{
  "type": "Domain",
  "indicator": "waybackmachine.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/waybackmachine.com",
    "alexa": "http://www.alexa.com/siteinfo/waybackmachine.com",
    "indicator": "waybackmachine.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4365753904,
      "indicator": "waybackmachine.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "6a0b06f047e3346072f0498c",
          "name": "beta | research",
          "description": "date research",
          "modified": "2026-05-20T08:57:00.942000",
          "created": "2026-05-18T12:32:48.538000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 157,
            "hostname": 227,
            "URL": 341,
            "FileHash-SHA256": 987,
            "IPv4": 113,
            "FileHash-SHA1": 41,
            "FileHash-MD5": 48,
            "email": 3
          },
          "indicator_count": 1917,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "11 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a09f2637a6b0fe5c3b1c747",
          "name": "FlexiSpy",
          "description": "[Pulses, as well as data, are the source of the Whois website, which was created in 2006 and is now being used to identify people who have been infected by a virus]",
          "modified": "2026-05-18T13:13:52.638000",
          "created": "2026-05-17T16:52:51.703000",
          "tags": [
            "creation date",
            "moved",
            "expiration date",
            "name servers",
            "date",
            "server",
            "passive dns",
            "urls",
            "files",
            "whois registrar",
            "title",
            "registrar abuse",
            "ascio",
            "iana id",
            "contact phone",
            "dnssec",
            "domain status",
            "registrar url",
            "registrar whois",
            "algorithm",
            "key identifier",
            "x509v3 subject",
            "v3 serial",
            "number",
            "cgb osectigo",
            "public server",
            "dv r36",
            "validity",
            "subject public",
            "code",
            "admin country",
            "admin postal",
            "domain name",
            "host blocklist",
            "github gist",
            "github",
            "file format",
            "search",
            "google",
            "text text",
            "ascii text",
            "crlf line",
            "thumbprint",
            "postal code",
            "registry domain",
            "registrar iana",
            "admin city"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 244,
            "domain": 116,
            "email": 3,
            "hostname": 229,
            "IPv4": 15,
            "FileHash-MD5": 24,
            "FileHash-SHA1": 32,
            "FileHash-SHA256": 261
          },
          "indicator_count": 924,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "13 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a09f2648fad43c2e2f73845",
          "name": "FlexiSpy",
          "description": "[Pulses, as well as data, are the source of the Whois website, which was created in 2006 and is now being used to identify people who have been infected by a virus]",
          "modified": "2026-05-18T13:13:50.971000",
          "created": "2026-05-17T16:52:52.401000",
          "tags": [
            "creation date",
            "moved",
            "expiration date",
            "name servers",
            "date",
            "server",
            "passive dns",
            "urls",
            "files",
            "whois registrar",
            "title",
            "registrar abuse",
            "ascio",
            "iana id",
            "contact phone",
            "dnssec",
            "domain status",
            "registrar url",
            "registrar whois",
            "algorithm",
            "key identifier",
            "x509v3 subject",
            "v3 serial",
            "number",
            "cgb osectigo",
            "public server",
            "dv r36",
            "validity",
            "subject public",
            "code",
            "admin country",
            "admin postal",
            "domain name",
            "host blocklist",
            "github gist",
            "github",
            "file format",
            "search",
            "google",
            "text text",
            "ascii text",
            "crlf line",
            "thumbprint",
            "postal code",
            "registry domain",
            "registrar iana",
            "admin city"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 244,
            "domain": 116,
            "email": 3,
            "hostname": 229,
            "IPv4": 15,
            "FileHash-MD5": 24,
            "FileHash-SHA1": 32,
            "FileHash-SHA256": 261
          },
          "indicator_count": 924,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "13 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a09f267384850f72c7bd03e",
          "name": "FlexiSpy",
          "description": "[Pulses, as well as data, are the source of the Whois website, which was created in 2006 and is now being used to identify people who have been infected by a virus]",
          "modified": "2026-05-18T13:13:50.627000",
          "created": "2026-05-17T16:52:55.517000",
          "tags": [
            "creation date",
            "moved",
            "expiration date",
            "name servers",
            "date",
            "server",
            "passive dns",
            "urls",
            "files",
            "whois registrar",
            "title",
            "registrar abuse",
            "ascio",
            "iana id",
            "contact phone",
            "dnssec",
            "domain status",
            "registrar url",
            "registrar whois",
            "algorithm",
            "key identifier",
            "x509v3 subject",
            "v3 serial",
            "number",
            "cgb osectigo",
            "public server",
            "dv r36",
            "validity",
            "subject public",
            "code",
            "admin country",
            "admin postal",
            "domain name",
            "host blocklist",
            "github gist",
            "github",
            "file format",
            "search",
            "google",
            "text text",
            "ascii text",
            "crlf line",
            "thumbprint",
            "postal code",
