",
            "entries",
            "pe32",
            "explorer",
            "worm",
            "write",
            "next",
            "trojan",
            "hellspawn",
            "md5 add",
            "malware",
            "data",
            "included iocs",
            "script urls",
            "script domains",
            "gmt content",
            "cash amtincart",
            "expirestue",
            "domain related",
            "sea x",
            "accept encoding",
            "request id",
            "body doctype",
            "apache",
            "encrypt",
            "skynet",
            "third eye tv",
            "calling",
            "delete app",
            "potus",
            "mtb aug",
            "backdoor",
            "gmt cache",
            "sameorigin",
            "443 ma2592000",
            "ipv4 add",
            "utilads",
            "trojandropper",
            "mtb sep",
            "win32upatre aug",
            "yara rule",
            "as15169",
            "guard",
            "smartassembly",
            "associated urls",
            "date checked",
            "url hostname",
            "server response",
            "domain",
            "url analysis",
            "files",
            "date",
            "delete service",
            "45470",
            "text",
            "hybrid",
            "present sep",
            "body",
            "fastly error",
            "please",
            "xor xor",
            "sha256 add",
            "analysis date",
            "file score",
            "detections alf",
            "june",
            "delphi",
            "attempts",
            "yara",
            "high security",
            "file type",
            "pe packer",
            "ransom"
          ],
          "references": [
            "skynet-dev.tcxn.net tcxn.net Registrar Ascio Technologies, Inc - connection to cloud proxy",
            "TrojanProxy:Win32/Malynfits CodeOverlap TrojanSpy:Win32/Nivdort CodeOverlap virus:Win32/Lywer CodeOverlap",
            "https://cryptobit.live/build/assets/app-CkRYqsKL.js \u2022 cryptobit.live \u2022 t.page \u2022 cdn.wallets.cryptobit.live",
            "Trump Support campaign \u2022_\u2022 lantana-mgmt.washington.palantircloud.com \u2022 containers-reishi.palantirfedstart.com",
            "Virus:DOS/Hellspawn 192.168.122.49 10/16/25\t\u2022  IPv4 142.251.9.105",
            "IDS Detections: Win32/Enosch.A gtalk connectivity check | W32/MoonLight.worm User-Agent (HellSpawn)",
            "PWS:Win32/Ymacco.AA50 Win.Trojan.Generic-9959068-0\t SLF:MSIL/PSTAnomaly.A Win.Dropper.Shakblades-7614016-0\t#LowFI:VBExpensiveLoop Win.Packed.Barys-10031677-0\tTEL:Trojan:MSIL/AgentTesla.VPA!MTB Win.Trojan. Backdoor:MSIL/Remcos!MTB",
            "hasownproperty.call \u2022 fireeye.grhd.",
            "Apple Store verified drop down breach  \u2018Apple took a screenshot of pages\u201d"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy:Win32/Nivdort",
              "display_name": "TrojanSpy:Win32/Nivdort",
              "target": "/malware/TrojanSpy:Win32/Nivdort"
            },
            {
              "id": "TrojanProxy:Win32/Malynfits",
              "display_name": "TrojanProxy:Win32/Malynfits",
              "target": "/malware/TrojanProxy:Win32/Malynfits"
            },
            {
              "id": "Virus:Win32/Lywer",
              "display_name": "Virus:Win32/Lywer",
              "target": "/malware/Virus:Win32/Lywer"
            },
            {
              "id": "Worm:Win32/Lightmoon.H",
              "display_name": "Worm:Win32/Lightmoon.H",
              "target": "/malware/Worm:Win32/Lightmoon.H"
            },
            {
              "id": "Virus:DOS/Hellspawn",
              "display_name": "Virus:DOS/Hellspawn",
              "target": "/malware/Virus:DOS/Hellspawn"
            },
            {
              "id": "Win.Trojan.Dialer-266",
              "display_name": "Win.Trojan.Dialer-266",
              "target": null
            },
            {
              "id": "AgentTesla",
              "display_name": "AgentTesla",
              "target": null
            },
            {
              "id": "Backdoor:MSIL/Remcos",
              "display_name": "Backdoor:MSIL/Remcos",
              "target": "/malware/Backdoor:MSIL/Remcos"
            },
            {
              "id": "ALF:JASYP:Trojan:Win32/IRCbot!atmn",
              "display_name": "ALF:JASYP:Trojan:Win32/IRCbot!atmn",
              "target": null
            },
            {
              "id": "Trojandropper:Win32/Muldrop.V!MTB",
              "display_name": "Trojandropper:Win32/Muldrop.V!MTB",
              "target": "/malware/Trojandropper:Win32/Muldrop.V!MTB"
            },
            {
              "id": "#LowFI:VBExpensiveLoop",
              "display_name": "#LowFI:VBExpensiveLoop",
              "target": null
            },
            {
              "id": "TEL:Trojan:MSIL/AgentTesla.VPA!MTB",
              "display_name": "TEL:Trojan:MSIL/AgentTesla.VPA!MTB",
              "target": null
            },
            {
              "id": "PWS:Win32/VB.CU",
              "display_name": "PWS:Win32/VB.CU",
              "target": "/malware/PWS:Win32/VB.CU"
            },
            {
              "id": "ALF:Ransom:Win32/Babax.SG!MTB",
              "display_name": "ALF:Ransom:Win32/Babax.SG!MTB",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1489",
              "name": "Service Stop",
              "display_name": "T1489 - Service Stop"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 690,
            "URL": 1479,
            "domain": 476,
            "FileHash-MD5": 526,
            "FileHash-SHA1": 505,
            "FileHash-SHA256": 1509,
            "email": 6
          },
          "indicator_count": 5191,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "227 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6844240c68255798e08beb3b",
          "name": "Bilety online: Tw\u00f3j kolejowy partner w podr\u00f3\u017cy",
          "description": "Microsoft has created a new version of its XMLHttpRequest, which allows users to access a website, via a browser or browser without the permission of a third party, using the same address.",
          "modified": "2025-07-07T00:01:51.704000",
          "created": "2025-06-07T11:35:40.942000",
          "tags": [
            "sign",
            "google sign",
            "forgot email",
            "criminalip",
            "create account",
            "bilety online",
            "sprzeday biletw",
            "polregio",
            "ssdeep",
            "license",
            "typeerror",
            "regexp",
            "promise",
            "function",
            "version",
            "typeof symbol",
            "copyright",
            "google llc",
            "apache license",
            "date",
            "without",
            "error",
            "blank",
            "trident",
            "generator",
            "class",
            "mountain view",
            "android",
            "submission",
            "california",
            "common name",
            "google inc",
            "unit android",
            "country code",
            "us state",
            "sha1",
            "sha256",
            "imphash",
            "pehash",
            "file type",
            "vhash",
            "authentihash"
          ],
          "references": [
            "http://bilety.polregio.pl",
            "https://bilety.polregio.pl",
            "http://www.salesmanago.pl/static/sm.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1295,
            "hostname": 302,
            "domain": 137,
            "FileHash-SHA256": 996,
            "FileHash-MD5": 38,
            "FileHash-SHA1": 40,
            "IPv4": 1
          },
          "indicator_count": 2809,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "329 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "675127405277d037355e5db6",
          "name": "Beehive.Systems",
          "description": "#if PRAGMA_ONCE, which includes the word \"pagma\" and the term \"penet\", should not be used as part of any attempt to set a new code.",
          "modified": "2024-12-05T04:08:32.154000",
          "created": "2024-12-05T04:08:32.154000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ilyailya",
            "id": "298851",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 16,
            "domain": 30,
            "hostname": 69
          },
          "indicator_count": 115,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 31,
          "modified_text": "543 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c0029e4e6d6bbe7b036051",
          "name": "https://github.com/imaya/zlib.js & https://github.com/kanaka/noVNC/blob/master/include/input.js",
          "description": "I found these two gems inadvertently while analyzing files that had been written too by whatever the hell this is and came across these urls as strings. plugging the urls directly into VT, or OTX proved fruitless so I just cloned the repo directly and what it provided was completely different that what it provided the analysis engines. More than half of the files are completely clean everywhere, but show up as a threat score of 9 or above here on OTX. half of those, were submitted to OTX 4 years ago - VT one year ago. It's a .NET based something and still frankly way over my paygrade.",
          "modified": "2024-03-05T22:00:26.685000",
          "created": "2024-02-04T21:33:18.106000",
          "tags": [
            "environemnt aware",
            "zlib",
            "js",
            "debug aware",
            "obfuscated",
            "long sleeps",
            "node",
            "github",
            ".NET",
            "CCP",
            "sneaky",
            "reactive",
            "APT"
          ],
          "references": [
            "",
            "https://www.virustotal.com/gui/file/7e93f94ac2d263e17519c9bcbbd014b1aa6c6d81b4198120760fd53258402b16/behavior",
            "https://any.run/report/3ba4834f3aa66174954319b1c1b8c708d3a169c0e4bcf9b1c7767c252abc78c9/6c030f14-638b-4d1f-857b-1c6dfbf71190?_gl=1*r6j8c3*_gcl_au*MTA5NTQzMjU3Ni4xNzA3MDcyMTY3*_ga*NjUwNDYyMTM1LjE3MDcwNzIxNjg.*_ga_53KB74YDZR*MTcwNzA3MjE2NC4xLjEuMTcwNzA3NzMzMy4wLjAuMA..#Static%20information",
            "https://www.virustotal.com/gui/url/45e7587df7e63542283047682750057788692266da7bf92f44f384a095887bd6",
            "https://www.virustotal.com/gui/file/420be75183f496e85363aed933631faaf491917d63c18d592fadbd5d55df0063/behavior",
            "https://any.run/report/3ba4834f3aa66174954319b1c1b8c708d3a169c0e4bcf9b1c7767c252abc78c9/6c030f14-638b-4d1f-857b-1c6dfbf71190?_gl=1*zsj01h*_gcl_au*MTA5NTQzMjU3Ni4xNzA3MDcyMTY3*_ga*NjUwNDYyMTM1LjE3MDcwNzIxNjg.*_ga_53KB74YDZR*MTcwNzA3MjE2NC4xLjEuMTcwNzA3OTI3OS4wLjAuMA..",
            "https://vtbehaviour.commondatastorage.googleapis.com/5346535cf86a93ab91f8510f0756a10034c4bd2d79f76dc8546d35c382a6f456_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1707084067&Signature=WcgSQU%2BALxfJwiKisWIi5MXWnpHKYcRUqjUtnikULwnB5IipfnmyuserevOZ8CTS%2FRDUR9Y2OgiYzb5HsCV1FU9qbGo%2FmhPphHKqL2CAFaCI8GnVHeiz1UpDXFlB%2Bh6FI%2B%2B3YCb%2BXr9Fw%2B1VpCuuJFXtUmrD8Cb9GsGde%2FgwMQX1IPZiBzegDN1hc%2BgsLkYioMDi%2Bsh%2BbDdvVWiMYlY2Z4uR%2B7vUBXdIt%2F%2FUfmof",
            "https://www.virustotal.com/gui/file/67e7028926a58f732336b592945c72af641afb6d9b835d1e463105cfdbd1a77a/details",
            "https://app.any.run/tasks/6c030f14-638b-4d1f-857b-1c6dfbf71190",
            "https://www.virustotal.com/gui/file/45f02b64f1a4396157412cdd25fb17273bae550dfd29c33de8d0bbd6260bbc66/behavior",
            "https://www.hybrid-analysis.com/file-collection/65bfeeb7a6c0ce4494026e35",
            "https://www.virustotal.com/gui/file/5346535cf86a93ab91f8510f0756a10034c4bd2d79f76dc8546d35c382a6f456/behavior",
            "https://www.virustotal.com/gui/url/63f0e653821a47158d69fac1ede971842368af7c5e903e46caac3e83edc371c9/details",
