{
  "type": "Domain",
  "indicator": "ukpaycn.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/ukpaycn.com",
    "alexa": "http://www.alexa.com/siteinfo/ukpaycn.com",
    "indicator": "ukpaycn.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4095408874,
      "indicator": "ukpaycn.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "6879f8fcecc13fd4ad77e76d",
          "name": "Chinese Malware Delivery Domains: Part III",
          "description": "This report details an ongoing campaign by a threat actor operating during Chinese time zone hours, targeting Chinese-speaking individuals and entities globally. Since June 2023, the actor has created over 2,800 domains for malware delivery, primarily targeting Windows systems through fake application download sites and update prompts. The actor has made operational changes, including anti-automation measures, reduced site tracker services, increased server distribution, and more discreet registration details. The campaign uses fake login pages, marketing apps, and cryptocurrency-related apps to distribute malware. The actor's motivations appear to be financially driven, potentially including credential theft, financial theft, and access brokering. The report emphasizes the importance of user awareness, enhanced security measures, and multi-layered defense strategies to counter this persistent threat.",
          "modified": "2025-08-17T07:00:08.502000",
          "created": "2025-07-18T07:34:20.203000",
          "tags": [
            "fake-updates",
            "windows",
            "phishing",
            "cryptocurrency"
          ],
          "references": [
            "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iii"
          ],
          "public": 1,
          "adversary": "SilverFox",
          "targeted_countries": [
            "China"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1036.005",
              "name": "Match Legitimate Name or Location",
              "display_name": "T1036.005 - Match Legitimate Name or Location"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204.001",
              "name": "Malicious Link",
              "display_name": "T1204.001 - Malicious Link"
            }
          ],
          "industries": [
            "Finance",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 75,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1131,
            "hostname": 4,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 23
          },
          "indicator_count": 1164,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 387195,
          "modified_text": "290 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69399bc051278b22dd92e262",
          "name": "Chinese Malware Delivery Domains",
          "description": "Since June 2023, DomainTools Investigations has been analyzing a significant cluster of malware delivery domains associated with Chinese threat actors. Initially, the investigation identified over 2,800 domains, with a subsequent discovery of an additional 1,900 domains, indicating a heavily operationalized malware infrastructure. The adaptive nature of this infrastructure has evolved noticeably, with a shift from a centralized hosting strategy to a more decentralized model by August 2025. This fragmentation reflects improvements in operational security and localization strategies, relying increasingly on domestic registrars from China while employing randomized domain naming conventions.\n\nThe operational methods of the threat actors have adapted significantly, reducing dependency on single ISPs from 90% to a maximum of 40%, thus spreading their infrastructure across five countries instead of just three.",
          "modified": "2025-12-10T16:11:44.839000",
          "created": "2025-12-10T16:11:44.839000",
          "tags": [
            "download url",
            "domain",
            "baidu tracker",
            "sha256 file",
            "google tag",
            "manager code",
            "type"
          ],
          "references": [
            "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iv/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1583.003",
              "name": "Virtual Private Server",
              "display_name": "T1583.003 - Virtual Private Server"
            },
            {
              "id": "T1585",
              "name": "Establish Accounts",
              "display_name": "T1585 - Establish Accounts"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1588",
              "name": "Obtain Capabilities",
              "display_name": "T1588 - Obtain Capabilities"
            }
          ],
          "industries": [
            "Entertainment",
            "Telecommunications"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 18,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 15,
            "URL": 1,
            "domain": 1322,
            "email": 1,
            "hostname": 1
          },
          "indicator_count": 1361,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 544,
          "modified_text": "175 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "687e1ad284872df7fdd74ce1",
          "name": "Chinese Malware Delivery Domains: Part III",
          "description": "",
          "modified": "2025-08-20T10:01:02.432000",
          "created": "2025-07-21T10:47:46.801000",
          "tags": [
            "url https",
            "indicator",
            "type"
          ],
          "references": [
            "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iii/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 25,
            "FileHash-SHA1": 23,
            "FileHash-SHA256": 24,
            "domain": 1175,
            "hostname": 4
          },
          "indicator_count": 1251,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "287 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "687df49eaf1af13ad0a3aded",
          "name": "Chinese Malware Delivery Domains: Part III",
          "description": "",
          "modified": "2025-08-17T07:00:08.502000",