            "registry domain",
            "registrar iana",
            "admin city"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 244,
            "domain": 116,
            "email": 3,
            "hostname": 229,
            "IPv4": 15,
            "FileHash-MD5": 24,
            "FileHash-SHA1": 32,
            "FileHash-SHA256": 261
          },
          "indicator_count": 924,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "13 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "6a0b06f047e3346072f0498c",
      "name": "beta | research",
      "description": "date research",
      "modified": "2026-05-20T08:57:00.942000",
      "created": "2026-05-18T12:32:48.538000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 157,
        "hostname": 227,
        "URL": 341,
        "FileHash-SHA256": 987,
        "IPv4": 113,
        "FileHash-SHA1": 41,
        "FileHash-MD5": 48,
        "email": 3
      },
      "indicator_count": 1917,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "11 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a09f2637a6b0fe5c3b1c747",
      "name": "FlexiSpy",
      "description": "[Pulses, as well as data, are the source of the Whois website, which was created in 2006 and is now being used to identify people who have been infected by a virus]",
      "modified": "2026-05-18T13:13:52.638000",
      "created": "2026-05-17T16:52:51.703000",
      "tags": [
        "creation date",
        "moved",
        "expiration date",
        "name servers",
        "date",
        "server",
        "passive dns",
        "urls",
        "files",
        "whois registrar",
        "title",
        "registrar abuse",
        "ascio",
        "iana id",
        "contact phone",
        "dnssec",
        "domain status",
        "registrar url",
        "registrar whois",
        "algorithm",
        "key identifier",
        "x509v3 subject",
        "v3 serial",
        "number",
        "cgb osectigo",
        "public server",
        "dv r36",
        "validity",
        "subject public",
        "code",
        "admin country",
        "admin postal",
        "domain name",
        "host blocklist",
        "github gist",
        "github",
        "file format",
        "search",
        "google",
        "text text",
        "ascii text",
        "crlf line",
        "thumbprint",
        "postal code",
        "registry domain",
        "registrar iana",
        "admin city"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 244,
        "domain": 116,
        "email": 3,
        "hostname": 229,
        "IPv4": 15,
        "FileHash-MD5": 24,
        "FileHash-SHA1": 32,
        "FileHash-SHA256": 261
      },
      "indicator_count": 924,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "13 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a09f2648fad43c2e2f73845",
      "name": "FlexiSpy",
      "description": "[Pulses, as well as data, are the source of the Whois website, which was created in 2006 and is now being used to identify people who have been infected by a virus]",
      "modified": "2026-05-18T13:13:50.971000",
      "created": "2026-05-17T16:52:52.401000",
      "tags": [
        "creation date",
        "moved",
        "expiration date",
        "name servers",
        "date",
        "server",
        "passive dns",
        "urls",
        "files",
        "whois registrar",
        "title",
        "registrar abuse",
        "ascio",
        "iana id",
        "contact phone",
        "dnssec",
        "domain status",
        "registrar url",
        "registrar whois",
        "algorithm",
        "key identifier",
        "x509v3 subject",
        "v3 serial",
        "number",
        "cgb osectigo",
        "public server",
        "dv r36",
        "validity",
        "subject public",
        "code",
        "admin country",
        "admin postal",
        "domain name",
        "host blocklist",
        "github gist",
        "github",
        "file format",
        "search",
        "google",
        "text text",
        "ascii text",
        "crlf line",
        "thumbprint",
        "postal code",
        "registry domain",
        "registrar iana",
        "admin city"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 244,
        "domain": 116,
        "email": 3,
        "hostname": 229,
        "IPv4": 15,
        "FileHash-MD5": 24,
        "FileHash-SHA1": 32,
        "FileHash-SHA256": 261
      },
      "indicator_count": 924,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "13 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a09f267384850f72c7bd03e",
      "name": "FlexiSpy",
      "description": "[Pulses, as well as data, are the source of the Whois website, which was created in 2006 and is now being used to identify people who have been infected by a virus]",
      "modified": "2026-05-18T13:13:50.627000",
      "created": "2026-05-17T16:52:55.517000",
      "tags": [
        "creation date",
        "moved",
        "expiration date",
        "name servers",
        "date",
        "server",
        "passive dns",
        "urls",
        "files",
        "whois registrar",
        "title",
        "registrar abuse",
        "ascio",
        "iana id",
        "contact phone",
        "dnssec",
        "domain status",
        "registrar url",
        "registrar whois",
        "algorithm",
        "key identifier",
        "x509v3 subject",
        "v3 serial",
        "number",
        "cgb osectigo",
        "public server",
        "dv r36",
        "validity",
        "subject public",
        "code",
        "admin country",
        "admin postal",
        "domain name",
        "host blocklist",
        "github gist",
        "github",
        "file format",
        "search",
        "google",
        "text text",
        "ascii text",
        "crlf line",
        "thumbprint",
        "postal code",
        "registry domain",
        "registrar iana",
        "admin city"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 244,
        "domain": 116,
        "email": 3,
        "hostname": 229,
        "IPv4": 15,
        "FileHash-MD5": 24,
        "FileHash-SHA1": 32,
        "FileHash-SHA256": 261
      },
      "indicator_count": 924,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "13 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "waybackmachine.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "waybackmachine.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780235349.048933
}