            "https://vtbehaviour.commondatastorage.googleapis.com/7e93f94ac2d263e17519c9bcbbd014b1aa6c6d81b4198120760fd53258402b16_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1707084255&Signature=glGGS%2BaG%2F8HnZlkeCZuOYgD6ayeYlEXnI46%2Bq3clKoDEaPGwAGqidiQQcqoZj%2FpwwlN3oSKAEwaDhGgS2yn35nrU1MdX0MMQE3IUu6UVkUqbU1FDYuHRRlPnp27iNpMugshqeygkHkOMeCXli0WrqWtW7sIBLQRj6sfmfujKlheok7RwQspu%2Ft1SytFOmMCfM7YqAFADTj7WU9JjCvgzjJA9MFHcZ4IViuJHI5y5gJuUa5a%2F7N",
            "https://otx.alienvault.com/indicator/url/https://github.com/kanaka/noVNC/blob/master/include/input.js",
            "https://vtbehaviour.commondatastorage.googleapis.com/7e93f94ac2d263e17519c9bcbbd014b1aa6c6d81b4198120760fd53258402b16_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1707084256&Signature=dYoVJj0iMC1%2BgtnhdiQHT4HWnqp0%2FLpvOhpzPsb3j3iskv25mbsb3oocaeeWs8rF1Vl5bTV%2B4FAIcSsp69SD3g7SYAwExGZPknXuS%2FucApcHr08O73qt9NGsN3k%2B94DDXzQ00nP8JAcEmnAjiGeIjNOi9mUDDn9rHv29PXSaHF8g0EFjGw5pCdtMudmOgRxd9nK7NnLMvVgV0UX5r5TQpvvrkJ%2B7vEyKePd%2FvoIGA%2Bxgmp9ccfvd%2"
          ],
          "public": 1,
          "adversary": "unkown - Chinese speaking",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Unknown",
              "display_name": "Unknown",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            }
          ],
          "industries": [
            "individuals"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Merkd1904",
            "id": "196517",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 22,
            "hostname": 40,
            "FileHash-SHA1": 5,
            "URL": 43,
            "FileHash-MD5": 2,
            "FileHash-SHA256": 2
          },
          "indicator_count": 114,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 73,
          "modified_text": "817 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64da05cdba55fc9cf872cb11",
          "name": "IOC's off of my personal devices Aug 14th - June 28th | Come one come all, something for everyone",
          "description": "Now that I've been able to get a pulse published I'm going to be recursively and actively updating this pulse with IOC's pulled off of files marked malicious, suspicious, ambigious, or clean with a threat score from my personal devices. I will also add files that have a high amount of indicators and no threat score as well and let AlienVault sort it out. Hopefully I'll be able i'll be able to fill the gap to my last Pulse the better part of a year ago. \n\nNearly all of these files are debug and VM aware, with a majority having a legitimate certificate chain. The ones that do run have been initialized in a live environment (aka my desktop, laptop, phone, etc).",
          "modified": "2024-02-14T21:44:01.779000",
          "created": "2023-08-14T10:45:33.014000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "falcon sandbox",
            "hybrid analysis",
            "sandbox files",
            "urls quick",
            "scans files",
            "urls file",
            "releases",
            "updates faq",
            "public api",
            "knowledge base"
          ],
          "references": [
            "https://otx.alienvault.com/indicator/file/b197cf4cee44d52be11275f49f3143b4f7f8e735",
            "https://hybrid-analysis.com/sample/4dbe669e9b8b9cfe1bfa98019ccf2e56230ed136adce966649ee38e61e934303/64da0aedbe662a714b0480b1",
            "https://www.virustotal.com/gui/file/207bfec939e7c017c4704ba76172ee2c954f485ba593bc1bc8c7666e78251861/behavior",
            "https://www.virustotal.com/gui/file/3db36d262eb15c349b4b945e0b1d9772c262cd2b7d57c40ede429958daeab97e?nocache=1",
            "https://otx.alienvault.com/indicator/file/08515dcc6df957c9c5d4f00db4f568b3ee29c337",
            "https://www.joesandbox.com/analysis/1041402",
            "http://hybrid-analysis.com/sample/e9fc2ca7297a65937de9887be565eb5bbd149ba2c1a1ea4d3ca88302ede7ecac",
            "https://www.virustotal.com/gui/file/a7b4797c4a29864aacb7b40dd854adaf3936791d7c326d02d4aad37982d801a9/community",
            "http://hybrid-analysis.com/sample/e4db1656c4cfff0a4ced5a943b8433388c7b4935711d522014c819328f19001d/64da070d00534407c40c1034",
            "http://hybrid-analysis.com/sample/4dbe669e9b8b9cfe1bfa98019ccf2e56230ed136adce966649ee38e61e934303",
            "http://hybrid-analysis.com/sample/4cf079d4d7a154cd93f65934b5d115f07af8f25ee24930e6cc606dfb0aea2a4e",
            "https://otx.alienvault.com/indicator/file/1831d8972bfae639576d10903c2d586e",
            "https://hybrid-analysis.com/sample/beff391ce640cc8fdfcec22b77c5d2bc4776304e3a404e8168ce315226c4fc41/5eae8f731389173b4c432b17",
            "https://otx.alienvault.com/indicator/file/c85cc6f8ff7d69d7a7af9498d7d75bc05e35fb69f34d7b50d9057608f7b73f51",
            "",
            "https://tria.ge/230806-j3tdasgd72",
            "https://tria.ge/230806-j8mspsgd84",
            "https://tria.ge/230806-j8tk9ahg7t",
            "https://tria.ge/230809-vsggjadf59",
            "https://tria.ge/230809-vtdr2afd2t"
          ],
          "public": 1,
          "adversary": "Unknown - Most likely multiple spanning Cyrillic and Chinese in terms of artifacts",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "neshta",
              "display_name": "neshta",
              "target": null
            },
            {
              "id": "Expiro",
              "display_name": "Expiro",
              "target": null
            },
            {
              "id": "Win.Dropper.Gh0stRAT",
              "display_name": "Win.Dropper.Gh0stRAT",
              "target": null
            },
            {
              "id": "Win.Malware.Eclz-9953021-0",
              "display_name": "Win.Malware.Eclz-9953021-0",
              "target": null
            },
            {
              "id": "Win32:Farfli-BH",
              "display_name": "Win32:Farfli-BH",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Nemucod",
              "display_name": "TrojanDownloader:Win32/Nemucod",
              "target": "/malware/TrojanDownloader:Win32/Nemucod"
            },
            {
              "id": "Win.Malware.Snojan-6775202-0",
              "display_name": "Win.Malware.Snojan-6775202-0",
              "target": null
            },
            {
              "id": "Win.Malware.Qshell-9875653-0",
              "display_name": "Win.Malware.Qshell-9875653-0",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Zegost.E!bit",
              "display_name": "TrojanDownloader:Win32/Zegost.E!bit",
              "target": "/malware/TrojanDownloader:Win32/Zegost.E!bit"
            },
            {
              "id": "Backdoor:Win32/Zegost.CQ!bit",
              "display_name": "Backdoor:Win32/Zegost.CQ!bit",
              "target": "/malware/Backdoor:Win32/Zegost.CQ!bit"
            },
            {
              "id": "#Lowfi:SuspiciousSectionName",
              "display_name": "#Lowfi:SuspiciousSectionName",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Zegost.gen!B",
              "display_name": "Backdoor:Win32/Zegost.gen!B",
              "target": "/malware/Backdoor:Win32/Zegost.gen!B"
            },
            {
              "id": "Win.Dropper.Gh0stRAT-7696262-0",
              "display_name": "Win.Dropper.Gh0stRAT-7696262-0",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Zegost.BU",
              "display_name": "Backdoor:Win32/Zegost.BU",
              "target": "/malware/Backdoor:Win32/Zegost.BU"
            },
            {
              "id": "Trojan:Win32/Farfli.DSK!MTB",
              "display_name": "Trojan:Win32/Farfli.DSK!MTB",
              "target": "/malware/Trojan:Win32/Farfli.DSK!MTB"
            },
            {
              "id": "Backdoor:Win32/Zegost.BK",
              "display_name": "Backdoor:Win32/Zegost.BK",
              "target": "/malware/Backdoor:Win32/Zegost.BK"
            },
            {
              "id": "HackTool:Win32/Mimikatz.F",
              "display_name": "HackTool:Win32/Mimikatz.F",
              "target": "/malware/HackTool:Win32/Mimikatz.F"
            },
            {
              "id": "Trojan:Win32/GhostRatCrypt.GA!MTB",
              "display_name": "Trojan:Win32/GhostRatCrypt.GA!MTB",
              "target": "/malware/Trojan:Win32/GhostRatCrypt.GA!MTB"
            },
            {
              "id": "Backdoor:Win32/Zegost.CG",
              "display_name": "Backdoor:Win32/Zegost.CG",
              "target": "/malware/Backdoor:Win32/Zegost.CG"
            },
            {
              "id": "Backdoor:Win32/Zegost.AD",
              "display_name": "Backdoor:Win32/Zegost.AD",
              "target": "/malware/Backdoor:Win32/Zegost.AD"
            },
            {
              "id": "Worm:Win32/Sfone.A",
              "display_name": "Worm:Win32/Sfone.A",
              "target": "/malware/Worm:Win32/Sfone.A"
            },
            {
              "id": "Backdoor:Win32/Zegost!atmn",
              "display_name": "Backdoor:Win32/Zegost!atmn",
              "target": "/malware/Backdoor:Win32/Zegost!atmn"
            },
            {
              "id": "Backdoor:Win32/Zegost.H!dll",
              "display_name": "Backdoor:Win32/Zegost.H!dll",
              "target": "/malware/Backdoor:Win32/Zegost.H!dll"
            },
            {
              "id": "Zeppelin_10",
              "display_name": "Zeppelin_10",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win32/Cipduk.D!dha",
              "display_name": "ALF:Trojan:Win32/Cipduk.D!dha",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Zegost.BR",
              "display_name": "Backdoor:Win32/Zegost.BR",
              "target": "/malware/Backdoor:Win32/Zegost.BR"
            },
            {
              "id": "Backdoor:Win32/Farfli.AX",
              "display_name": "Backdoor:Win32/Farfli.AX",
              "target": "/malware/Backdoor:Win32/Farfli.AX"
            },
            {
              "id": "ALF:HeraklezEval:Worm:Win32/Sfone",
              "display_name": "ALF:HeraklezEval:Worm:Win32/Sfone",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Zegost.L",
              "display_name": "Backdoor:Win32/Zegost.L",
              "target": "/malware/Backdoor:Win32/Zegost.L"
            },
            {
              "id": "Backdoor:MSIL/Zegost.GG!MTB",
              "display_name": "Backdoor:MSIL/Zegost.GG!MTB",
              "target": "/malware/Backdoor:MSIL/Zegost.GG!MTB"
            },
            {
              "id": "SLF:Win32/Dozlodz.A!MTB",
              "display_name": "SLF:Win32/Dozlodz.A!MTB",
              "target": "/malware/SLF:Win32/Dozlodz.A!MTB"
            },
            {
              "id": "Win64:Xpirat\\ [Inf]",
              "display_name": "Win64:Xpirat\\ [Inf]",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Zegost.KM!MTB",
              "display_name": "Backdoor:Win32/Zegost.KM!MTB",
              "target": "/malware/Backdoor:Win32/Zegost.KM!MTB"
            },
            {
              "id": "AdvancedInstaller",
              "display_name": "AdvancedInstaller",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/Venik",
              "display_name": "TrojanDropper:Win32/Venik",
              "target": "/malware/TrojanDropper:Win32/Venik"
            },
            {
              "id": "hacker87",
              "display_name": "hacker87",
              "target": null
            },
            {
              "id": "PurpleFox",
              "display_name": "PurpleFox",
              "target": null
            },
            {
              "id": "PCRat",
              "display_name": "PCRat",
              "target": null
            },
            {
              "id": "Gh0stCringe",
              "display_name": "Gh0stCringe",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "individuals"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Merkd1904",
            "id": "196517",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2387,
            "FileHash-SHA1": 2126,
            "FileHash-SHA256": 9395,
            "SSLCertFingerprint": 27,
            "domain": 88,
            "URL": 185,
            "hostname": 165,
            "email": 11
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 82,
          "modified_text": "837 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c8f50527fb73205bfca",