          "created": "2025-07-21T08:04:46.438000",
          "tags": [
            "fake-updates",
            "windows",
            "phishing",
            "cryptocurrency"
          ],
          "references": [
            "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iii"
          ],
          "public": 1,
          "adversary": "SilverFox",
          "targeted_countries": [
            "China"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1036.005",
              "name": "Match Legitimate Name or Location",
              "display_name": "T1036.005 - Match Legitimate Name or Location"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204.001",
              "name": "Malicious Link",
              "display_name": "T1204.001 - Malicious Link"
            }
          ],
          "industries": [
            "Finance",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "6879f8fcecc13fd4ad77e76d",
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1131,
            "hostname": 4,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 23
          },
          "indicator_count": 1164,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 277,
          "modified_text": "290 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "687f04dd38fbf121138122b6",
          "name": "IOC - Chinese Malware Delivery Domains: Part III",
          "description": "",
          "modified": "2025-08-17T07:00:08.502000",
          "created": "2025-07-22T03:26:21.248000",
          "tags": [
            "fake-updates",
            "windows",
            "phishing",
            "cryptocurrency"
          ],
          "references": [
            "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iii"
          ],
          "public": 1,
          "adversary": "SilverFox",
          "targeted_countries": [
            "China"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1036.005",
              "name": "Match Legitimate Name or Location",
              "display_name": "T1036.005 - Match Legitimate Name or Location"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204.001",
              "name": "Malicious Link",
              "display_name": "T1204.001 - Malicious Link"
            }
          ],
          "industries": [
            "Finance",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "6879f8fcecc13fd4ad77e76d",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "celestre",
            "id": "295357",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1131,
            "hostname": 4,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 23
          },
          "indicator_count": 1164,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 140,
          "modified_text": "290 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iii",
        "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iv/",
        "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iii/"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "SilverFox"
          ],
          "malware_families": [],
          "industries": [
            "Technology",
            "Finance"
          ]
        },
        "other": {
          "adversary": [
            "SilverFox"
          ],
          "malware_families": [],
          "industries": [
            "Telecommunications",
            "Technology",
            "Finance",
            "Entertainment"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "6879f8fcecc13fd4ad77e76d",
      "name": "Chinese Malware Delivery Domains: Part III",
      "description": "This report details an ongoing campaign by a threat actor operating during Chinese time zone hours, targeting Chinese-speaking individuals and entities globally. Since June 2023, the actor has created over 2,800 domains for malware delivery, primarily targeting Windows systems through fake application download sites and update prompts. The actor has made operational changes, including anti-automation measures, reduced site tracker services, increased server distribution, and more discreet registration details. The campaign uses fake login pages, marketing apps, and cryptocurrency-related apps to distribute malware. The actor's motivations appear to be financially driven, potentially including credential theft, financial theft, and access brokering. The report emphasizes the importance of user awareness, enhanced security measures, and multi-layered defense strategies to counter this persistent threat.",
      "modified": "2025-08-17T07:00:08.502000",
      "created": "2025-07-18T07:34:20.203000",
      "tags": [
        "fake-updates",
        "windows",
        "phishing",
        "cryptocurrency"
      ],
      "references": [
        "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iii"
      ],
      "public": 1,
      "adversary": "SilverFox",
      "targeted_countries": [
        "China"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1036.005",
          "name": "Match Legitimate Name or Location",
          "display_name": "T1036.005 - Match Legitimate Name or Location"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1547.001",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204.001",
          "name": "Malicious Link",
          "display_name": "T1204.001 - Malicious Link"
        }
      ],
      "industries": [
        "Finance",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 75,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1131,
        "hostname": 4,
        "FileHash-MD5": 4,
        "FileHash-SHA1": 2,
        "FileHash-SHA256": 23
      },
      "indicator_count": 1164,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 387195,
      "modified_text": "290 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69399bc051278b22dd92e262",
      "name": "Chinese Malware Delivery Domains",
