{
  "type": "Domain",
  "indicator": "vsock.cat",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/vsock.cat",
    "alexa": "http://www.alexa.com/siteinfo/vsock.cat",
    "indicator": "vsock.cat",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3745494928,
      "indicator": "vsock.cat",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "65c994c8b145925072b6583a",
          "name": "Private Loader cyber threat - Sliq.net | https://house.mo.gov",
          "description": "Link found active  in https://house.mo.gov. \nhttps://sg001-harmony.sliq.net/00325/harmony/en/PowerBrowser/RoomRouter?location=chamber&viewMode=3&globalStreamId=1 |",
          "modified": "2024-03-13T03:00:40.889000",
          "created": "2024-02-12T03:47:20.138000",
          "tags": [
            "ssl certificate",
            "threat roundup",
            "referrer",
            "historical ssl",
            "remcos rat",
            "august",
            "iocs",
            "contacted",
            "qakbot",
            "june",
            "service",
            "privateloader",
            "amadey",
            "blacknet rat",
            "qbot",
            "cobalt strike",
            "push",
            "core",
            "malformed domains",
            "sliq",
            "typosquatting",
            "malware",
            "network",
            "dns",
            "spyware",
            "access",
            "remote",
            "cyber threat",
            "virus network",
            "command and control",
            "remote connections",
            "exploits",
            "injection",
            "legislature",
            "trojan",
            "scanning host",
            "threat analyzer",
            "threat",
            "paste",
            "urls https",
            "locationchamber",
            "viewmode3",
            "hostnames",
            "url https",
            "false layer",
            "http"
          ],
          "references": [
            "https://sg001-harmony.sliq.net/00325/harmony/en/PowerBrowser/RoomRouter?location=chamber&viewMode=3&globalStreamId=1",
            "https://www.facebooksunglassshop.com [pegasus related]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Amadey",
              "display_name": "Amadey",
              "target": null
            },
            {
              "id": "BlackNET RAT",
              "display_name": "BlackNET RAT",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "QakBot",
              "display_name": "QakBot",
              "target": null
            },
            {
              "id": "QBot",
              "display_name": "QBot",
              "target": null
            },
            {
              "id": "Malware",
              "display_name": "Malware",
              "target": null
            },
            {
              "id": "PrivateLoader",
              "display_name": "PrivateLoader",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1608.002",
              "name": "Upload Tool",
              "display_name": "T1608.002 - Upload Tool"
            },
            {
              "id": "T1608.001",
              "name": "Upload Malware",
              "display_name": "T1608.001 - Upload Malware"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            }
          ],
          "industries": [
            "Government",
            "Technology",
            "Civil Society"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 36,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 56,
            "FileHash-SHA1": 36,
            "FileHash-SHA256": 1384,
            "CVE": 5,
            "URL": 1865,
            "domain": 222,
            "hostname": 648
          },
          "indicator_count": 4216,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "810 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65cab679e6ff8544ecf11962",
          "name": "Private Loader cyber threat - Sliq.net | https://house.mo.gov ",
          "description": "",
          "modified": "2024-03-13T03:00:40.889000",
          "created": "2024-02-13T00:23:21.062000",
          "tags": [
            "ssl certificate",
            "threat roundup",
            "referrer",
            "historical ssl",
            "remcos rat",
            "august",
            "iocs",
            "contacted",
            "qakbot",
            "june",
            "service",
            "privateloader",
            "amadey",
            "blacknet rat",
            "qbot",
            "cobalt strike",
            "push",
            "core",
            "malformed domains",
            "sliq",
            "typosquatting",
            "malware",
            "network",
            "dns",
            "spyware",
            "access",
            "remote",
            "cyber threat",
            "virus network",
            "command and control",
            "remote connections",
            "exploits",
            "injection",
            "legislature",
            "trojan",
            "scanning host",
            "threat analyzer",
            "threat",
            "paste",
            "urls https",
            "locationchamber",
