{
  "type": "Domain",
  "indicator": "webserver.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/webserver.com",
    "alexa": "http://www.alexa.com/siteinfo/webserver.com",
    "indicator": "webserver.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3836492634,
      "indicator": "webserver.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "6a030a7e7af998b0bc50d255",
          "name": "Inbox Termination Flood VirusTotal report                    for download.rar",
          "description": "[Malicious: Rar.rar (Rar!S8:z}b), a free archive that can be downloaded via 7Zip or 7zip, for use in the Windows operating system.] This email has vast capbilities, some of the best are email flooding, retrieval, destruction, extraction, tasks and more. This email on 6/3/25 led a client into a wormhole that they never actually got the delievery of it. Just the compliance locked email that destroyed their identity. It appears the temp folder that housed in malicious scripts was made months prior. I could not upload the Cape sandbox. Bundled 58, dropped 58, ensuring you will never get your life back.",
          "modified": "2026-05-12T11:49:25.043000",
          "created": "2026-05-12T11:09:50.783000",
          "tags": [
            "file type",
            "crlf line",
            "ascii text",
            "unicode text",
            "utf8 text",
            "html document",
            "json",
            "python script",
            "mitre attack",
            "network info",
            "window",
            "next",
            "flood email",
            "drops prompts",
            "malicious",
            "illegal",
            "gov",
            "crosstenant",
            "prepared months before in temp folder"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/86a27baba6d32b5c6fba49e2e99864c7d0feada360b55cfc63adb4383e58be77_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778583610&Signature=f3mubmpIGOjgn7yQIqVaPC8J5mcemkwpt3Yl3noIO7eheDcS0pvTXfJfGi4WzCTHzTXgjtWE36sh%2BSHtRa%2FHFX1lvvQnPgqQpvY%2FDVlhYYVKl1nwyiZFuUZliHBmes0%2FGUhViWWRiyYHxDkn7Yj7fV7EMQqnCtlxO%2FMVJf5%2BsmjEkpk%2Frahm4sEcFERizEQtsZBKSnnp%2B1v6RFDphsiX0Ri0ZISYRqmGpmH%2FGvP2%2FQKrXXc9br"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 212,
            "IPv4": 77,
            "URL": 398,
            "domain": 503,
            "hostname": 347,
            "email": 4
          },
          "indicator_count": 1557,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "19 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c3bd803f15cd94aab6e287",
          "name": "Lumma Stealer | Colorado Medical Center HCA",
          "description": "Needs further investigation. Miscellaneous attack affecting Denver physicians directory. Visitors accessing the page using insecure devices may be affected. PII & PHI breached. Monitoring.",
          "modified": "2024-03-08T17:04:03.644000",
          "created": "2024-02-07T17:27:28.349000",
          "tags": [
            "whois record",
            "ssl certificate",
            "contacted",
            "historical ssl",
            "referrer",
            "execution",
            "resolutions",
            "problems",
            "siblings domain",
            "whois whois",
            "startpage",
            "httponly",
            "samesitenone",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "language",
            "html document",
            "unicode text",
            "utf8 text",
            "doctype",
            "anchor hrefs",
            "hrefs",
            "denver",
            "tsara brashears",
            "apple ios",
            "password bypass",
            "apple phone",
            "unlocker",
            "shell code",
            "script",
            "contacted urls",
            "hacktool",
            "malicious",
            "download",
            "malware",
            "relic",
            "monitoring",
            "domains",
            "eurodns sa",
            "markmonitor",
            "ip detections",
            "country",
            "graph",
            "https",
            "mitre att",
            "ta0007 network",
            "t1046 sends",
            "ssdp",
            "command",
            "control ta0011",
            "protocol t1071",
            "performs dns",
            "layer protocol",
            "number",
            "cus cndigicert",
            "ja3s",
            "subject",
            "sha2 secure",
            "server ca",
            "odigicert inc",
            "cus cnmicrosoft",
            "algorithm",
            "memory pattern",
            "file system",
            "registry",
            "registry keys",
            "process",
            "created",
            "processes tree",
            "february",
            "healthone",
            "gmbh version",
            "status page",
            "service privacy",
            "legal",
            "impressum",