          "name": "Dreamhost.com - Drift Widget",
          "description": "",
          "modified": "2023-12-06T15:00:31.809000",
          "created": "2023-12-06T15:00:31.809000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 174,
            "domain": 464,
            "URL": 1119,
            "hostname": 156,
            "FileHash-MD5": 2,
            "FileHash-SHA1": 1
          },
          "indicator_count": 1916,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62e80d56fba248bac0744780",
          "name": "\ud83e\udd14\ud83d\udea8 Could this be the source of all Evil? \ud83d\udea8\ud83e\udd14 Nubotnet - Team:KU Leuven/test2 - 2021.igem.org",
          "description": "",
          "modified": "2022-08-31T00:01:05.509000",
          "created": "2022-08-01T17:28:54.991000",
          "tags": [
            "apt",
            "runtime data",
            "decrypted ssl",
            "pcap",
            "windows nt",
            "tops",
            "cookie",
            "typeof t",
            "element",
            "error",
            "matrix",
            "typeerror",
            "bmfloor",
            "frameelement",
            "null",
            "skew",
            "parade"
          ],
          "references": [
            "https://2021.igem.org/Team:KU_Leuven/test2",
            "https://hybrid-analysis.com/sample/e126ff94aac3340dc05a27f062c4267cbfeaa998248bef0e72f000bba711aa76/62e6fb475edc950b894aa7b0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1696,
            "domain": 586,
            "hostname": 613,
            "FileHash-SHA256": 533,
            "FileHash-MD5": 34,
            "FileHash-SHA1": 33,
            "email": 1
          },
          "indicator_count": 3496,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 394,
          "modified_text": "1370 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62e69610305a20de80232e50",
          "name": ";http://tdarr.io/ - yet more net.sh",
          "description": "",
          "modified": "2022-08-30T00:01:48.297000",
          "created": "2022-07-31T14:47:44.291000",
          "tags": [
            "trojan",
            "apt",
            "runtime data",
            "decrypted ssl",
            "typeerror",
            "typeof symbol",
            "null",
            "accept",
            "unknown",
            "roboto",
            "generator",
            "matrix",
            "internal",
            "blank",
            "trident",
            "discord",
            "facebook",
            "twitch",
            "backend",
            "twitter",
            "suser",
            "android",
            "meta",
            "skew",
            "parade",
            "click",
            "malicious",
            "mozilla",
            "suspicious",
            "network traffic",
            "net.sh"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/3782c093f4a54060ab6a269e2cc5a0334352f4c210500d370f185b6799f0007a/62e280899822900706678798",
            "tdarr.io",
            "net.sh neural netw"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 786,
            "hostname": 498,
            "FileHash-SHA256": 122,
            "domain": 139,
            "FileHash-MD5": 43,
            "FileHash-SHA1": 36
          },
          "indicator_count": 1624,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 393,
          "modified_text": "1371 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62676c65b80720b582b46037",
          "name": "Dreamhost.com - Drift Widget",
          "description": "function.1, a new version of JavaScript, has been added to the end of the year to make it easier for users to keep up with the latest developments in the search for a specific date.",
          "modified": "2022-05-25T00:04:03.622000",
          "created": "2022-04-26T03:52:05.599000",
          "tags": [
            "template7class",
            "regexp",
            "root",
            "context",
            "match",
            "body",
            "template7",
            "error",
            "prop",
            "function",
            "date",
            "null",
            "slice",
            "void",
            "factory",
            "window",
            "find",
            "simple",
            "false",
            "hj",
            "object",
            "hotjar",
            "email",
            "typeof symbol",
            "typeof e",
            "telefon",
            "array",
            "survey",
            "meta",
            "cookie",
            "scroll",
            "keypress",
            "trident",
            "live",
            "fullscreen",
            "generic",
            "widget",
            "ciudad",
            "adore",
            "experiment",
            "mutation",
            "click",
            "pluginname",
            "hidden",
            "nttt",
            "fieldset",
            "class",
            "form",
            "fast",
            "jquery",
            "format",
            "february",
            "april",
            "june",
            "august",
            "nova",
            "paris",
            "tokyo",
            "easy",
            "speed",
            "back",
            "target",
            "copy",
            "kill",
            "this",
            "infinity",
            "accept",
            "locale",
            "custom build",
            "https",
            "boolean",
            "new boolean",
            "typeof",
            "typeerror",
            "bootstrap",
            "typeof t",
            "javascript",
            "show",
            "drift widget",
            "segoe ui",
            "emoji",
            "type",
            "copyright",
            "browse",
            "roboto",
            "helvetica neue",
            "arial",
            "noto",
            "apple color",
            "twitter",
            "typeof require",
            "modulenotfound",
            "font awesome",
            "typeof define",
            "script",
            "new date",
            "number",
            "trackevent",
            "string",
            "watched",
            "search",
            "clicked",
            "path",
            "starter",
            "download",
            "derek",
            "code",
            "esnull",
            "gtmphvk7ln",
            "closure library",
            "xdfunction",
            "reduceright",
            "vd",
            "g1f7wlmm0k2",
            "r420",
            "uint8array",
            "typeof d",
            "ieproto",
            "typeof n",
            "widgetrootqa",
            "driftconductor"
          ],
          "references": [
            "xfe-URL-Dreamhost.com-stix2-2.1-export.json",
            "https://js.driftt.com/include/1650944100000/2y43hyefanc8.js",
            "https://www.google-analytics.com/plugins/ua/linkid.js",
            "https://www.googletagmanager.com/gtag/js?id=G-1F7WLMM0K2&l=dataLayer&cx=c",
            "https://www.google-analytics.com/gtm/optimize.js?id=GTM-PHVK7LN",
            "https://www.googletagmanager.com/gtm.js?id=GTM-TLN654",
            "https://kit.fontawesome.com/7d998cc9b7.js",
            "https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js",
            "https://www.dreamhost.com/assets/bootstrap-aa47564acfdf18ce859b8e1fd130d889920ae66415b3db4de8505d42a0477b09.css",
            "https://js.driftt.com/core?embedId=2y43hyefanc8&region=US&forceShow=false&skipCampaigns=false&sessionId=5a8c1b8d-2626-4a43-a7a6-76e9416f2f52&sessionStarted=1650943819.009&campaignRefreshToken=a2d9846a-8932-4e3c-a8d5-878681a555e0&hideController=false&pageLoadStartTime=1650943817154&mode=CHAT&driftEnableLog=false",
            "https://js.driftt.com/core/chat?region=US&driftEnableLog=false&pageLoadStartTime=1650943817154",
            "https://vars.hotjar.com/box-4924254a9ce4dc9b959b6e4a9b662d60.html",
            "https://www.dreamhost.com/assets/scripts/bootstrap-7670fc8587f9fd0608d2af67f392281a9a4fbf4cb4252952ecb8d34f6ee286b3.js",
            "https://www.dreamhost.com/assets/scripts/webp-support-1dd791309dc3fa5b166a0a326e49345fe5acb5acbc1831f4c7be87efce1abf51.js",
            "https://www.dreamhost.com/assets/site-75a1aba399db4de4e4093997b8fc8ff8ec5e65b5f4258c9a658a5cacacbf6e0d.js",
            "https://script.hotjar.com/modules.0076bf93c385ddf0ff58.js",
            "https://cdn.abrankings.com/js/client.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "hj",
              "display_name": "hj",
              "target": null
            },
            {
              "id": "Vd",
              "display_name": "Vd",
              "target": null
            },
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 174,
            "URL": 1119,
            "domain": 464,
            "hostname": 156,
            "FileHash-MD5": 2,
            "FileHash-SHA1": 1
          },
          "indicator_count": 1916,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1468 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62549aabb033e7afc5069f98",
          "name": "Malware - victim=fr",
          "description": "Mme, Mlle,   M. Compte, yn \u00f4l \u00c2\u00a31.5m (\u20ac2.4m; \u00e2\u201a\u00ac1m)",
          "modified": "2022-05-11T21:04:45.103000",
          "created": "2022-04-11T21:16:27.786000",
          "tags": [
            "freebox",
            "free",
            "mois pendant",
            "sabonner voir",
            "fibre free",
            "la fibre",
            "votre",
            "wifi",
            "freebox en",
            "offre",
            "delta",
            "face",
            "prix",
            "date",
            "this",
            "typeof e",
            "true",
            "function",
            "left",
            "bottom",
            "html",
            "nullt",
            "false",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "close",
            "null",
            "back",
            "bounce",
            "kolab",
            "target",
            "object",
            "tcfuiservice",
            "reflect",
            "typeof proxy",
            "boolean",
            "agree",
            "disagree",
            "select",
            "save",
            "learn",
            "click",
            "gnu gpl",
            "copyright",
            "javascript code",
            "license",
            "extwin1",
            "framed1",
            "roundcube",
            "webmail client",
            "script",
            "team",
            "format",
            "regexp",
            "software",
            "error",
            "pseudo",
            "child",
            "the software",
            "sufeffxa0",
            "class",
            "attr",
            "javascript",
            "express",
            "nous",
            "didomi",
            "typeof t",
            "hmuvfyyh",
            "sekindo",
            "lkqd",
            "aol cdn",
            "ffffff",
            "montserrat",
            "adsl",
            "offres adsl",
            "internet",
            "t\u00e9l\u00e9phone",
            "t\u00e9l\u00e9phonie",
            "mobiles",
            "forfaits mobiles",
            "tv",
            "t\u00e9l\u00e9vision",
            "vod",
            "vid\u00e9o \u00e0 la demande",
            "multiposte",
            "radio",
            "routeur",
            "freeplayer",
            "multiplay",
            "d\u00e9groupage",
            "total",
            "partiel",
            "e-mail",
            "mail",
            "m\u00e9l",
            "fournisseur d'acc\u00e8s",
            "i.s.p.",
            "isp",
            "internaute",
            "internautes",
            "france",
            "fran\u00e7ais",
            "zimbra",
            "le webmail",
            "free fait",
            "webmail imp",
            "cela n",
            "webmail zimbra",
            "stockage",
            "pour migrer",
            "accder",
            "testteltext",
            "sans",
            "testziptext",
            "testziptext i",
            "testteltext i",