            "viewmode3",
            "hostnames",
            "url https",
            "false layer",
            "http"
          ],
          "references": [
            "https://sg001-harmony.sliq.net/00325/harmony/en/PowerBrowser/RoomRouter?location=chamber&viewMode=3&globalStreamId=1",
            "https://www.facebooksunglassshop.com [pegasus related]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Amadey",
              "display_name": "Amadey",
              "target": null
            },
            {
              "id": "BlackNET RAT",
              "display_name": "BlackNET RAT",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "QakBot",
              "display_name": "QakBot",
              "target": null
            },
            {
              "id": "QBot",
              "display_name": "QBot",
              "target": null
            },
            {
              "id": "Malware",
              "display_name": "Malware",
              "target": null
            },
            {
              "id": "PrivateLoader",
              "display_name": "PrivateLoader",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1608.002",
              "name": "Upload Tool",
              "display_name": "T1608.002 - Upload Tool"
            },
            {
              "id": "T1608.001",
              "name": "Upload Malware",
              "display_name": "T1608.001 - Upload Malware"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            }
          ],
          "industries": [
            "Government",
            "Technology",
            "Civil Society"
          ],
          "TLP": "white",
          "cloned_from": "65c994c8b145925072b6583a",
          "export_count": 32,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 56,
            "FileHash-SHA1": 36,
            "FileHash-SHA256": 1384,
            "CVE": 5,
            "URL": 1865,
            "domain": 222,
            "hostname": 648
          },
          "indicator_count": 4216,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "810 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65831c52eceb4090b5d49d21",
          "name": "Critical (GC)",
          "description": "",
          "modified": "2024-01-19T15:01:02.500000",
          "created": "2023-12-20T16:54:42.626000",
          "tags": [
            "ssl certificate",
            "threat roundup",
            "referrer",
            "historical",
            "historical ssl",
            "colors",
            "pattern match",
            "windir",
            "openurl c",
            "logo",
            "december",
            "default browser",
            "guest system",
            "professional",
            "service pack",
            "click",
            "strings",
            "report",
            "command_and_control",
            "file",
            "ascii text",
            "done adding",
            "catalog file",
            "appdata",
            "united",
            "windows nt",
            "indicator",
            "mitre att",
            "date",
            "unknown",
            "error",
            "general",
            "local",
            "facebook",
            "class",
            "generator",
            "critical",
            "span",
            "gc",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "httponly",
            "secure",
            "dynamic expires",
            "blacklist",
            "site",
            "cisco umbrella",
            "worm",
            "malware-as_a_service"
          ],
          "references": [
            "https://neca.omeclk.com/portal/wts/uc^cn^ejkaejsaBeyk7-^Oa",
            "https://www.hybrid-analysis.com/sample/f7cb7c256e840ab93e6991462cedf6eac928c12f4102798986e2c5d27d1abc7f"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            },
            {
              "id": "Malware",
              "display_name": "Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 57,
            "FileHash-SHA1": 59,
            "FileHash-SHA256": 1358,
            "URL": 1430,
            "domain": 245,
            "hostname": 676
          },
          "indicator_count": 3825,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "863 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f12d6276e255c7d06acc0",
          "name": "EWA Phishing & Exploit in short link survey redirect",
          "description": "",
          "modified": "2023-10-30T02:20:06.113000",
          "created": "2023-10-30T02:20:06.113000",
          "tags": [
            "external system",
            "windir",
            "ck id",
            "show technique",
            "mitre att",
            "ck matrix",
            "hashtablemutex",
            "sample",
            "antivirus",
            "api call",
            "general",
            "pattern match",
            "done adding",
            "catalog file",
            "temp",
            "network related",
            "https webserver",
            "flag",
            "united",
            "server",
            "date",
            "india india",
            "localappdata",
            "source",
            "binary file",
