{
  "type": "Domain",
  "indicator": "triallightrfp.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/triallightrfp.com",
    "alexa": "http://www.alexa.com/siteinfo/triallightrfp.com",
    "indicator": "triallightrfp.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4092088563,
      "indicator": "triallightrfp.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "6875cbb7f546e86006afa0ea",
          "name": "Ransomware attack ConnectCare Alberta - 07.12.25",
          "description": "On 07.12.25 ConnectCare Alberta experienced what was initially thought to be an outtage or downtime. Further analysis of data captured in realtime reveals this to not be the case. Healthcare Provider and patient services were disrupted across multiple zone in the Province of Alberta. Other organizations impacted include: The Government of Alberta, The Alberta NDP, The Alberta UCP, The University of Alberta, both Alberta Health Services & Covenant Health, Telus Communications, United Nurses of Alberta, Alberta Physicians Association, Treaty 8 FNA & Confederacy of Treaty Six, in addition to the City of Edmonton.\nGraph:",
          "modified": "2025-08-14T03:03:45.057000",
          "created": "2025-07-15T03:32:07.251000",
          "tags": [
            "entity",
            "Alberta",
            "Alberta Health Services",
            "Covenent Health",
            "Alberta NDP",
            "Treaty 6",
            "Treaty 7",
            "Treaty 8",
            "UAlberta",
            "Connect Care",
            "Telus",
            "Rogers",
            "City of Edmonton",
            "Edmonton Police Services",
            "United Nurses of Alberta",
            "Alberta Medical Association",
            "EduRoam",
            "DGA",
            "Alberta Doctors",
            "University of Calgary",
            "Alberta UCP",
            "Ministry of Advanced Education",
            "Ministry of Health",
            "Ministry of Tech & Innovation",
            "Ransomware",
            "Botnet"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/gdef52451e74740eaabbbcc6db2209b722e6a17129ba94f4eb92fa176bcea66f7?theme=dark",
            "https://www.virustotal.com/gui/collection/525d014c83ee92554cb6a88685ba822e147f30dbc797a18b6071081a109b7dcb",
            "https://www.virustotal.com/gui/collection/525d014c83ee92554cb6a88685ba822e147f30dbc797a18b6071081a109b7dcb/iocs",
            "https://viz.greynoise.io/analysis/16d9bc15-d3ed-4e71-9631-16742e511649"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare",
            "Government",
            "Education"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 41,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 122,
            "FileHash-SHA1": 123,
            "FileHash-SHA256": 931,
            "URL": 60,
            "domain": 58,
            "email": 2,
            "hostname": 812
          },
          "indicator_count": 2108,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 131,
          "modified_text": "292 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68768fee832e9d7358e7ec77",
          "name": "IT4US Ransom clone",
          "description": "",
          "modified": "2025-08-14T03:03:45.057000",
          "created": "2025-07-15T17:29:18.363000",
          "tags": [
            "entity",
            "Alberta",
            "Alberta Health Services",
            "Covenent Health",
            "Alberta NDP",
            "Treaty 6",
            "Treaty 7",
            "Treaty 8",
            "UAlberta",
            "Connect Care",
            "Telus",
            "Rogers",
            "City of Edmonton",
            "Edmonton Police Services",
            "United Nurses of Alberta",
            "Alberta Medical Association",
            "EduRoam",
            "DGA",
            "Alberta Doctors",
            "University of Calgary",
            "Alberta UCP",
            "Ministry of Advanced Education",
            "Ministry of Health",
            "Ministry of Tech & Innovation",
            "Ransomware",
            "Botnet"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/gdef52451e74740eaabbbcc6db2209b722e6a17129ba94f4eb92fa176bcea66f7?theme=dark",
            "https://www.virustotal.com/gui/collection/525d014c83ee92554cb6a88685ba822e147f30dbc797a18b6071081a109b7dcb",
            "https://www.virustotal.com/gui/collection/525d014c83ee92554cb6a88685ba822e147f30dbc797a18b6071081a109b7dcb/iocs",
            "https://viz.greynoise.io/analysis/16d9bc15-d3ed-4e71-9631-16742e511649"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare",
            "Government",
            "Education"
          ],
          "TLP": "white",
          "cloned_from": "6875cbb7f546e86006afa0ea",
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Dougline",
            "id": "350513",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 122,
            "FileHash-SHA1": 123,
            "FileHash-SHA256": 931,
            "URL": 60,
            "domain": 58,
            "email": 2,
            "hostname": 812
          },
          "indicator_count": 2108,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 2,
          "modified_text": "292 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://viz.greynoise.io/analysis/16d9bc15-d3ed-4e71-9631-16742e511649",