            "url https",
            "reverse dns",
            "general full",
            "security tls",
            "protocol h2",
            "software",
            "frankfurt",
            "main",
            "germany",
            "resource hash",
            "de indicators",
            "hashes",
            "value",
            "scriptsrcelem",
            "variables",
            "boomrmq string",
            "boomrapikey",
            "boomr function",
            "system",
            "babelpolyfill",
            "assign function",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "aes256gcm",
            "level",
            "akamaiasn1",
            "europeberlin",
            "generic malware",
            "tag count",
            "tue dec",
            "threat report",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "root ca",
            "pattern match",
            "authority",
            "span",
            "presbyterianst",
            "luke",
            "medical center",
            "class",
            "accept",
            "date",
            "refresh",
            "blood",
            "liver cancer",
            "breast cancer",
            "lung cancer",
            "kidney cancer",
            "skin cancer",
            "sarcoma",
            "prostate cancer",
            "body",
            "facebook",
            "twitter",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "error",
            "tools",
            "look",
            "verify",
            "restart",
            "cookie",
            "command and control",
            "mitre",
            "scanning host",
            "exploit source",
            "trojan",
            "callback function",
            "targets",
            "targeting",
            "samesite=none",
            "kde",
            "konqueror",
            "phi",
            "pii",
            "wTJh.exe",
            "malware ransom trojan evader rat",
            "network",
            "rat trojan",
            "relacionada",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "matches rule",
            "emotet",
            "lockbit",
            "critical",
            "copy",
            "installer",
            "dark power",
            "wiper",
            "ransomware",
            "cobalt strike",
            "ursnif",
            "core",
            "as55688 pt",
            "passive dns",
            "scan endpoints",
            "all octoseek",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "asn as55688",
            "threat",
            "paste",
            "iocs",
            "analyze",
            "hostnames",
            "united",
            "aaaa",
            "unknown",
            "a domains",
            "search",
            "creation date",
            "record value",
            "next",
            "pornhub",
            "anyxxxtube",
            "domain",
            "gandi sas",
            "hostname",
            "basic",
            "pe32",
            "intel",
            "ms windows",
            "generic windos",
            "executable",
            "dos executable",
            "generic",
            "pe32 packer",
            "petite",
            "vs98",
            "info compiler",
            "products",
            "header intel",
            "name md5",
            "type",
            "rticon neutral",
            "overlay",
            "dos exe",
            "threat roundup",
            "pe resource",
            "june",
            "lumma stealer",
            "ransomexx",
            "azorult",
            "njrat",
            "open",
            "problem",
            "plugx",
            "android",
            "sex_phot.jpg.exe",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "delphi generic",
            "icons library",
            "pe32 linker",
            "lcc linker",
            "empty hash",
            "tulach",
            "sabey",
            "rat",
            "remote",
            "remote access trojan"
          ],
          "references": [
            "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians",
            "https://www.hybrid-analysis.com/sample/63bf920be2401947bd686d7dd146af7f3e56800409307360105bf50cebb1c1ea",
            "www2.megawebfind.com [command and control]",
            "http://ifdnzact.com/?dn=megawebdeals.com&pid=9PO755G95 [ phishing]",
            "20.99.186.246 [exploit source]",
            "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians/ [heuristic]",
            "Win32:RATX-gen [Trj] identified.",
            "CS Sigma Rules: Shadow Copies Deletion Using Operating Systems Utilities by Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades)",
            "CS Sigma Rules: Disable UAC Using Registry by frack113",
            "http://45.159.189.105/bot/regex [ tracking | botnet]",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [Password cracker | Patient being tracked through multiple medical systems]",