            "click",
            "input",
            "pcap",
            "files clean1",
            "size",
            "type data",
            "av scan",
            "result",
            "copy md5",
            "sha1",
            "copy sha1",
            "runtime process",
            "sha256",
            "copy sha256",
            "asn13335",
            "cloudflarenet",
            "india",
            "asn16509",
            "amazon02",
            "frankfurt",
            "main",
            "germany",
            "asn15169",
            "value",
            "august",
            "variables",
            "zone function",
            "fontawesome",
            "editbox",
            "button function",
            "pushbutton",
            "textfield",
            "passwordfield",
            "domains",
            "hashes"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65133deee8ee099ab75a49aa",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 137,
            "domain": 64,
            "hostname": 34,
            "FileHash-SHA256": 31,
            "FileHash-MD5": 9,
            "FileHash-SHA1": 7
          },
          "indicator_count": 282,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "945 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65133deee8ee099ab75a49aa",
          "name": "EWA Phishing & Exploit in short link survey redirect",
          "description": "",
          "modified": "2023-09-26T20:24:14.268000",
          "created": "2023-09-26T20:24:14.268000",
          "tags": [
            "external system",
            "windir",
            "ck id",
            "show technique",
            "mitre att",
            "ck matrix",
            "hashtablemutex",
            "sample",
            "antivirus",
            "api call",
            "general",
            "pattern match",
            "done adding",
            "catalog file",
            "temp",
            "network related",
            "https webserver",
            "flag",
            "united",
            "server",
            "date",
            "india india",
            "localappdata",
            "source",
            "binary file",
            "click",
            "input",
            "pcap",
            "files clean1",
            "size",
            "type data",
            "av scan",
            "result",
            "copy md5",
            "sha1",
            "copy sha1",
            "runtime process",
            "sha256",
            "copy sha256",
            "asn13335",
            "cloudflarenet",
            "india",
            "asn16509",
            "amazon02",
            "frankfurt",
            "main",
            "germany",
            "asn15169",
            "value",
            "august",
            "variables",
            "zone function",
            "fontawesome",
            "editbox",
            "button function",
            "pushbutton",
            "textfield",
            "passwordfield",
            "domains",
            "hashes"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "64eae78aa781e6f8be552647",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 137,
            "domain": 64,
            "hostname": 34,
            "FileHash-SHA256": 31,
            "FileHash-MD5": 9,
            "FileHash-SHA1": 7
          },
          "indicator_count": 282,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "978 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64eae78aa781e6f8be552647",
          "name": "EWA Phishing & Exploit in   short link survey redirect.",
          "description": "Malicious redirect for hospital visit survey.  \nShort link: https://sprl.in/HRJqy0eX \u2192exploit_source\t\t\t\nredirects to:  https://www.ewatpa.com/cashless-claim-feedback/N5PZHDSGiMevZASQdsrtLg",
          "modified": "2023-09-26T05:00:14.694000",
          "created": "2023-08-27T06:04:58.559000",
          "tags": [
            "external system",
            "windir",
            "ck id",
            "show technique",
            "mitre att",
            "ck matrix",
            "hashtablemutex",
            "sample",
            "antivirus",
            "api call",
            "general",
            "pattern match",
            "done adding",
            "catalog file",
            "temp",
            "network related",
            "https webserver",
            "flag",
            "united",
            "server",
            "date",
            "india india",
            "localappdata",
            "source",
            "binary file",
            "click",
            "input",
            "pcap",
            "files clean1",
            "size",
            "type data",
            "av scan",
            "result",
            "copy md5",
            "sha1",
            "copy sha1",
            "runtime process",
            "sha256",
            "copy sha256",
            "asn13335",
            "cloudflarenet",
            "india",
            "asn16509",
            "amazon02",
            "frankfurt",
            "main",
            "germany",
            "asn15169",
            "value",
            "august",
            "variables",