        "https://www.virustotal.com/graph/embed/gdef52451e74740eaabbbcc6db2209b722e6a17129ba94f4eb92fa176bcea66f7?theme=dark",
        "https://www.virustotal.com/gui/collection/525d014c83ee92554cb6a88685ba822e147f30dbc797a18b6071081a109b7dcb/iocs",
        "https://www.virustotal.com/gui/collection/525d014c83ee92554cb6a88685ba822e147f30dbc797a18b6071081a109b7dcb"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [
            "Healthcare",
            "Education",
            "Government"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "6875cbb7f546e86006afa0ea",
      "name": "Ransomware attack ConnectCare Alberta - 07.12.25",
      "description": "On 07.12.25 ConnectCare Alberta experienced what was initially thought to be an outtage or downtime. Further analysis of data captured in realtime reveals this to not be the case. Healthcare Provider and patient services were disrupted across multiple zone in the Province of Alberta. Other organizations impacted include: The Government of Alberta, The Alberta NDP, The Alberta UCP, The University of Alberta, both Alberta Health Services & Covenant Health, Telus Communications, United Nurses of Alberta, Alberta Physicians Association, Treaty 8 FNA & Confederacy of Treaty Six, in addition to the City of Edmonton.\nGraph:",
      "modified": "2025-08-14T03:03:45.057000",
      "created": "2025-07-15T03:32:07.251000",
      "tags": [
        "entity",
        "Alberta",
        "Alberta Health Services",
        "Covenent Health",
        "Alberta NDP",
        "Treaty 6",
        "Treaty 7",
        "Treaty 8",
        "UAlberta",
        "Connect Care",
        "Telus",
        "Rogers",
        "City of Edmonton",
        "Edmonton Police Services",
        "United Nurses of Alberta",
        "Alberta Medical Association",
        "EduRoam",
        "DGA",
        "Alberta Doctors",
        "University of Calgary",
        "Alberta UCP",
        "Ministry of Advanced Education",
        "Ministry of Health",
        "Ministry of Tech & Innovation",
        "Ransomware",
        "Botnet"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/gdef52451e74740eaabbbcc6db2209b722e6a17129ba94f4eb92fa176bcea66f7?theme=dark",
        "https://www.virustotal.com/gui/collection/525d014c83ee92554cb6a88685ba822e147f30dbc797a18b6071081a109b7dcb",
        "https://www.virustotal.com/gui/collection/525d014c83ee92554cb6a88685ba822e147f30dbc797a18b6071081a109b7dcb/iocs",
        "https://viz.greynoise.io/analysis/16d9bc15-d3ed-4e71-9631-16742e511649"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare",
        "Government",
        "Education"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 41,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 122,
        "FileHash-SHA1": 123,
        "FileHash-SHA256": 931,
        "URL": 60,
        "domain": 58,
        "email": 2,
        "hostname": 812
      },
      "indicator_count": 2108,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 131,
      "modified_text": "292 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68768fee832e9d7358e7ec77",
      "name": "IT4US Ransom clone",
      "description": "",
      "modified": "2025-08-14T03:03:45.057000",
      "created": "2025-07-15T17:29:18.363000",
      "tags": [
        "entity",
        "Alberta",
        "Alberta Health Services",
        "Covenent Health",
        "Alberta NDP",
        "Treaty 6",
        "Treaty 7",
        "Treaty 8",
        "UAlberta",
        "Connect Care",
        "Telus",
        "Rogers",
        "City of Edmonton",
        "Edmonton Police Services",
        "United Nurses of Alberta",
        "Alberta Medical Association",
        "EduRoam",
        "DGA",
        "Alberta Doctors",
        "University of Calgary",
        "Alberta UCP",
        "Ministry of Advanced Education",
        "Ministry of Health",
        "Ministry of Tech & Innovation",
        "Ransomware",
        "Botnet"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/gdef52451e74740eaabbbcc6db2209b722e6a17129ba94f4eb92fa176bcea66f7?theme=dark",
        "https://www.virustotal.com/gui/collection/525d014c83ee92554cb6a88685ba822e147f30dbc797a18b6071081a109b7dcb",
        "https://www.virustotal.com/gui/collection/525d014c83ee92554cb6a88685ba822e147f30dbc797a18b6071081a109b7dcb/iocs",
        "https://viz.greynoise.io/analysis/16d9bc15-d3ed-4e71-9631-16742e511649"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare",
        "Government",
        "Education"
      ],
      "TLP": "white",
      "cloned_from": "6875cbb7f546e86006afa0ea",
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Dougline",
        "id": "350513",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 122,
        "FileHash-SHA1": 123,
        "FileHash-SHA256": 931,
        "URL": 60,
        "domain": 58,
        "email": 2,
        "hostname": 812
      },
      "indicator_count": 2108,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 2,
      "modified_text": "292 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "triallightrfp.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "triallightrfp.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780453755.3709514
}