{
  "type": "Domain",
  "indicator": "titanclaritty.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/titanclaritty.com",
    "alexa": "http://www.alexa.com/siteinfo/titanclaritty.com",
    "indicator": "titanclaritty.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4132430910,
      "indicator": "titanclaritty.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "69c69d20e0d39b6cb13bcf90",
          "name": "Titan Clarity phishing campaign",
          "description": "A phishing campaign involving multiple domains has been identified. All sender domains contain either \u201cTitan\u201d or \u201cClarity\u201d within the domain name. While subject lines vary, the majority relate to employment themes, including jobs, work opportunities, interviews, and callback requests.",
          "modified": "2026-05-07T08:08:39.060000",
          "created": "2026-03-27T15:07:12.263000",
          "tags": [
            "titan",
            "clarity",
            "phishing",
            "campaign",
            "malicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United Kingdom of Great Britain and Northern Ireland"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1192",
              "name": "Spearphishing Link",
              "display_name": "T1192 - Spearphishing Link"
            }
          ],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FS13JKMK",
            "id": "312129",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_312129/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 45,
            "FileHash-SHA256": 3,
            "hostname": 6,
            "URL": 10
          },
          "indicator_count": 64,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 73,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68cd84c51079287599bfd226",
          "name": "Phishing [190925]",
          "description": "Phishing domains and IP addresses that have been used to send malicious emails.",
          "modified": "2025-10-19T15:00:19.964000",
          "created": "2025-09-19T16:28:53.289000",
          "tags": [
            "phishing",
            "HMRC",
            "meta",
            "spearphishing",
            "facebook",
            "malicious-domain",
            "malicious-IP"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United Kingdom of Great Britain and Northern Ireland"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1192",
              "name": "Spearphishing Link",
              "display_name": "T1192 - Spearphishing Link"
            }
          ],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FS13JKMK",
            "id": "312129",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_312129/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 31,
            "hostname": 31,
            "email": 8,
            "FileHash-SHA256": 5,
            "URL": 35
          },
          "indicator_count": 110,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 73,
          "modified_text": "223 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [
            "Government"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "69c69d20e0d39b6cb13bcf90",
      "name": "Titan Clarity phishing campaign",
      "description": "A phishing campaign involving multiple domains has been identified. All sender domains contain either \u201cTitan\u201d or \u201cClarity\u201d within the domain name. While subject lines vary, the majority relate to employment themes, including jobs, work opportunities, interviews, and callback requests.",
      "modified": "2026-05-07T08:08:39.060000",
      "created": "2026-03-27T15:07:12.263000",
      "tags": [
        "titan",
        "clarity",
        "phishing",
        "campaign",
        "malicious"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United Kingdom of Great Britain and Northern Ireland"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1192",
          "name": "Spearphishing Link",
          "display_name": "T1192 - Spearphishing Link"
        }
      ],
      "industries": [
        "Government"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "FS13JKMK",
        "id": "312129",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_312129/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 45,
        "FileHash-SHA256": 3,
        "hostname": 6,
        "URL": 10
      },
      "indicator_count": 64,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 73,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68cd84c51079287599bfd226",
      "name": "Phishing [190925]",
      "description": "Phishing domains and IP addresses that have been used to send malicious emails.",
      "modified": "2025-10-19T15:00:19.964000",
      "created": "2025-09-19T16:28:53.289000",
      "tags": [
        "phishing",
        "HMRC",
        "meta",
        "spearphishing",
        "facebook",
        "malicious-domain",
        "malicious-IP"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United Kingdom of Great Britain and Northern Ireland"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1192",
          "name": "Spearphishing Link",
          "display_name": "T1192 - Spearphishing Link"
        }
      ],
      "industries": [
        "Government"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "FS13JKMK",
        "id": "312129",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_312129/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 31,
        "hostname": 31,
        "email": 8,
        "FileHash-SHA256": 5,
        "URL": 35
      },
      "indicator_count": 110,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 73,
      "modified_text": "223 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "titanclaritty.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "titanclaritty.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780227305.9205673
}