            "typenumber",
            "screenh",
            "tvbycanal",
            "tvbycanal147",
            "tvbycanal204",
            "tvbycanal83",
            "tvbycanal80",
            "tvbycanal34",
            "4000",
            "typeof console",
            "console",
            "nullc",
            "nulld",
            "customevent",
            "msanimationend",
            "typeof n",
            "typeof r",
            "x20trnf",
            "width",
            "accept",
            "json",
            "moz o",
            "custom build",
            "https",
            "xmlhttprequest",
            "typeof module",
            "webkit",
            "android",
            "flash",
            "span",
            "un espace",
            "phpmysql",
            "helvetica"
          ],
          "references": [
            "xfe-IP-212.27.63.109-stix2-2.1-export.json",
            "http://pageperso.free.fr/im/css/free.css",
            "http://passback.free.fr/pub/pp_300x250.html",
            "https://subscribe.free.fr/accesgratuit/index.html",
            "https://subscribe.free.fr/assets/js/vendor/modernizr.custom.js",
            "https://subscribe.free.fr/assets/js/vendor/jquery-1.9.1.min.js",
            "https://subscribe.free.fr/assets/js/plugins.min.js",
            "https://subscribe.free.fr/assets/js/vendor/wow.min.js",
            "https://subscribe.free.fr/assets/js/main.min.js",
            "https://subscribe.free.fr/assets/css/accesgratuit.min.css",
            "https://subscribe.free.fr/assets/css/app2.min.css",
            "https://webmail.free.fr/",
            "https://sdk.privacy-center.org/87df2f8d-232a-4617-8efc-3764b3bbd0c0/loader.js?target=webmail.free.fr",
            "https://webmail.free.fr/program/js/jquery.min.js?s=1510166541",
            "https://webmail.free.fr/program/js/app.min.js?s=1510166525",
            "https://sdk.privacy-center.org/ui-gdpr-en.a96c69ed0cb8f37a2deea6c49dd453517875ac60.js",
            "https://webmail.free.fr/plugins/jqueryui/js/jquery-ui.min.js?s=1510166524",
            "https://www.free.fr/freebox/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1078,
            "URL": 2104,
            "domain": 290,
            "FileHash-SHA256": 117,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 2
          },
          "indicator_count": 3595,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1481 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "624fc692f1d830cd6e86956b",
          "name": "ReduceRight",
          "description": "If you want to know what to do with your intercoms, spare a thought for e.intercom and add a new listener to your browser.. and use it to control the system.",
          "modified": "2022-05-08T00:03:14.586000",
          "created": "2022-04-08T05:22:26.672000",
          "tags": [
            "typerange",
            "40deg",
            "segoe ui",
            "roboto",
            "arial",
            "consolas",
            "liberation mono",
            "menlo",
            "45deg",
            "webkitkeyframes",
            "object",
            "error",
            "please",
            "post",
            "urlsearchparams",
            "paused",
            "sfunction",
            "scene",
            "event",
            "after",
            "problem",
            "date",
            "next",
            "close",
            "typeof define",
            "typeof module",
            "html tags",
            "ox20trnf",
            "dom element",
            "regexp",
            "typeof e",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "function",
            "symbol",
            "corejs",
            "denis pushkarev",
            "array",
            "typeof window",
            "typeof self",
            "string",
            "ieproto",
            "activexobject",
            "formdata",
            "customevent",
            "typeof o",
            "typeof s",
            "json response",
            "refill",
            "wpcf7",
            "wpcf7locale",
            "typeerror",
            "generator",
            "iab2",
            "code",
            "n color",
            "number",
            "cookie",
            "n strictly",
            "hostn host",
            "button",
            "null",
            "65535",
            "typeof symbol",
            "promise",
            "msie",
            "trident",
            "banner",
            "genven",
            "expecting iab",
            "iab tcf",
            "oldcctid",
            "newdomainid",
            "unknown",
            "acceptall",
            "rejectall",
            "checkbox",
            "reduceright",
            "custom",
            "trackevent",
            "purchase",
            "viewcontent",
            "facebook pixel",
            "uetpush",
            "copyright",
            "path",
            "contact",
            "void",
            "image",
            "price",
            "pnull",
            "html",
            "style",
            "ctnull",
            "uint32array",
            "fanull",
            "license",
            "ynull",
            "config",
            "meta",
            "body",
            "iframe",
            "accept",
            "syntaxerror",
            "xmlhttprequest",
            "samesitelax",
            "innull",
            "snnull",
            "addtocart",
            "signup",
            "addtowishlist",
            "lead",
            "typeof require",
            "sha256",
            "search",
            "typeof",
            "pixel code",
            "iterator",
            "constantvalue",
            "globalvariable",
            "facebook",
            "service",
            "phonenumber",
            "boolean",
            "functional",
            "member",
            "bnew regexp",
            "qfunction",
            "adview",
            "addbillinginfo",
            "addtolist",
            "download",
            "install",
            "09af",
            "ver0",
            "tag0",
            "extdata0",
            "ua ch",
            "invalid",
            "edge",
            "dataname",
            "intercom",
            "apple",
            "webkiti",
            "criosi"
          ],
          "references": [
            "https://widget.intercom.io/widget/wsyrfbge",
            "xfe-IP-193.176.186.154-stix2-2.0-export.json",
            "https://bat.bing.com/bat.js",
            "https://snap.licdn.com/li.lms-analytics/insight.min.js",
            "https://connect.facebook.net/signals/config/459577157542621?v=2.9.57&r=stable",
            "https://connect.facebook.net/signals/plugins/identity.js?v=2.9.57",
            "https://connect.facebook.net/en_US/fbevents.js",
            "https://www.redditstatic.com/ads/pixel.js",
            "https://sc.lfeeder.com/lftracker_v1_lYNOR8xM56G7WQJZ.js",
            "https://h.clarity.ms/s/0.6.34/clarity.js",
            "https://www.clarity.ms/tag/7oq672bycl",
            "https://www.googletagmanager.com/gtm.js?id=GTM-5GRKNZJ",
            "https://cdn-ukwest.onetrust.com/scripttemplates/otSDKStub.js",
            "https://www.clickcease.com/monitor/stat.js",
            "https://cdn-ukwest.onetrust.com/scripttemplates/6.17.0/otBannerSdk.js",
            "https://www.heficed.com/wp/wp-includes/js/dist/vendor/regenerator-runtime.min.js",
            "https://www.heficed.com/wp/wp-includes/js/dist/vendor/wp-polyfill.min.js",
            "https://www.heficed.com/app/cache/min/1/app/plugins/contact-form-7/includes/js/index.js?ver=1647518891",
            "https://www.heficed.com/wp/wp-includes/js/jquery/jquery.min.js",
            "https://www.heficed.com/wp/wp-includes/js/jquery/jquery-migrate.min.js",
            "https://www.heficed.com/app/cache/min/1/app/themes/heficed-theme/dist/scripts/main_66bf268e.js?ver=1647518891",
            "https://www.heficed.com/app/cache/min/1/05ffa85815681d905ca82cbee25d8762.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 242,
            "URL": 401,
            "FileHash-SHA256": 69,
            "domain": 47,
            "FileHash-MD5": 1,
            "email": 1
          },
          "indicator_count": 761,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1485 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "https://www.dreamhost.com/assets/site-75a1aba399db4de4e4093997b8fc8ff8ec5e65b5f4258c9a658a5cacacbf6e0d.js",
        "http://pageperso.free.fr/im/css/free.css",
        "http://www.salesmanago.pl/static/sm.js",
        "net.sh neural netw",
        "https://www.heficed.com/app/cache/min/1/app/themes/heficed-theme/dist/scripts/main_66bf268e.js?ver=1647518891",
        "http://hybrid-analysis.com/sample/e9fc2ca7297a65937de9887be565eb5bbd149ba2c1a1ea4d3ca88302ede7ecac",
        "https://sdk.privacy-center.org/87df2f8d-232a-4617-8efc-3764b3bbd0c0/loader.js?target=webmail.free.fr",
        "Apple Store verified drop down breach  \u2018Apple took a screenshot of pages\u201d",
        "http://passback.free.fr/pub/pp_300x250.html",
        "https://2021.igem.org/Team:KU_Leuven/test2",
        "https://hybrid-analysis.com/sample/e126ff94aac3340dc05a27f062c4267cbfeaa998248bef0e72f000bba711aa76/62e6fb475edc950b894aa7b0",
        "https://webmail.free.fr/plugins/jqueryui/js/jquery-ui.min.js?s=1510166524",
        "PWS:Win32/Ymacco.AA50 Win.Trojan.Generic-9959068-0\t SLF:MSIL/PSTAnomaly.A Win.Dropper.Shakblades-7614016-0\t#LowFI:VBExpensiveLoop Win.Packed.Barys-10031677-0\tTEL:Trojan:MSIL/AgentTesla.VPA!MTB Win.Trojan. Backdoor:MSIL/Remcos!MTB",
        "https://www.dreamhost.com/assets/bootstrap-aa47564acfdf18ce859b8e1fd130d889920ae66415b3db4de8505d42a0477b09.css",
        "https://www.google-analytics.com/plugins/ua/linkid.js",
        "https://www.virustotal.com/gui/url/45e7587df7e63542283047682750057788692266da7bf92f44f384a095887bd6",
        "https://kit.fontawesome.com/7d998cc9b7.js",
        "https://otx.alienvault.com/indicator/url/https://github.com/kanaka/noVNC/blob/master/include/input.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-TLN654",
        "https://www.googletagmanager.com/gtag/js?id=G-1F7WLMM0K2&l=dataLayer&cx=c",
        "https://tria.ge/230809-vsggjadf59",
        "https://cryptobit.live/build/assets/app-CkRYqsKL.js \u2022 cryptobit.live \u2022 t.page \u2022 cdn.wallets.cryptobit.live",
        "http://hybrid-analysis.com/sample/e4db1656c4cfff0a4ced5a943b8433388c7b4935711d522014c819328f19001d/64da070d00534407c40c1034",
        "https://tria.ge/230806-j8mspsgd84",
        "https://widget.intercom.io/widget/wsyrfbge",
        "https://subscribe.free.fr/accesgratuit/index.html",
        "https://hybrid-analysis.com/sample/4dbe669e9b8b9cfe1bfa98019ccf2e56230ed136adce966649ee38e61e934303/64da0aedbe662a714b0480b1",
        "https://www.dreamhost.com/assets/scripts/webp-support-1dd791309dc3fa5b166a0a326e49345fe5acb5acbc1831f4c7be87efce1abf51.js",
        "https://www.heficed.com/app/cache/min/1/05ffa85815681d905ca82cbee25d8762.css",
        "https://tria.ge/230806-j3tdasgd72",
        "https://webmail.free.fr/program/js/app.min.js?s=1510166525",
        "tdarr.io",
        "https://www.virustotal.com/gui/file/a7b4797c4a29864aacb7b40dd854adaf3936791d7c326d02d4aad37982d801a9/community",
        "https://www.heficed.com/wp/wp-includes/js/dist/vendor/wp-polyfill.min.js",
        "https://www.virustotal.com/gui/file/67e7028926a58f732336b592945c72af641afb6d9b835d1e463105cfdbd1a77a/details",
        "https://www.heficed.com/app/cache/min/1/app/plugins/contact-form-7/includes/js/index.js?ver=1647518891",
        "https://connect.facebook.net/en_US/fbevents.js",
        "https://www.clarity.ms/tag/7oq672bycl",
        "https://www.virustotal.com/gui/file/420be75183f496e85363aed933631faaf491917d63c18d592fadbd5d55df0063/behavior",
        "https://script.hotjar.com/modules.0076bf93c385ddf0ff58.js",
        "https://www.virustotal.com/gui/file/7e93f94ac2d263e17519c9bcbbd014b1aa6c6d81b4198120760fd53258402b16/behavior",
        "https://webmail.free.fr/program/js/jquery.min.js?s=1510166541",
        "TrojanProxy:Win32/Malynfits CodeOverlap TrojanSpy:Win32/Nivdort CodeOverlap virus:Win32/Lywer CodeOverlap",