            "0-173-x.msn.com | https://twitter.com/PORNO_SEXYBABES | 0-3.duckdns.org | 0-212.pornhub.org | 000web.pornhub.org",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
            "CS Sigma Rules: Wow6432Node CurrentVersion Autorun Keys Modification by Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)",
            "Remote Access Trojan"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Indonesia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "Relic",
              "display_name": "Relic",
              "target": null
            },
            {
              "id": "Win32:RATX-gen [Trj]",
              "display_name": "Win32:RATX-gen [Trj]",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            },
            {
              "id": "Ursnif",
              "display_name": "Ursnif",
              "target": null
            },
            {
              "id": "Dark Power",
              "display_name": "Dark Power",
              "target": null
            },
            {
              "id": "W32/Hupigon.NCU",
              "display_name": "W32/Hupigon.NCU",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Azorult",
              "display_name": "Azorult",
              "target": null
            },
            {
              "id": "Wiper",
              "display_name": "Wiper",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            }
          ],
          "industries": [
            "Healthcare",
            "Civil Society"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 68,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 883,
            "URL": 1412,
            "FileHash-MD5": 283,
            "FileHash-SHA1": 231,
            "FileHash-SHA256": 2909,
            "domain": 824,
            "email": 3,
            "CVE": 3
          },
          "indicator_count": 6548,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "814 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [Password cracker | Patient being tracked through multiple medical systems]",
        "https://www.hybrid-analysis.com/sample/63bf920be2401947bd686d7dd146af7f3e56800409307360105bf50cebb1c1ea",
        "http://45.159.189.105/bot/regex [ tracking | botnet]",
        "0-173-x.msn.com | https://twitter.com/PORNO_SEXYBABES | 0-3.duckdns.org | 0-212.pornhub.org | 000web.pornhub.org",
        "CS Sigma Rules: Wow6432Node CurrentVersion Autorun Keys Modification by Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)",
        "https://vtbehaviour.commondatastorage.googleapis.com/86a27baba6d32b5c6fba49e2e99864c7d0feada360b55cfc63adb4383e58be77_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778583610&Signature=f3mubmpIGOjgn7yQIqVaPC8J5mcemkwpt3Yl3noIO7eheDcS0pvTXfJfGi4WzCTHzTXgjtWE36sh%2BSHtRa%2FHFX1lvvQnPgqQpvY%2FDVlhYYVKl1nwyiZFuUZliHBmes0%2FGUhViWWRiyYHxDkn7Yj7fV7EMQqnCtlxO%2FMVJf5%2BsmjEkpk%2Frahm4sEcFERizEQtsZBKSnnp%2B1v6RFDphsiX0Ri0ZISYRqmGpmH%2FGvP2%2FQKrXXc9br",
        "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians",
        "www2.megawebfind.com [command and control]",
        "Remote Access Trojan",
        "http://ifdnzact.com/?dn=megawebdeals.com&pid=9PO755G95 [ phishing]",
        "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians/ [heuristic]",
        "Win32:RATX-gen [Trj] identified.",
        "CS Sigma Rules: Disable UAC Using Registry by frack113",
        "CS Sigma Rules: Shadow Copies Deletion Using Operating Systems Utilities by Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades)",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
        "20.99.186.246 [exploit source]"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Virut",
            "Lumma stealer",
            "Ursnif",
            "Azorult",
            "Hacktool",
            "Dark power",
            "Ransomware",
            "Cobalt strike",
            "Relic",
            "Tulach",
            "Lockbit",
            "Wiper",
            "Win32:ratx-gen [trj]",
            "W32/hupigon.ncu"
          ],
          "industries": [
            "Civil society",
            "Healthcare"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "6a030a7e7af998b0bc50d255",
      "name": "Inbox Termination Flood VirusTotal report                    for download.rar",
      "description": "[Malicious: Rar.rar (Rar!S8:z}b), a free archive that can be downloaded via 7Zip or 7zip, for use in the Windows operating system.] This email has vast capbilities, some of the best are email flooding, retrieval, destruction, extraction, tasks and more. This email on 6/3/25 led a client into a wormhole that they never actually got the delievery of it. Just the compliance locked email that destroyed their identity. It appears the temp folder that housed in malicious scripts was made months prior. I could not upload the Cape sandbox. Bundled 58, dropped 58, ensuring you will never get your life back.",