            "zone function",
            "fontawesome",
            "editbox",
            "button function",
            "pushbutton",
            "textfield",
            "passwordfield",
            "domains",
            "hashes"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 137,
            "domain": 64,
            "hostname": 34,
            "FileHash-SHA256": 31,
            "FileHash-MD5": 9,
            "FileHash-SHA1": 7
          },
          "indicator_count": 282,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "979 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://neca.omeclk.com/portal/wts/uc^cn^ejkaejsaBeyk7-^Oa",
        "https://sg001-harmony.sliq.net/00325/harmony/en/PowerBrowser/RoomRouter?location=chamber&viewMode=3&globalStreamId=1",
        "https://www.hybrid-analysis.com/sample/f7cb7c256e840ab93e6991462cedf6eac928c12f4102798986e2c5d27d1abc7f",
        "https://www.facebooksunglassshop.com [pegasus related]"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Amadey",
            "Qakbot",
            "Blacknet rat",
            "Privateloader",
            "Gc",
            "Qbot",
            "Malware",
            "Cobalt strike"
          ],
          "industries": [
            "Civil society",
            "Government",
            "Technology"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "65c994c8b145925072b6583a",
      "name": "Private Loader cyber threat - Sliq.net | https://house.mo.gov",
      "description": "Link found active  in https://house.mo.gov. \nhttps://sg001-harmony.sliq.net/00325/harmony/en/PowerBrowser/RoomRouter?location=chamber&viewMode=3&globalStreamId=1 |",
      "modified": "2024-03-13T03:00:40.889000",
      "created": "2024-02-12T03:47:20.138000",
      "tags": [
        "ssl certificate",
        "threat roundup",
        "referrer",
        "historical ssl",
        "remcos rat",
        "august",
        "iocs",
        "contacted",
        "qakbot",
        "june",
        "service",
        "privateloader",
        "amadey",
        "blacknet rat",
        "qbot",
        "cobalt strike",
        "push",
        "core",
        "malformed domains",
        "sliq",
        "typosquatting",
        "malware",
        "network",
        "dns",
        "spyware",
        "access",
        "remote",
        "cyber threat",
        "virus network",
        "command and control",
        "remote connections",
        "exploits",
        "injection",
        "legislature",
        "trojan",
        "scanning host",
        "threat analyzer",
        "threat",
        "paste",
        "urls https",
        "locationchamber",
        "viewmode3",
        "hostnames",
        "url https",
        "false layer",
        "http"
      ],
      "references": [
        "https://sg001-harmony.sliq.net/00325/harmony/en/PowerBrowser/RoomRouter?location=chamber&viewMode=3&globalStreamId=1",
        "https://www.facebooksunglassshop.com [pegasus related]"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Amadey",
          "display_name": "Amadey",
          "target": null
        },
        {
          "id": "BlackNET RAT",
          "display_name": "BlackNET RAT",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "QakBot",
          "display_name": "QakBot",
          "target": null
        },
        {
          "id": "QBot",
          "display_name": "QBot",
          "target": null
        },
        {
          "id": "Malware",
          "display_name": "Malware",
          "target": null
        },
        {
          "id": "PrivateLoader",
          "display_name": "PrivateLoader",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1608.002",
          "name": "Upload Tool",
          "display_name": "T1608.002 - Upload Tool"
        },
        {
          "id": "T1608.001",
          "name": "Upload Malware",
          "display_name": "T1608.001 - Upload Malware"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        }
      ],
      "industries": [
        "Government",
        "Technology",
        "Civil Society"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 36,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 56,
        "FileHash-SHA1": 36,
        "FileHash-SHA256": 1384,
        "CVE": 5,
        "URL": 1865,
        "domain": 222,
        "hostname": 648
      },
      "indicator_count": 4216,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "810 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65cab679e6ff8544ecf11962",
      "name": "Private Loader cyber threat - Sliq.net | https://house.mo.gov ",
      "description": "",
      "modified": "2024-03-13T03:00:40.889000",
      "created": "2024-02-13T00:23:21.062000",
      "tags": [
        "ssl certificate",
        "threat roundup",
        "referrer",
        "historical ssl",
        "remcos rat",
        "august",
        "iocs",
        "contacted",
        "qakbot",
        "june",
        "service",
        "privateloader",
        "amadey",
        "blacknet rat",
        "qbot",
        "cobalt strike",
        "push",
        "core",
        "malformed domains",
        "sliq",