        "https://www.virustotal.com/gui/file/207bfec939e7c017c4704ba76172ee2c954f485ba593bc1bc8c7666e78251861/behavior",
        "https://www.joesandbox.com/analysis/1041402",
        "https://otx.alienvault.com/indicator/file/c85cc6f8ff7d69d7a7af9498d7d75bc05e35fb69f34d7b50d9057608f7b73f51",
        "IDS Detections: Win32/Enosch.A gtalk connectivity check | W32/MoonLight.worm User-Agent (HellSpawn)",
        "Virus:DOS/Hellspawn 192.168.122.49 10/16/25\t\u2022  IPv4 142.251.9.105",
        "https://www.virustotal.com/gui/file/5346535cf86a93ab91f8510f0756a10034c4bd2d79f76dc8546d35c382a6f456/behavior",
        "https://www.redditstatic.com/ads/pixel.js",
        "http://hybrid-analysis.com/sample/4cf079d4d7a154cd93f65934b5d115f07af8f25ee24930e6cc606dfb0aea2a4e",
        "skynet-dev.tcxn.net tcxn.net Registrar Ascio Technologies, Inc - connection to cloud proxy",
        "https://www.googletagmanager.com/gtm.js?id=GTM-5GRKNZJ",
        "https://hybrid-analysis.com/sample/beff391ce640cc8fdfcec22b77c5d2bc4776304e3a404e8168ce315226c4fc41/5eae8f731389173b4c432b17",
        "http://bilety.polregio.pl",
        "https://cdn-ukwest.onetrust.com/scripttemplates/6.17.0/otBannerSdk.js",
        "https://vtbehaviour.commondatastorage.googleapis.com/7e93f94ac2d263e17519c9bcbbd014b1aa6c6d81b4198120760fd53258402b16_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1707084256&Signature=dYoVJj0iMC1%2BgtnhdiQHT4HWnqp0%2FLpvOhpzPsb3j3iskv25mbsb3oocaeeWs8rF1Vl5bTV%2B4FAIcSsp69SD3g7SYAwExGZPknXuS%2FucApcHr08O73qt9NGsN3k%2B94DDXzQ00nP8JAcEmnAjiGeIjNOi9mUDDn9rHv29PXSaHF8g0EFjGw5pCdtMudmOgRxd9nK7NnLMvVgV0UX5r5TQpvvrkJ%2B7vEyKePd%2FvoIGA%2Bxgmp9ccfvd%2",
        "https://www.virustotal.com/gui/file/45f02b64f1a4396157412cdd25fb17273bae550dfd29c33de8d0bbd6260bbc66/behavior",
        "https://subscribe.free.fr/assets/js/main.min.js",
        "https://cdn-ukwest.onetrust.com/scripttemplates/otSDKStub.js",
        "https://www.clickcease.com/monitor/stat.js",
        "https://vars.hotjar.com/box-4924254a9ce4dc9b959b6e4a9b662d60.html",
        "https://js.driftt.com/core?embedId=2y43hyefanc8&region=US&forceShow=false&skipCampaigns=false&sessionId=5a8c1b8d-2626-4a43-a7a6-76e9416f2f52&sessionStarted=1650943819.009&campaignRefreshToken=a2d9846a-8932-4e3c-a8d5-878681a555e0&hideController=false&pageLoadStartTime=1650943817154&mode=CHAT&driftEnableLog=false",
        "https://www.free.fr/freebox/",
        "xfe-URL-Dreamhost.com-stix2-2.1-export.json",
        "https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js",
        "https://www.dreamhost.com/assets/scripts/bootstrap-7670fc8587f9fd0608d2af67f392281a9a4fbf4cb4252952ecb8d34f6ee286b3.js",
        "xfe-IP-212.27.63.109-stix2-2.1-export.json",
        "https://snap.licdn.com/li.lms-analytics/insight.min.js",
        "https://connect.facebook.net/signals/plugins/identity.js?v=2.9.57",
        "xfe-IP-193.176.186.154-stix2-2.0-export.json",
        "https://any.run/report/3ba4834f3aa66174954319b1c1b8c708d3a169c0e4bcf9b1c7767c252abc78c9/6c030f14-638b-4d1f-857b-1c6dfbf71190?_gl=1*r6j8c3*_gcl_au*MTA5NTQzMjU3Ni4xNzA3MDcyMTY3*_ga*NjUwNDYyMTM1LjE3MDcwNzIxNjg.*_ga_53KB74YDZR*MTcwNzA3MjE2NC4xLjEuMTcwNzA3NzMzMy4wLjAuMA..#Static%20information",
        "https://connect.facebook.net/signals/config/459577157542621?v=2.9.57&r=stable",
        "https://vtbehaviour.commondatastorage.googleapis.com/5346535cf86a93ab91f8510f0756a10034c4bd2d79f76dc8546d35c382a6f456_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1707084067&Signature=WcgSQU%2BALxfJwiKisWIi5MXWnpHKYcRUqjUtnikULwnB5IipfnmyuserevOZ8CTS%2FRDUR9Y2OgiYzb5HsCV1FU9qbGo%2FmhPphHKqL2CAFaCI8GnVHeiz1UpDXFlB%2Bh6FI%2B%2B3YCb%2BXr9Fw%2B1VpCuuJFXtUmrD8Cb9GsGde%2FgwMQX1IPZiBzegDN1hc%2BgsLkYioMDi%2Bsh%2BbDdvVWiMYlY2Z4uR%2B7vUBXdIt%2F%2FUfmof",
        "https://app.any.run/tasks/6c030f14-638b-4d1f-857b-1c6dfbf71190",
        "https://www.virustotal.com/gui/url/63f0e653821a47158d69fac1ede971842368af7c5e903e46caac3e83edc371c9/details",
        "hasownproperty.call \u2022 fireeye.grhd.",
        "https://www.google-analytics.com/gtm/optimize.js?id=GTM-PHVK7LN",
        "https://bilety.polregio.pl",
        "https://otx.alienvault.com/indicator/file/08515dcc6df957c9c5d4f00db4f568b3ee29c337",
        "https://subscribe.free.fr/assets/js/vendor/modernizr.custom.js",
        "https://otx.alienvault.com/indicator/file/b197cf4cee44d52be11275f49f3143b4f7f8e735",
        "https://www.hybrid-analysis.com/file-collection/65bfeeb7a6c0ce4494026e35",
        "https://subscribe.free.fr/assets/js/vendor/jquery-1.9.1.min.js",
        "https://www.heficed.com/wp/wp-includes/js/jquery/jquery.min.js",
        "https://subscribe.free.fr/assets/js/plugins.min.js",
        "https://subscribe.free.fr/assets/js/vendor/wow.min.js",
        "https://www.heficed.com/wp/wp-includes/js/dist/vendor/regenerator-runtime.min.js",
        "https://bat.bing.com/bat.js",
        "https://tria.ge/230806-j8tk9ahg7t",
        "https://vtbehaviour.commondatastorage.googleapis.com/7e93f94ac2d263e17519c9bcbbd014b1aa6c6d81b4198120760fd53258402b16_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1707084255&Signature=glGGS%2BaG%2F8HnZlkeCZuOYgD6ayeYlEXnI46%2Bq3clKoDEaPGwAGqidiQQcqoZj%2FpwwlN3oSKAEwaDhGgS2yn35nrU1MdX0MMQE3IUu6UVkUqbU1FDYuHRRlPnp27iNpMugshqeygkHkOMeCXli0WrqWtW7sIBLQRj6sfmfujKlheok7RwQspu%2Ft1SytFOmMCfM7YqAFADTj7WU9JjCvgzjJA9MFHcZ4IViuJHI5y5gJuUa5a%2F7N",
        "http://hybrid-analysis.com/sample/4dbe669e9b8b9cfe1bfa98019ccf2e56230ed136adce966649ee38e61e934303",
        "https://sdk.privacy-center.org/ui-gdpr-en.a96c69ed0cb8f37a2deea6c49dd453517875ac60.js",
        "https://www.heficed.com/wp/wp-includes/js/jquery/jquery-migrate.min.js",
        "https://sc.lfeeder.com/lftracker_v1_lYNOR8xM56G7WQJZ.js",
        "Trump Support campaign \u2022_\u2022 lantana-mgmt.washington.palantircloud.com \u2022 containers-reishi.palantirfedstart.com",
        "https://subscribe.free.fr/assets/css/accesgratuit.min.css",
        "https://js.driftt.com/core/chat?region=US&driftEnableLog=false&pageLoadStartTime=1650943817154",
        "https://js.driftt.com/include/1650944100000/2y43hyefanc8.js",
        "https://www.virustotal.com/gui/file/3db36d262eb15c349b4b945e0b1d9772c262cd2b7d57c40ede429958daeab97e?nocache=1",
        "https://tria.ge/230809-vtdr2afd2t",
        "https://any.run/report/3ba4834f3aa66174954319b1c1b8c708d3a169c0e4bcf9b1c7767c252abc78c9/6c030f14-638b-4d1f-857b-1c6dfbf71190?_gl=1*zsj01h*_gcl_au*MTA5NTQzMjU3Ni4xNzA3MDcyMTY3*_ga*NjUwNDYyMTM1LjE3MDcwNzIxNjg.*_ga_53KB74YDZR*MTcwNzA3MjE2NC4xLjEuMTcwNzA3OTI3OS4wLjAuMA..",
        "https://hybrid-analysis.com/sample/3782c093f4a54060ab6a269e2cc5a0334352f4c210500d370f185b6799f0007a/62e280899822900706678798",
        "https://otx.alienvault.com/indicator/file/1831d8972bfae639576d10903c2d586e",
        "https://h.clarity.ms/s/0.6.34/clarity.js",
        "https://subscribe.free.fr/assets/css/app2.min.css",
        "https://cdn.abrankings.com/js/client.js",
        "https://webmail.free.fr/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "unkown - Chinese speaking",
            "Unknown - Most likely multiple spanning Cyrillic and Chinese in terms of artifacts"
          ],
          "malware_families": [
            "Hacktool:win32/mimikatz.f",
            "Worm:win32/sfone.a",
            "Alf:ransom:win32/babax.sg!mtb",
            "Alf:jasyp:trojan:win32/ircbot!atmn",
            "Hj",
            "Slf:win32/dozlodz.a!mtb",
            "Backdoor:win32/zegost.km!mtb",
            "Win.malware.qshell-9875653-0",
            "Trojanproxy:win32/malynfits",
            "Backdoor:win32/zegost.bk",
            "#lowfi:suspicioussectionname",
            "Trojandropper:win32/venik",
            "Backdoor:win32/zegost.cg",
            "Win.malware.eclz-9953021-0",
            "Agenttesla",
            "Unknown",
            "Tel:trojan:msil/agenttesla.vpa!mtb",
            "Backdoor:win32/farfli.ax",
            "Pws:win32/vb.cu",
            "Trojandropper:win32/muldrop.v!mtb",
            "Advancedinstaller",
            "Backdoor:win32/zegost.cq!bit",
            "Neshta",
            "Backdoor:win32/zegost.ad",
            "Virus:dos/hellspawn",
            "Backdoor:win32/zegost.l",
            "Expiro",
            "Win.dropper.gh0strat-7696262-0",
            "Backdoor:win32/zegost!atmn",
            "Backdoor:win32/zegost.h!dll",
            "Hacker87",
            "Trojanspy:win32/nivdort",
            "Backdoor:msil/remcos",
            "Gh0stcringe",
            "Backdoor:win32/zegost.gen!b",
            "Virus:win32/lywer",
            "Reduceright",
            "Alf:trojan:win32/cipduk.d!dha",
            "Purplefox",
            "Backdoor:win32/zegost.br",
            "Trojan:win32/ghostratcrypt.ga!mtb",
            "Backdoor:win32/zegost.bu",
            "Alf:heraklezeval:worm:win32/sfone",
            "Backdoor:msil/zegost.gg!mtb",
            "Win64:xpirat\\ [inf]",
            "Pcrat",
            "Win.malware.snojan-6775202-0",
            "Trojandownloader:win32/zegost.e!bit",
            "Trojan:win32/farfli.dsk!mtb",
            "Zeppelin_10",
            "Vd",
            "Win.dropper.gh0strat",
            "Win.trojan.dialer-266",
            "Win32:farfli-bh",
            "#lowfi:vbexpensiveloop",
            "Worm:win32/lightmoon.h",
            "Trojandownloader:win32/nemucod"
          ],
          "industries": [
            "Individuals"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 11,
  "pulses": [
    {
      "id": "68c954a80675ccc89b0e9b63",
      "name": "Trump #45470 | Palantir container | virus:DOS/Hellspawn + ioS (compromised)",
      "description": "Overt. Trump support campaign text message from #45470. Malicious. Received on a victims hyper compromised iPhone. Attempts to or did take CnC of device. Stutters device, changed App Store , has delete service, device sweep,  shuts down service , halts all pages, denial of service, throttles service, steals\npasswords,  bots , I don\u2019t know if device can be refurbished or research purposes - Palantir DC DGA domains - Trump. Multiple IoC\u2019s , malware with code overlap, it appears to be from a legitimate text for updates #. Visibly affected all aspects of device and software. Commands device shut down. \n[OTX populated: Failed to retrieve suggested indicator for beta-ui, according to the latest results from the Welsh Government's Office for National Statistics (ONS) and the National Data Centre (NDS))",
      "modified": "2025-10-16T12:03:14.279000",
      "created": "2025-09-16T12:14:32.327000",
      "tags": [
        "ttl value",
        "extraction",
        "data upload",
        "failed",
        "extra data",
        "include review",
        "exclude sugges",
        "stop",
        "line",
        "path",
        "polyline",
        "getprocaddress",
        "circle",
        "span",
        "ck id",
        "mitre att",
        "ck matrix",
        "null",
        "error",
        "open",
        "spinner",
        "title",
        "code",
        "iframe",
        "window",
        "void",
        "infinity",
        "crypto",
        "footer",
        "generator",
        "general",
        "format",
        "click",
        "strings",
        "meta",
        "install",
        "encoder",
        "learn",
        "command",
        "name tactics",
        "suspicious",
        "informative",
        "spawns",
        "evasion att",
        "t1480 execution",
        "file defense",
        "adversaries",
        "calls",
        "reads",
        "defense evasion",
        "model",
        "server",
        "registrar abuse",
        "ascio",
        "contact phone",
        "admin city",
        "admin country",
        "admin postal",
        "dnssec",
        "http",
        "ip address",
        "passive dns",
        "related nids",
        "urls",
        "files location",
        "united",
        "flag united",
        "a domains",
        "search",
        "unknown aaaa",
        "certificate",
        "yara detections",
        "av detections",
        "ids detections",
        "alerts",