      "modified": "2026-05-12T11:49:25.043000",
      "created": "2026-05-12T11:09:50.783000",
      "tags": [
        "file type",
        "crlf line",
        "ascii text",
        "unicode text",
        "utf8 text",
        "html document",
        "json",
        "python script",
        "mitre attack",
        "network info",
        "window",
        "next",
        "flood email",
        "drops prompts",
        "malicious",
        "illegal",
        "gov",
        "crosstenant",
        "prepared months before in temp folder"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/86a27baba6d32b5c6fba49e2e99864c7d0feada360b55cfc63adb4383e58be77_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778583610&Signature=f3mubmpIGOjgn7yQIqVaPC8J5mcemkwpt3Yl3noIO7eheDcS0pvTXfJfGi4WzCTHzTXgjtWE36sh%2BSHtRa%2FHFX1lvvQnPgqQpvY%2FDVlhYYVKl1nwyiZFuUZliHBmes0%2FGUhViWWRiyYHxDkn7Yj7fV7EMQqnCtlxO%2FMVJf5%2BsmjEkpk%2Frahm4sEcFERizEQtsZBKSnnp%2B1v6RFDphsiX0Ri0ZISYRqmGpmH%2FGvP2%2FQKrXXc9br"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8,
        "FileHash-SHA1": 8,
        "FileHash-SHA256": 212,
        "IPv4": 77,
        "URL": 398,
        "domain": 503,
        "hostname": 347,
        "email": 4
      },
      "indicator_count": 1557,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "19 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65c3bd803f15cd94aab6e287",
      "name": "Lumma Stealer | Colorado Medical Center HCA",
      "description": "Needs further investigation. Miscellaneous attack affecting Denver physicians directory. Visitors accessing the page using insecure devices may be affected. PII & PHI breached. Monitoring.",
      "modified": "2024-03-08T17:04:03.644000",
      "created": "2024-02-07T17:27:28.349000",
      "tags": [
        "whois record",
        "ssl certificate",
        "contacted",
        "historical ssl",
        "referrer",
        "execution",
        "resolutions",
        "problems",
        "siblings domain",
        "whois whois",
        "startpage",
        "httponly",
        "samesitenone",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "language",
        "html document",
        "unicode text",
        "utf8 text",
        "doctype",
        "anchor hrefs",
        "hrefs",
        "denver",
        "tsara brashears",
        "apple ios",
        "password bypass",
        "apple phone",
        "unlocker",
        "shell code",
        "script",
        "contacted urls",
        "hacktool",
        "malicious",
        "download",
        "malware",
        "relic",
        "monitoring",
        "domains",
        "eurodns sa",
        "markmonitor",
        "ip detections",
        "country",
        "graph",
        "https",
        "mitre att",
        "ta0007 network",
        "t1046 sends",
        "ssdp",
        "command",
        "control ta0011",
        "protocol t1071",
        "performs dns",
        "layer protocol",
        "number",
        "cus cndigicert",
        "ja3s",
        "subject",
        "sha2 secure",
        "server ca",
        "odigicert inc",
        "cus cnmicrosoft",
        "algorithm",
        "memory pattern",
        "file system",
        "registry",
        "registry keys",
        "process",
        "created",
        "processes tree",
        "february",
        "healthone",
        "gmbh version",
        "status page",
        "service privacy",
        "legal",
        "impressum",
        "url https",
        "reverse dns",
        "general full",
        "security tls",
        "protocol h2",
        "software",
        "frankfurt",
        "main",
        "germany",
        "resource hash",
        "de indicators",
        "hashes",
        "value",
        "scriptsrcelem",
        "variables",
        "boomrmq string",
        "boomrapikey",
        "boomr function",
        "system",
        "babelpolyfill",
        "assign function",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "aes256gcm",
        "level",
        "akamaiasn1",
        "europeberlin",
        "generic malware",
        "tag count",
        "tue dec",
        "threat report",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "root ca",
        "pattern match",
        "authority",
        "span",
        "presbyterianst",
        "luke",
        "medical center",
        "class",
        "accept",
        "date",
        "refresh",
        "blood",
        "liver cancer",
        "breast cancer",
        "lung cancer",
        "kidney cancer",
        "skin cancer",
        "sarcoma",
        "prostate cancer",
        "body",
        "facebook",
        "twitter",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "error",
        "tools",
        "look",
        "verify",
        "restart",
        "cookie",
        "command and control",
        "mitre",
        "scanning host",
        "exploit source",
        "trojan",
        "callback function",