        "typosquatting",
        "malware",
        "network",
        "dns",
        "spyware",
        "access",
        "remote",
        "cyber threat",
        "virus network",
        "command and control",
        "remote connections",
        "exploits",
        "injection",
        "legislature",
        "trojan",
        "scanning host",
        "threat analyzer",
        "threat",
        "paste",
        "urls https",
        "locationchamber",
        "viewmode3",
        "hostnames",
        "url https",
        "false layer",
        "http"
      ],
      "references": [
        "https://sg001-harmony.sliq.net/00325/harmony/en/PowerBrowser/RoomRouter?location=chamber&viewMode=3&globalStreamId=1",
        "https://www.facebooksunglassshop.com [pegasus related]"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Amadey",
          "display_name": "Amadey",
          "target": null
        },
        {
          "id": "BlackNET RAT",
          "display_name": "BlackNET RAT",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "QakBot",
          "display_name": "QakBot",
          "target": null
        },
        {
          "id": "QBot",
          "display_name": "QBot",
          "target": null
        },
        {
          "id": "Malware",
          "display_name": "Malware",
          "target": null
        },
        {
          "id": "PrivateLoader",
          "display_name": "PrivateLoader",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1608.002",
          "name": "Upload Tool",
          "display_name": "T1608.002 - Upload Tool"
        },
        {
          "id": "T1608.001",
          "name": "Upload Malware",
          "display_name": "T1608.001 - Upload Malware"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        }
      ],
      "industries": [
        "Government",
        "Technology",
        "Civil Society"
      ],
      "TLP": "white",
      "cloned_from": "65c994c8b145925072b6583a",
      "export_count": 32,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 56,
        "FileHash-SHA1": 36,
        "FileHash-SHA256": 1384,
        "CVE": 5,
        "URL": 1865,
        "domain": 222,
        "hostname": 648
      },
      "indicator_count": 4216,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "810 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65831c52eceb4090b5d49d21",
      "name": "Critical (GC)",
      "description": "",
      "modified": "2024-01-19T15:01:02.500000",
      "created": "2023-12-20T16:54:42.626000",
      "tags": [
        "ssl certificate",
        "threat roundup",
        "referrer",
        "historical",
        "historical ssl",
        "colors",
        "pattern match",
        "windir",
        "openurl c",
        "logo",
        "december",
        "default browser",
        "guest system",
        "professional",
        "service pack",
        "click",
        "strings",
        "report",
        "command_and_control",
        "file",
        "ascii text",
        "done adding",
        "catalog file",
        "appdata",
        "united",
        "windows nt",
        "indicator",
        "mitre att",
        "date",
        "unknown",
        "error",
        "general",
        "local",
        "facebook",
        "class",
        "generator",
        "critical",
        "span",
        "gc",
        "http response",
        "final url",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "httponly",
        "secure",
        "dynamic expires",
        "blacklist",
        "site",
        "cisco umbrella",
        "worm",
        "malware-as_a_service"
      ],
      "references": [
        "https://neca.omeclk.com/portal/wts/uc^cn^ejkaejsaBeyk7-^Oa",
        "https://www.hybrid-analysis.com/sample/f7cb7c256e840ab93e6991462cedf6eac928c12f4102798986e2c5d27d1abc7f"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada"
      ],
      "malware_families": [
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        },
        {
          "id": "Malware",
          "display_name": "Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 57,
        "FileHash-SHA1": 59,
        "FileHash-SHA256": 1358,
        "URL": 1430,
        "domain": 245,
        "hostname": 676
      },
      "indicator_count": 3825,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "863 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f12d6276e255c7d06acc0",
      "name": "EWA Phishing & Exploit in short link survey redirect",
      "description": "",
      "modified": "2023-10-30T02:20:06.113000",
      "created": "2023-10-30T02:20:06.113000",
      "tags": [
        "external system",
        "windir",
        "ck id",
        "show technique",
        "mitre att",
        "ck matrix",
        "hashtablemutex",
        "sample",
        "antivirus",
        "api call",
        "general",
        "pattern match",
        "done adding",
        "catalog file",
        "temp",
        "network related",
        "https webserver",
        "flag",
        "united",
        "server",
        "date",
        "india india",
        "localappdata",
        "source",
        "binary file",
        "click",