        "entries elf",
        "filehash",
        "name servers",
        "servers",
        "moved",
        "script script",
        "aaaa",
        "unknown ns",
        "domain add",
        "formbook cnc",
        "checkin",
        "lowfi",
        "mtb jun",
        "github pages",
        "twitter",
        "accept",
        "cryptobit",
        "extra",
        "referen data",
        "trojanproxy",
        "dynamicloader",
        "high",
        "write c",
        "medium",
        "intel",
        "ms windows",
        "entries",
        "pe32",
        "explorer",
        "worm",
        "write",
        "next",
        "trojan",
        "hellspawn",
        "md5 add",
        "malware",
        "data",
        "included iocs",
        "script urls",
        "script domains",
        "gmt content",
        "cash amtincart",
        "expirestue",
        "domain related",
        "sea x",
        "accept encoding",
        "request id",
        "body doctype",
        "apache",
        "encrypt",
        "skynet",
        "third eye tv",
        "calling",
        "delete app",
        "potus",
        "mtb aug",
        "backdoor",
        "gmt cache",
        "sameorigin",
        "443 ma2592000",
        "ipv4 add",
        "utilads",
        "trojandropper",
        "mtb sep",
        "win32upatre aug",
        "yara rule",
        "as15169",
        "guard",
        "smartassembly",
        "associated urls",
        "date checked",
        "url hostname",
        "server response",
        "domain",
        "url analysis",
        "files",
        "date",
        "delete service",
        "45470",
        "text",
        "hybrid",
        "present sep",
        "body",
        "fastly error",
        "please",
        "xor xor",
        "sha256 add",
        "analysis date",
        "file score",
        "detections alf",
        "june",
        "delphi",
        "attempts",
        "yara",
        "high security",
        "file type",
        "pe packer",
        "ransom"
      ],
      "references": [
        "skynet-dev.tcxn.net tcxn.net Registrar Ascio Technologies, Inc - connection to cloud proxy",
        "TrojanProxy:Win32/Malynfits CodeOverlap TrojanSpy:Win32/Nivdort CodeOverlap virus:Win32/Lywer CodeOverlap",
        "https://cryptobit.live/build/assets/app-CkRYqsKL.js \u2022 cryptobit.live \u2022 t.page \u2022 cdn.wallets.cryptobit.live",
        "Trump Support campaign \u2022_\u2022 lantana-mgmt.washington.palantircloud.com \u2022 containers-reishi.palantirfedstart.com",
        "Virus:DOS/Hellspawn 192.168.122.49 10/16/25\t\u2022  IPv4 142.251.9.105",
        "IDS Detections: Win32/Enosch.A gtalk connectivity check | W32/MoonLight.worm User-Agent (HellSpawn)",
        "PWS:Win32/Ymacco.AA50 Win.Trojan.Generic-9959068-0\t SLF:MSIL/PSTAnomaly.A Win.Dropper.Shakblades-7614016-0\t#LowFI:VBExpensiveLoop Win.Packed.Barys-10031677-0\tTEL:Trojan:MSIL/AgentTesla.VPA!MTB Win.Trojan. Backdoor:MSIL/Remcos!MTB",
        "hasownproperty.call \u2022 fireeye.grhd.",
        "Apple Store verified drop down breach  \u2018Apple took a screenshot of pages\u201d"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "TrojanSpy:Win32/Nivdort",
          "display_name": "TrojanSpy:Win32/Nivdort",
          "target": "/malware/TrojanSpy:Win32/Nivdort"
        },
        {
          "id": "TrojanProxy:Win32/Malynfits",
          "display_name": "TrojanProxy:Win32/Malynfits",
          "target": "/malware/TrojanProxy:Win32/Malynfits"
        },
        {
          "id": "Virus:Win32/Lywer",
          "display_name": "Virus:Win32/Lywer",
          "target": "/malware/Virus:Win32/Lywer"
        },
        {
          "id": "Worm:Win32/Lightmoon.H",
          "display_name": "Worm:Win32/Lightmoon.H",
          "target": "/malware/Worm:Win32/Lightmoon.H"
        },
        {
          "id": "Virus:DOS/Hellspawn",
          "display_name": "Virus:DOS/Hellspawn",
          "target": "/malware/Virus:DOS/Hellspawn"
        },
        {
          "id": "Win.Trojan.Dialer-266",
          "display_name": "Win.Trojan.Dialer-266",
          "target": null
        },
        {
          "id": "AgentTesla",
          "display_name": "AgentTesla",
          "target": null
        },
        {
          "id": "Backdoor:MSIL/Remcos",
          "display_name": "Backdoor:MSIL/Remcos",
          "target": "/malware/Backdoor:MSIL/Remcos"
        },
        {
          "id": "ALF:JASYP:Trojan:Win32/IRCbot!atmn",
          "display_name": "ALF:JASYP:Trojan:Win32/IRCbot!atmn",
          "target": null
        },
        {
          "id": "Trojandropper:Win32/Muldrop.V!MTB",
          "display_name": "Trojandropper:Win32/Muldrop.V!MTB",
          "target": "/malware/Trojandropper:Win32/Muldrop.V!MTB"
        },
        {
          "id": "#LowFI:VBExpensiveLoop",
          "display_name": "#LowFI:VBExpensiveLoop",
          "target": null
        },
        {
          "id": "TEL:Trojan:MSIL/AgentTesla.VPA!MTB",
          "display_name": "TEL:Trojan:MSIL/AgentTesla.VPA!MTB",
          "target": null
        },
        {
          "id": "PWS:Win32/VB.CU",
          "display_name": "PWS:Win32/VB.CU",
          "target": "/malware/PWS:Win32/VB.CU"
        },
        {
          "id": "ALF:Ransom:Win32/Babax.SG!MTB",
          "display_name": "ALF:Ransom:Win32/Babax.SG!MTB",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1489",
          "name": "Service Stop",
          "display_name": "T1489 - Service Stop"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 690,
        "URL": 1479,
        "domain": 476,
        "FileHash-MD5": 526,
        "FileHash-SHA1": 505,
        "FileHash-SHA256": 1509,
        "email": 6
      },
      "indicator_count": 5191,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "227 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6844240c68255798e08beb3b",
      "name": "Bilety online: Tw\u00f3j kolejowy partner w podr\u00f3\u017cy",
      "description": "Microsoft has created a new version of its XMLHttpRequest, which allows users to access a website, via a browser or browser without the permission of a third party, using the same address.",
      "modified": "2025-07-07T00:01:51.704000",
      "created": "2025-06-07T11:35:40.942000",
      "tags": [
        "sign",
        "google sign",
        "forgot email",
        "criminalip",
        "create account",
        "bilety online",
        "sprzeday biletw",
        "polregio",
        "ssdeep",
        "license",
        "typeerror",
        "regexp",
        "promise",
        "function",
        "version",
        "typeof symbol",
        "copyright",
        "google llc",
        "apache license",
        "date",
        "without",
        "error",
        "blank",
        "trident",
        "generator",
        "class",
        "mountain view",
        "android",
        "submission",
        "california",
        "common name",
        "google inc",
        "unit android",
        "country code",
        "us state",
        "sha1",
        "sha256",
        "imphash",
        "pehash",
        "file type",
        "vhash",
        "authentihash"
      ],
      "references": [
        "http://bilety.polregio.pl",
        "https://bilety.polregio.pl",
        "http://www.salesmanago.pl/static/sm.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1295,
        "hostname": 302,
        "domain": 137,
        "FileHash-SHA256": 996,
        "FileHash-MD5": 38,
        "FileHash-SHA1": 40,
        "IPv4": 1
      },
      "indicator_count": 2809,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 123,
      "modified_text": "329 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "675127405277d037355e5db6",
      "name": "Beehive.Systems",
      "description": "#if PRAGMA_ONCE, which includes the word \"pagma\" and the term \"penet\", should not be used as part of any attempt to set a new code.",
      "modified": "2024-12-05T04:08:32.154000",
      "created": "2024-12-05T04:08:32.154000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "ilyailya",
        "id": "298851",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 16,
        "domain": 30,
        "hostname": 69
      },
      "indicator_count": 115,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 31,
      "modified_text": "543 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65c0029e4e6d6bbe7b036051",
      "name": "https://github.com/imaya/zlib.js & https://github.com/kanaka/noVNC/blob/master/include/input.js",
      "description": "I found these two gems inadvertently while analyzing files that had been written too by whatever the hell this is and came across these urls as strings. plugging the urls directly into VT, or OTX proved fruitless so I just cloned the repo directly and what it provided was completely different that what it provided the analysis engines. More than half of the files are completely clean everywhere, but show up as a threat score of 9 or above here on OTX. half of those, were submitted to OTX 4 years ago - VT one year ago. It's a .NET based something and still frankly way over my paygrade.",
      "modified": "2024-03-05T22:00:26.685000",
      "created": "2024-02-04T21:33:18.106000",
      "tags": [
        "environemnt aware",
        "zlib",
        "js",
        "debug aware",
        "obfuscated",
        "long sleeps",
        "node",
        "github",
        ".NET",
        "CCP",
        "sneaky",
        "reactive",
        "APT"
      ],
      "references": [
        "",
        "https://www.virustotal.com/gui/file/7e93f94ac2d263e17519c9bcbbd014b1aa6c6d81b4198120760fd53258402b16/behavior",
        "https://any.run/report/3ba4834f3aa66174954319b1c1b8c708d3a169c0e4bcf9b1c7767c252abc78c9/6c030f14-638b-4d1f-857b-1c6dfbf71190?_gl=1*r6j8c3*_gcl_au*MTA5NTQzMjU3Ni4xNzA3MDcyMTY3*_ga*NjUwNDYyMTM1LjE3MDcwNzIxNjg.*_ga_53KB74YDZR*MTcwNzA3MjE2NC4xLjEuMTcwNzA3NzMzMy4wLjAuMA..#Static%20information",
        "https://www.virustotal.com/gui/url/45e7587df7e63542283047682750057788692266da7bf92f44f384a095887bd6",
        "https://www.virustotal.com/gui/file/420be75183f496e85363aed933631faaf491917d63c18d592fadbd5d55df0063/behavior",
        "https://any.run/report/3ba4834f3aa66174954319b1c1b8c708d3a169c0e4bcf9b1c7767c252abc78c9/6c030f14-638b-4d1f-857b-1c6dfbf71190?_gl=1*zsj01h*_gcl_au*MTA5NTQzMjU3Ni4xNzA3MDcyMTY3*_ga*NjUwNDYyMTM1LjE3MDcwNzIxNjg.*_ga_53KB74YDZR*MTcwNzA3MjE2NC4xLjEuMTcwNzA3OTI3OS4wLjAuMA..",
        "https://vtbehaviour.commondatastorage.googleapis.com/5346535cf86a93ab91f8510f0756a10034c4bd2d79f76dc8546d35c382a6f456_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1707084067&Signature=WcgSQU%2BALxfJwiKisWIi5MXWnpHKYcRUqjUtnikULwnB5IipfnmyuserevOZ8CTS%2FRDUR9Y2OgiYzb5HsCV1FU9qbGo%2FmhPphHKqL2CAFaCI8GnVHeiz1UpDXFlB%2Bh6FI%2B%2B3YCb%2BXr9Fw%2B1VpCuuJFXtUmrD8Cb9GsGde%2FgwMQX1IPZiBzegDN1hc%2BgsLkYioMDi%2Bsh%2BbDdvVWiMYlY2Z4uR%2B7vUBXdIt%2F%2FUfmof",
        "https://www.virustotal.com/gui/file/67e7028926a58f732336b592945c72af641afb6d9b835d1e463105cfdbd1a77a/details",
        "https://app.any.run/tasks/6c030f14-638b-4d1f-857b-1c6dfbf71190",
        "https://www.virustotal.com/gui/file/45f02b64f1a4396157412cdd25fb17273bae550dfd29c33de8d0bbd6260bbc66/behavior",
        "https://www.hybrid-analysis.com/file-collection/65bfeeb7a6c0ce4494026e35",
        "https://www.virustotal.com/gui/file/5346535cf86a93ab91f8510f0756a10034c4bd2d79f76dc8546d35c382a6f456/behavior",
        "https://www.virustotal.com/gui/url/63f0e653821a47158d69fac1ede971842368af7c5e903e46caac3e83edc371c9/details",
        "https://vtbehaviour.commondatastorage.googleapis.com/7e93f94ac2d263e17519c9bcbbd014b1aa6c6d81b4198120760fd53258402b16_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1707084255&Signature=glGGS%2BaG%2F8HnZlkeCZuOYgD6ayeYlEXnI46%2Bq3clKoDEaPGwAGqidiQQcqoZj%2FpwwlN3oSKAEwaDhGgS2yn35nrU1MdX0MMQE3IUu6UVkUqbU1FDYuHRRlPnp27iNpMugshqeygkHkOMeCXli0WrqWtW7sIBLQRj6sfmfujKlheok7RwQspu%2Ft1SytFOmMCfM7YqAFADTj7WU9JjCvgzjJA9MFHcZ4IViuJHI5y5gJuUa5a%2F7N",
        "https://otx.alienvault.com/indicator/url/https://github.com/kanaka/noVNC/blob/master/include/input.js",