      "description": "Since June 2023, DomainTools Investigations has been analyzing a significant cluster of malware delivery domains associated with Chinese threat actors. Initially, the investigation identified over 2,800 domains, with a subsequent discovery of an additional 1,900 domains, indicating a heavily operationalized malware infrastructure. The adaptive nature of this infrastructure has evolved noticeably, with a shift from a centralized hosting strategy to a more decentralized model by August 2025. This fragmentation reflects improvements in operational security and localization strategies, relying increasingly on domestic registrars from China while employing randomized domain naming conventions.\n\nThe operational methods of the threat actors have adapted significantly, reducing dependency on single ISPs from 90% to a maximum of 40%, thus spreading their infrastructure across five countries instead of just three.",
      "modified": "2025-12-10T16:11:44.839000",
      "created": "2025-12-10T16:11:44.839000",
      "tags": [
        "download url",
        "domain",
        "baidu tracker",
        "sha256 file",
        "google tag",
        "manager code",
        "type"
      ],
      "references": [
        "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iv/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1583.003",
          "name": "Virtual Private Server",
          "display_name": "T1583.003 - Virtual Private Server"
        },
        {
          "id": "T1585",
          "name": "Establish Accounts",
          "display_name": "T1585 - Establish Accounts"
        },
        {
          "id": "T1587",
          "name": "Develop Capabilities",
          "display_name": "T1587 - Develop Capabilities"
        },
        {
          "id": "T1588",
          "name": "Obtain Capabilities",
          "display_name": "T1588 - Obtain Capabilities"
        }
      ],
      "industries": [
        "Entertainment",
        "Telecommunications"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 18,
        "FileHash-SHA1": 3,
        "FileHash-SHA256": 15,
        "URL": 1,
        "domain": 1322,
        "email": 1,
        "hostname": 1
      },
      "indicator_count": 1361,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 544,
      "modified_text": "175 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "687e1ad284872df7fdd74ce1",
      "name": "Chinese Malware Delivery Domains: Part III",
      "description": "",
      "modified": "2025-08-20T10:01:02.432000",
      "created": "2025-07-21T10:47:46.801000",
      "tags": [
        "url https",
        "indicator",
        "type"
      ],
      "references": [
        "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iii/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 25,
        "FileHash-SHA1": 23,
        "FileHash-SHA256": 24,
        "domain": 1175,
        "hostname": 4
      },
      "indicator_count": 1251,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 863,
      "modified_text": "287 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "687df49eaf1af13ad0a3aded",
      "name": "Chinese Malware Delivery Domains: Part III",
      "description": "",
      "modified": "2025-08-17T07:00:08.502000",
      "created": "2025-07-21T08:04:46.438000",
      "tags": [
        "fake-updates",
        "windows",
        "phishing",
        "cryptocurrency"
      ],
      "references": [
        "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iii"
      ],
      "public": 1,
      "adversary": "SilverFox",
      "targeted_countries": [
        "China"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1036.005",
          "name": "Match Legitimate Name or Location",
          "display_name": "T1036.005 - Match Legitimate Name or Location"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1547.001",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204.001",
          "name": "Malicious Link",
          "display_name": "T1204.001 - Malicious Link"
        }
      ],
      "industries": [
        "Finance",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": "6879f8fcecc13fd4ad77e76d",
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Tr1sa111",
        "id": "192483",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1131,
        "hostname": 4,
        "FileHash-MD5": 4,
        "FileHash-SHA1": 2,
        "FileHash-SHA256": 23
      },
      "indicator_count": 1164,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 277,
      "modified_text": "290 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "687f04dd38fbf121138122b6",
      "name": "IOC - Chinese Malware Delivery Domains: Part III",
      "description": "",
      "modified": "2025-08-17T07:00:08.502000",
      "created": "2025-07-22T03:26:21.248000",
      "tags": [
        "fake-updates",
        "windows",
        "phishing",
        "cryptocurrency"
      ],
      "references": [
        "https://dti.domaintools.com/chinese-malware-delivery-domains-part-iii"
      ],
      "public": 1,
      "adversary": "SilverFox",
      "targeted_countries": [
        "China"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1036.005",
          "name": "Match Legitimate Name or Location",
          "display_name": "T1036.005 - Match Legitimate Name or Location"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1547.001",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204.001",
          "name": "Malicious Link",
          "display_name": "T1204.001 - Malicious Link"
        }
      ],
      "industries": [
        "Finance",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": "6879f8fcecc13fd4ad77e76d",
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "celestre",
        "id": "295357",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1131,
        "hostname": 4,
        "FileHash-MD5": 4,
        "FileHash-SHA1": 2,
        "FileHash-SHA256": 23
      },
      "indicator_count": 1164,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 140,
      "modified_text": "290 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "ukpaycn.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "ukpaycn.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780526232.6228025
}