        "input",
        "pcap",
        "files clean1",
        "size",
        "type data",
        "av scan",
        "result",
        "copy md5",
        "sha1",
        "copy sha1",
        "runtime process",
        "sha256",
        "copy sha256",
        "asn13335",
        "cloudflarenet",
        "india",
        "asn16509",
        "amazon02",
        "frankfurt",
        "main",
        "germany",
        "asn15169",
        "value",
        "august",
        "variables",
        "zone function",
        "fontawesome",
        "editbox",
        "button function",
        "pushbutton",
        "textfield",
        "passwordfield",
        "domains",
        "hashes"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65133deee8ee099ab75a49aa",
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 137,
        "domain": 64,
        "hostname": 34,
        "FileHash-SHA256": 31,
        "FileHash-MD5": 9,
        "FileHash-SHA1": 7
      },
      "indicator_count": 282,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "945 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65133deee8ee099ab75a49aa",
      "name": "EWA Phishing & Exploit in short link survey redirect",
      "description": "",
      "modified": "2023-09-26T20:24:14.268000",
      "created": "2023-09-26T20:24:14.268000",
      "tags": [
        "external system",
        "windir",
        "ck id",
        "show technique",
        "mitre att",
        "ck matrix",
        "hashtablemutex",
        "sample",
        "antivirus",
        "api call",
        "general",
        "pattern match",
        "done adding",
        "catalog file",
        "temp",
        "network related",
        "https webserver",
        "flag",
        "united",
        "server",
        "date",
        "india india",
        "localappdata",
        "source",
        "binary file",
        "click",
        "input",
        "pcap",
        "files clean1",
        "size",
        "type data",
        "av scan",
        "result",
        "copy md5",
        "sha1",
        "copy sha1",
        "runtime process",
        "sha256",
        "copy sha256",
        "asn13335",
        "cloudflarenet",
        "india",
        "asn16509",
        "amazon02",
        "frankfurt",
        "main",
        "germany",
        "asn15169",
        "value",
        "august",
        "variables",
        "zone function",
        "fontawesome",
        "editbox",
        "button function",
        "pushbutton",
        "textfield",
        "passwordfield",
        "domains",
        "hashes"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "64eae78aa781e6f8be552647",
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 137,
        "domain": 64,
        "hostname": 34,
        "FileHash-SHA256": 31,
        "FileHash-MD5": 9,
        "FileHash-SHA1": 7
      },
      "indicator_count": 282,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "978 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "64eae78aa781e6f8be552647",
      "name": "EWA Phishing & Exploit in   short link survey redirect.",
      "description": "Malicious redirect for hospital visit survey.  \nShort link: https://sprl.in/HRJqy0eX \u2192exploit_source\t\t\t\nredirects to:  https://www.ewatpa.com/cashless-claim-feedback/N5PZHDSGiMevZASQdsrtLg",
      "modified": "2023-09-26T05:00:14.694000",
      "created": "2023-08-27T06:04:58.559000",
      "tags": [
        "external system",
        "windir",
        "ck id",
        "show technique",
        "mitre att",
        "ck matrix",
        "hashtablemutex",
        "sample",
        "antivirus",
        "api call",
        "general",
        "pattern match",
        "done adding",
        "catalog file",
        "temp",
        "network related",
        "https webserver",
        "flag",
        "united",
        "server",
        "date",
        "india india",
        "localappdata",
        "source",
        "binary file",
        "click",
        "input",
        "pcap",
        "files clean1",
        "size",
        "type data",
        "av scan",
        "result",
        "copy md5",
        "sha1",
        "copy sha1",
        "runtime process",
        "sha256",
        "copy sha256",
        "asn13335",
        "cloudflarenet",
        "india",
        "asn16509",
        "amazon02",
        "frankfurt",
        "main",
        "germany",
        "asn15169",
        "value",
        "august",
        "variables",
        "zone function",
        "fontawesome",
        "editbox",
        "button function",
        "pushbutton",
        "textfield",
        "passwordfield",
        "domains",
        "hashes"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 137,
        "domain": 64,
        "hostname": 34,
        "FileHash-SHA256": 31,
        "FileHash-MD5": 9,
        "FileHash-SHA1": 7
      },
      "indicator_count": 282,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "979 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "vsock.cat",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "vsock.cat",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780319884.4694278
}