        "https://vtbehaviour.commondatastorage.googleapis.com/7e93f94ac2d263e17519c9bcbbd014b1aa6c6d81b4198120760fd53258402b16_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1707084256&Signature=dYoVJj0iMC1%2BgtnhdiQHT4HWnqp0%2FLpvOhpzPsb3j3iskv25mbsb3oocaeeWs8rF1Vl5bTV%2B4FAIcSsp69SD3g7SYAwExGZPknXuS%2FucApcHr08O73qt9NGsN3k%2B94DDXzQ00nP8JAcEmnAjiGeIjNOi9mUDDn9rHv29PXSaHF8g0EFjGw5pCdtMudmOgRxd9nK7NnLMvVgV0UX5r5TQpvvrkJ%2B7vEyKePd%2FvoIGA%2Bxgmp9ccfvd%2"
      ],
      "public": 1,
      "adversary": "unkown - Chinese speaking",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Unknown",
          "display_name": "Unknown",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1087",
          "name": "Account Discovery",
          "display_name": "T1087 - Account Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1133",
          "name": "External Remote Services",
          "display_name": "T1133 - External Remote Services"
        }
      ],
      "industries": [
        "individuals"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Merkd1904",
        "id": "196517",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 22,
        "hostname": 40,
        "FileHash-SHA1": 5,
        "URL": 43,
        "FileHash-MD5": 2,
        "FileHash-SHA256": 2
      },
      "indicator_count": 114,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 73,
      "modified_text": "817 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "64da05cdba55fc9cf872cb11",
      "name": "IOC's off of my personal devices Aug 14th - June 28th | Come one come all, something for everyone",
      "description": "Now that I've been able to get a pulse published I'm going to be recursively and actively updating this pulse with IOC's pulled off of files marked malicious, suspicious, ambigious, or clean with a threat score from my personal devices. I will also add files that have a high amount of indicators and no threat score as well and let AlienVault sort it out. Hopefully I'll be able i'll be able to fill the gap to my last Pulse the better part of a year ago. \n\nNearly all of these files are debug and VM aware, with a majority having a legitimate certificate chain. The ones that do run have been initialized in a live environment (aka my desktop, laptop, phone, etc).",
      "modified": "2024-02-14T21:44:01.779000",
      "created": "2023-08-14T10:45:33.014000",
      "tags": [
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "falcon sandbox",
        "hybrid analysis",
        "sandbox files",
        "urls quick",
        "scans files",
        "urls file",
        "releases",
        "updates faq",
        "public api",
        "knowledge base"
      ],
      "references": [
        "https://otx.alienvault.com/indicator/file/b197cf4cee44d52be11275f49f3143b4f7f8e735",
        "https://hybrid-analysis.com/sample/4dbe669e9b8b9cfe1bfa98019ccf2e56230ed136adce966649ee38e61e934303/64da0aedbe662a714b0480b1",
        "https://www.virustotal.com/gui/file/207bfec939e7c017c4704ba76172ee2c954f485ba593bc1bc8c7666e78251861/behavior",
        "https://www.virustotal.com/gui/file/3db36d262eb15c349b4b945e0b1d9772c262cd2b7d57c40ede429958daeab97e?nocache=1",
        "https://otx.alienvault.com/indicator/file/08515dcc6df957c9c5d4f00db4f568b3ee29c337",
        "https://www.joesandbox.com/analysis/1041402",
        "http://hybrid-analysis.com/sample/e9fc2ca7297a65937de9887be565eb5bbd149ba2c1a1ea4d3ca88302ede7ecac",
        "https://www.virustotal.com/gui/file/a7b4797c4a29864aacb7b40dd854adaf3936791d7c326d02d4aad37982d801a9/community",
        "http://hybrid-analysis.com/sample/e4db1656c4cfff0a4ced5a943b8433388c7b4935711d522014c819328f19001d/64da070d00534407c40c1034",
        "http://hybrid-analysis.com/sample/4dbe669e9b8b9cfe1bfa98019ccf2e56230ed136adce966649ee38e61e934303",
        "http://hybrid-analysis.com/sample/4cf079d4d7a154cd93f65934b5d115f07af8f25ee24930e6cc606dfb0aea2a4e",
        "https://otx.alienvault.com/indicator/file/1831d8972bfae639576d10903c2d586e",
        "https://hybrid-analysis.com/sample/beff391ce640cc8fdfcec22b77c5d2bc4776304e3a404e8168ce315226c4fc41/5eae8f731389173b4c432b17",
        "https://otx.alienvault.com/indicator/file/c85cc6f8ff7d69d7a7af9498d7d75bc05e35fb69f34d7b50d9057608f7b73f51",
        "",
        "https://tria.ge/230806-j3tdasgd72",
        "https://tria.ge/230806-j8mspsgd84",
        "https://tria.ge/230806-j8tk9ahg7t",
        "https://tria.ge/230809-vsggjadf59",
        "https://tria.ge/230809-vtdr2afd2t"
      ],
      "public": 1,
      "adversary": "Unknown - Most likely multiple spanning Cyrillic and Chinese in terms of artifacts",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "neshta",
          "display_name": "neshta",
          "target": null
        },
        {
          "id": "Expiro",
          "display_name": "Expiro",
          "target": null
        },
        {
          "id": "Win.Dropper.Gh0stRAT",
          "display_name": "Win.Dropper.Gh0stRAT",
          "target": null
        },
        {
          "id": "Win.Malware.Eclz-9953021-0",
          "display_name": "Win.Malware.Eclz-9953021-0",
          "target": null
        },
        {
          "id": "Win32:Farfli-BH",
          "display_name": "Win32:Farfli-BH",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Nemucod",
          "display_name": "TrojanDownloader:Win32/Nemucod",
          "target": "/malware/TrojanDownloader:Win32/Nemucod"
        },
        {
          "id": "Win.Malware.Snojan-6775202-0",
          "display_name": "Win.Malware.Snojan-6775202-0",
          "target": null
        },
        {
          "id": "Win.Malware.Qshell-9875653-0",
          "display_name": "Win.Malware.Qshell-9875653-0",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Zegost.E!bit",
          "display_name": "TrojanDownloader:Win32/Zegost.E!bit",
          "target": "/malware/TrojanDownloader:Win32/Zegost.E!bit"
        },
        {
          "id": "Backdoor:Win32/Zegost.CQ!bit",
          "display_name": "Backdoor:Win32/Zegost.CQ!bit",
          "target": "/malware/Backdoor:Win32/Zegost.CQ!bit"
        },
        {
          "id": "#Lowfi:SuspiciousSectionName",
          "display_name": "#Lowfi:SuspiciousSectionName",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Zegost.gen!B",
          "display_name": "Backdoor:Win32/Zegost.gen!B",
          "target": "/malware/Backdoor:Win32/Zegost.gen!B"
        },
        {
          "id": "Win.Dropper.Gh0stRAT-7696262-0",
          "display_name": "Win.Dropper.Gh0stRAT-7696262-0",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Zegost.BU",
          "display_name": "Backdoor:Win32/Zegost.BU",
          "target": "/malware/Backdoor:Win32/Zegost.BU"
        },
        {
          "id": "Trojan:Win32/Farfli.DSK!MTB",
          "display_name": "Trojan:Win32/Farfli.DSK!MTB",
          "target": "/malware/Trojan:Win32/Farfli.DSK!MTB"
        },
        {
          "id": "Backdoor:Win32/Zegost.BK",
          "display_name": "Backdoor:Win32/Zegost.BK",
          "target": "/malware/Backdoor:Win32/Zegost.BK"
        },
        {
          "id": "HackTool:Win32/Mimikatz.F",
          "display_name": "HackTool:Win32/Mimikatz.F",
          "target": "/malware/HackTool:Win32/Mimikatz.F"
        },
        {
          "id": "Trojan:Win32/GhostRatCrypt.GA!MTB",
          "display_name": "Trojan:Win32/GhostRatCrypt.GA!MTB",
          "target": "/malware/Trojan:Win32/GhostRatCrypt.GA!MTB"
        },
        {
          "id": "Backdoor:Win32/Zegost.CG",
          "display_name": "Backdoor:Win32/Zegost.CG",
          "target": "/malware/Backdoor:Win32/Zegost.CG"
        },
        {
          "id": "Backdoor:Win32/Zegost.AD",
          "display_name": "Backdoor:Win32/Zegost.AD",
          "target": "/malware/Backdoor:Win32/Zegost.AD"
        },
        {
          "id": "Worm:Win32/Sfone.A",
          "display_name": "Worm:Win32/Sfone.A",
          "target": "/malware/Worm:Win32/Sfone.A"
        },
        {
          "id": "Backdoor:Win32/Zegost!atmn",
          "display_name": "Backdoor:Win32/Zegost!atmn",
          "target": "/malware/Backdoor:Win32/Zegost!atmn"
        },
        {
          "id": "Backdoor:Win32/Zegost.H!dll",
          "display_name": "Backdoor:Win32/Zegost.H!dll",
          "target": "/malware/Backdoor:Win32/Zegost.H!dll"
        },
        {
          "id": "Zeppelin_10",
          "display_name": "Zeppelin_10",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win32/Cipduk.D!dha",
          "display_name": "ALF:Trojan:Win32/Cipduk.D!dha",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Zegost.BR",
          "display_name": "Backdoor:Win32/Zegost.BR",
          "target": "/malware/Backdoor:Win32/Zegost.BR"
        },
        {
          "id": "Backdoor:Win32/Farfli.AX",
          "display_name": "Backdoor:Win32/Farfli.AX",
          "target": "/malware/Backdoor:Win32/Farfli.AX"
        },
        {
          "id": "ALF:HeraklezEval:Worm:Win32/Sfone",
          "display_name": "ALF:HeraklezEval:Worm:Win32/Sfone",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Zegost.L",
          "display_name": "Backdoor:Win32/Zegost.L",
          "target": "/malware/Backdoor:Win32/Zegost.L"
        },
        {
          "id": "Backdoor:MSIL/Zegost.GG!MTB",
          "display_name": "Backdoor:MSIL/Zegost.GG!MTB",
          "target": "/malware/Backdoor:MSIL/Zegost.GG!MTB"
        },
        {
          "id": "SLF:Win32/Dozlodz.A!MTB",
          "display_name": "SLF:Win32/Dozlodz.A!MTB",
          "target": "/malware/SLF:Win32/Dozlodz.A!MTB"
        },
        {
          "id": "Win64:Xpirat\\ [Inf]",
          "display_name": "Win64:Xpirat\\ [Inf]",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Zegost.KM!MTB",
          "display_name": "Backdoor:Win32/Zegost.KM!MTB",
          "target": "/malware/Backdoor:Win32/Zegost.KM!MTB"
        },
        {
          "id": "AdvancedInstaller",
          "display_name": "AdvancedInstaller",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/Venik",
          "display_name": "TrojanDropper:Win32/Venik",
          "target": "/malware/TrojanDropper:Win32/Venik"
        },
        {
          "id": "hacker87",
          "display_name": "hacker87",
          "target": null
        },
        {
          "id": "PurpleFox",
          "display_name": "PurpleFox",
          "target": null
        },
        {
          "id": "PCRat",
          "display_name": "PCRat",
          "target": null
        },
        {
          "id": "Gh0stCringe",
          "display_name": "Gh0stCringe",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "individuals"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Merkd1904",
        "id": "196517",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2387,
        "FileHash-SHA1": 2126,
        "FileHash-SHA256": 9395,
        "SSLCertFingerprint": 27,
        "domain": 88,
        "URL": 185,
        "hostname": 165,
        "email": 11
      },
      "indicator_count": 14384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 82,
      "modified_text": "837 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708c8f50527fb73205bfca",
      "name": "Dreamhost.com - Drift Widget",
      "description": "",
      "modified": "2023-12-06T15:00:31.809000",
      "created": "2023-12-06T15:00:31.809000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 174,
        "domain": 464,
        "URL": 1119,
        "hostname": 156,
        "FileHash-MD5": 2,
        "FileHash-SHA1": 1
      },
      "indicator_count": 1916,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62e80d56fba248bac0744780",
      "name": "\ud83e\udd14\ud83d\udea8 Could this be the source of all Evil? \ud83d\udea8\ud83e\udd14 Nubotnet - Team:KU Leuven/test2 - 2021.igem.org",
      "description": "",
      "modified": "2022-08-31T00:01:05.509000",
      "created": "2022-08-01T17:28:54.991000",
      "tags": [
        "apt",
        "runtime data",
        "decrypted ssl",
        "pcap",
        "windows nt",
        "tops",
        "cookie",
        "typeof t",
        "element",
        "error",
        "matrix",
        "typeerror",
        "bmfloor",