        "targets",
        "targeting",
        "samesite=none",
        "kde",
        "konqueror",
        "phi",
        "pii",
        "wTJh.exe",
        "malware ransom trojan evader rat",
        "network",
        "rat trojan",
        "relacionada",
        "critical risk",
        "cyberstalking",
        "elf collection",
        "matches rule",
        "emotet",
        "lockbit",
        "critical",
        "copy",
        "installer",
        "dark power",
        "wiper",
        "ransomware",
        "cobalt strike",
        "ursnif",
        "core",
        "as55688 pt",
        "passive dns",
        "scan endpoints",
        "all octoseek",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "asn as55688",
        "threat",
        "paste",
        "iocs",
        "analyze",
        "hostnames",
        "united",
        "aaaa",
        "unknown",
        "a domains",
        "search",
        "creation date",
        "record value",
        "next",
        "pornhub",
        "anyxxxtube",
        "domain",
        "gandi sas",
        "hostname",
        "basic",
        "pe32",
        "intel",
        "ms windows",
        "generic windos",
        "executable",
        "dos executable",
        "generic",
        "pe32 packer",
        "petite",
        "vs98",
        "info compiler",
        "products",
        "header intel",
        "name md5",
        "type",
        "rticon neutral",
        "overlay",
        "dos exe",
        "threat roundup",
        "pe resource",
        "june",
        "lumma stealer",
        "ransomexx",
        "azorult",
        "njrat",
        "open",
        "problem",
        "plugx",
        "android",
        "sex_phot.jpg.exe",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "delphi generic",
        "icons library",
        "pe32 linker",
        "lcc linker",
        "empty hash",
        "tulach",
        "sabey",
        "rat",
        "remote",
        "remote access trojan"
      ],
      "references": [
        "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians",
        "https://www.hybrid-analysis.com/sample/63bf920be2401947bd686d7dd146af7f3e56800409307360105bf50cebb1c1ea",
        "www2.megawebfind.com [command and control]",
        "http://ifdnzact.com/?dn=megawebdeals.com&pid=9PO755G95 [ phishing]",
        "20.99.186.246 [exploit source]",
        "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians/ [heuristic]",
        "Win32:RATX-gen [Trj] identified.",
        "CS Sigma Rules: Shadow Copies Deletion Using Operating Systems Utilities by Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades)",
        "CS Sigma Rules: Disable UAC Using Registry by frack113",
        "http://45.159.189.105/bot/regex [ tracking | botnet]",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [Password cracker | Patient being tracked through multiple medical systems]",
        "0-173-x.msn.com | https://twitter.com/PORNO_SEXYBABES | 0-3.duckdns.org | 0-212.pornhub.org | 000web.pornhub.org",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
        "CS Sigma Rules: Wow6432Node CurrentVersion Autorun Keys Modification by Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)",
        "Remote Access Trojan"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Indonesia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "Relic",
          "display_name": "Relic",
          "target": null
        },
        {
          "id": "Win32:RATX-gen [Trj]",
          "display_name": "Win32:RATX-gen [Trj]",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "LockBit",
          "display_name": "LockBit",
          "target": null
        },
        {
          "id": "Ursnif",
          "display_name": "Ursnif",
          "target": null
        },
        {
          "id": "Dark Power",
          "display_name": "Dark Power",
          "target": null
        },
        {
          "id": "W32/Hupigon.NCU",
          "display_name": "W32/Hupigon.NCU",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "Azorult",
          "display_name": "Azorult",
          "target": null
        },
        {
          "id": "Wiper",
          "display_name": "Wiper",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        }
      ],
      "industries": [
        "Healthcare",
        "Civil Society"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 68,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 883,
        "URL": 1412,
        "FileHash-MD5": 283,
        "FileHash-SHA1": 231,
        "FileHash-SHA256": 2909,
        "domain": 824,
        "email": 3,
        "CVE": 3
      },
      "indicator_count": 6548,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "814 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "webserver.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "webserver.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780301921.6308074
}