        "frameelement",
        "null",
        "skew",
        "parade"
      ],
      "references": [
        "https://2021.igem.org/Team:KU_Leuven/test2",
        "https://hybrid-analysis.com/sample/e126ff94aac3340dc05a27f062c4267cbfeaa998248bef0e72f000bba711aa76/62e6fb475edc950b894aa7b0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1696,
        "domain": 586,
        "hostname": 613,
        "FileHash-SHA256": 533,
        "FileHash-MD5": 34,
        "FileHash-SHA1": 33,
        "email": 1
      },
      "indicator_count": 3496,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 394,
      "modified_text": "1370 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62e69610305a20de80232e50",
      "name": ";http://tdarr.io/ - yet more net.sh",
      "description": "",
      "modified": "2022-08-30T00:01:48.297000",
      "created": "2022-07-31T14:47:44.291000",
      "tags": [
        "trojan",
        "apt",
        "runtime data",
        "decrypted ssl",
        "typeerror",
        "typeof symbol",
        "null",
        "accept",
        "unknown",
        "roboto",
        "generator",
        "matrix",
        "internal",
        "blank",
        "trident",
        "discord",
        "facebook",
        "twitch",
        "backend",
        "twitter",
        "suser",
        "android",
        "meta",
        "skew",
        "parade",
        "click",
        "malicious",
        "mozilla",
        "suspicious",
        "network traffic",
        "net.sh"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/3782c093f4a54060ab6a269e2cc5a0334352f4c210500d370f185b6799f0007a/62e280899822900706678798",
        "tdarr.io",
        "net.sh neural netw"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 786,
        "hostname": 498,
        "FileHash-SHA256": 122,
        "domain": 139,
        "FileHash-MD5": 43,
        "FileHash-SHA1": 36
      },
      "indicator_count": 1624,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 393,
      "modified_text": "1371 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62676c65b80720b582b46037",
      "name": "Dreamhost.com - Drift Widget",
      "description": "function.1, a new version of JavaScript, has been added to the end of the year to make it easier for users to keep up with the latest developments in the search for a specific date.",
      "modified": "2022-05-25T00:04:03.622000",
      "created": "2022-04-26T03:52:05.599000",
      "tags": [
        "template7class",
        "regexp",
        "root",
        "context",
        "match",
        "body",
        "template7",
        "error",
        "prop",
        "function",
        "date",
        "null",
        "slice",
        "void",
        "factory",
        "window",
        "find",
        "simple",
        "false",
        "hj",
        "object",
        "hotjar",
        "email",
        "typeof symbol",
        "typeof e",
        "telefon",
        "array",
        "survey",
        "meta",
        "cookie",
        "scroll",
        "keypress",
        "trident",
        "live",
        "fullscreen",
        "generic",
        "widget",
        "ciudad",
        "adore",
        "experiment",
        "mutation",
        "click",
        "pluginname",
        "hidden",
        "nttt",
        "fieldset",
        "class",
        "form",
        "fast",
        "jquery",
        "format",
        "february",
        "april",
        "june",
        "august",
        "nova",
        "paris",
        "tokyo",
        "easy",
        "speed",
        "back",
        "target",
        "copy",
        "kill",
        "this",
        "infinity",
        "accept",
        "locale",
        "custom build",
        "https",
        "boolean",
        "new boolean",
        "typeof",
        "typeerror",
        "bootstrap",
        "typeof t",
        "javascript",
        "show",
        "drift widget",
        "segoe ui",
        "emoji",
        "type",
        "copyright",
        "browse",
        "roboto",
        "helvetica neue",
        "arial",
        "noto",
        "apple color",
        "twitter",
        "typeof require",
        "modulenotfound",
        "font awesome",
        "typeof define",
        "script",
        "new date",
        "number",
        "trackevent",
        "string",
        "watched",
        "search",
        "clicked",
        "path",
        "starter",
        "download",
        "derek",
        "code",
        "esnull",
        "gtmphvk7ln",
        "closure library",
        "xdfunction",
        "reduceright",
        "vd",
        "g1f7wlmm0k2",
        "r420",
        "uint8array",
        "typeof d",
        "ieproto",
        "typeof n",
        "widgetrootqa",
        "driftconductor"
      ],
      "references": [
        "xfe-URL-Dreamhost.com-stix2-2.1-export.json",
        "https://js.driftt.com/include/1650944100000/2y43hyefanc8.js",
        "https://www.google-analytics.com/plugins/ua/linkid.js",
        "https://www.googletagmanager.com/gtag/js?id=G-1F7WLMM0K2&l=dataLayer&cx=c",
        "https://www.google-analytics.com/gtm/optimize.js?id=GTM-PHVK7LN",
        "https://www.googletagmanager.com/gtm.js?id=GTM-TLN654",
        "https://kit.fontawesome.com/7d998cc9b7.js",
        "https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js",
        "https://www.dreamhost.com/assets/bootstrap-aa47564acfdf18ce859b8e1fd130d889920ae66415b3db4de8505d42a0477b09.css",
        "https://js.driftt.com/core?embedId=2y43hyefanc8&region=US&forceShow=false&skipCampaigns=false&sessionId=5a8c1b8d-2626-4a43-a7a6-76e9416f2f52&sessionStarted=1650943819.009&campaignRefreshToken=a2d9846a-8932-4e3c-a8d5-878681a555e0&hideController=false&pageLoadStartTime=1650943817154&mode=CHAT&driftEnableLog=false",
        "https://js.driftt.com/core/chat?region=US&driftEnableLog=false&pageLoadStartTime=1650943817154",
        "https://vars.hotjar.com/box-4924254a9ce4dc9b959b6e4a9b662d60.html",
        "https://www.dreamhost.com/assets/scripts/bootstrap-7670fc8587f9fd0608d2af67f392281a9a4fbf4cb4252952ecb8d34f6ee286b3.js",
        "https://www.dreamhost.com/assets/scripts/webp-support-1dd791309dc3fa5b166a0a326e49345fe5acb5acbc1831f4c7be87efce1abf51.js",
        "https://www.dreamhost.com/assets/site-75a1aba399db4de4e4093997b8fc8ff8ec5e65b5f4258c9a658a5cacacbf6e0d.js",
        "https://script.hotjar.com/modules.0076bf93c385ddf0ff58.js",
        "https://cdn.abrankings.com/js/client.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "hj",
          "display_name": "hj",
          "target": null
        },
        {
          "id": "Vd",
          "display_name": "Vd",
          "target": null
        },
        {
          "id": "ReduceRight",
          "display_name": "ReduceRight",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 174,
        "URL": 1119,
        "domain": 464,
        "hostname": 156,
        "FileHash-MD5": 2,
        "FileHash-SHA1": 1
      },
      "indicator_count": 1916,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1468 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62549aabb033e7afc5069f98",
      "name": "Malware - victim=fr",
      "description": "Mme, Mlle,   M. Compte, yn \u00f4l \u00c2\u00a31.5m (\u20ac2.4m; \u00e2\u201a\u00ac1m)",
      "modified": "2022-05-11T21:04:45.103000",
      "created": "2022-04-11T21:16:27.786000",
      "tags": [
        "freebox",
        "free",
        "mois pendant",
        "sabonner voir",
        "fibre free",
        "la fibre",
        "votre",
        "wifi",
        "freebox en",
        "offre",
        "delta",
        "face",
        "prix",
        "date",
        "this",
        "typeof e",
        "true",
        "function",
        "left",
        "bottom",
        "html",
        "nullt",
        "false",
        "next",
        "february",
        "april",
        "june",
        "august",
        "atom",
        "cookie",
        "close",
        "null",
        "back",
        "bounce",
        "kolab",
        "target",
        "object",
        "tcfuiservice",
        "reflect",
        "typeof proxy",
        "boolean",
        "agree",
        "disagree",
        "select",
        "save",
        "learn",
        "click",
        "gnu gpl",
        "copyright",
        "javascript code",
        "license",
        "extwin1",
        "framed1",
        "roundcube",
        "webmail client",
        "script",
        "team",
        "format",
        "regexp",
        "software",
        "error",
        "pseudo",
        "child",
        "the software",
        "sufeffxa0",
        "class",
        "attr",
        "javascript",
        "express",
        "nous",
        "didomi",
        "typeof t",
        "hmuvfyyh",
        "sekindo",
        "lkqd",
        "aol cdn",
        "ffffff",
        "montserrat",
        "adsl",
        "offres adsl",
        "internet",
        "t\u00e9l\u00e9phone",
        "t\u00e9l\u00e9phonie",
        "mobiles",
        "forfaits mobiles",
        "tv",
        "t\u00e9l\u00e9vision",
        "vod",
        "vid\u00e9o \u00e0 la demande",
        "multiposte",
        "radio",
        "routeur",
        "freeplayer",
        "multiplay",
        "d\u00e9groupage",
        "total",
        "partiel",
        "e-mail",
        "mail",
        "m\u00e9l",
        "fournisseur d'acc\u00e8s",
        "i.s.p.",
        "isp",
        "internaute",
        "internautes",
        "france",
        "fran\u00e7ais",
        "zimbra",
        "le webmail",
        "free fait",
        "webmail imp",
        "cela n",
        "webmail zimbra",
        "stockage",
        "pour migrer",
        "accder",
        "testteltext",
        "sans",
        "testziptext",
        "testziptext i",
        "testteltext i",
        "typenumber",
        "screenh",
        "tvbycanal",
        "tvbycanal147",
        "tvbycanal204",
        "tvbycanal83",
        "tvbycanal80",
        "tvbycanal34",
        "4000",
        "typeof console",
        "console",
        "nullc",
        "nulld",
        "customevent",
        "msanimationend",
        "typeof n",
        "typeof r",
        "x20trnf",
        "width",
        "accept",
        "json",
        "moz o",
        "custom build",
        "https",
        "xmlhttprequest",
        "typeof module",
        "webkit",
        "android",
        "flash",
        "span",
        "un espace",
        "phpmysql",
        "helvetica"
      ],
      "references": [
        "xfe-IP-212.27.63.109-stix2-2.1-export.json",
        "http://pageperso.free.fr/im/css/free.css",
        "http://passback.free.fr/pub/pp_300x250.html",
        "https://subscribe.free.fr/accesgratuit/index.html",
        "https://subscribe.free.fr/assets/js/vendor/modernizr.custom.js",
        "https://subscribe.free.fr/assets/js/vendor/jquery-1.9.1.min.js",
        "https://subscribe.free.fr/assets/js/plugins.min.js",
        "https://subscribe.free.fr/assets/js/vendor/wow.min.js",
        "https://subscribe.free.fr/assets/js/main.min.js",
        "https://subscribe.free.fr/assets/css/accesgratuit.min.css",
        "https://subscribe.free.fr/assets/css/app2.min.css",
        "https://webmail.free.fr/",
        "https://sdk.privacy-center.org/87df2f8d-232a-4617-8efc-3764b3bbd0c0/loader.js?target=webmail.free.fr",
        "https://webmail.free.fr/program/js/jquery.min.js?s=1510166541",
        "https://webmail.free.fr/program/js/app.min.js?s=1510166525",
        "https://sdk.privacy-center.org/ui-gdpr-en.a96c69ed0cb8f37a2deea6c49dd453517875ac60.js",
        "https://webmail.free.fr/plugins/jqueryui/js/jquery-ui.min.js?s=1510166524",
        "https://www.free.fr/freebox/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1078,
        "URL": 2104,
        "domain": 290,
        "FileHash-SHA256": 117,
        "FileHash-MD5": 4,
        "FileHash-SHA1": 2
      },
      "indicator_count": 3595,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1481 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "this.save",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "this.save",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780306947.3347516
}