{
  "type": "Domain",
  "indicator": "worldhealthbasicinfo.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/worldhealthbasicinfo.com",
    "alexa": "http://www.alexa.com/siteinfo/worldhealthbasicinfo.com",
    "indicator": "worldhealthbasicinfo.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2236822727,
      "indicator": "worldhealthbasicinfo.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 11,
      "pulses": [
        {
          "id": "617af11f370d993aeff26e71",
          "name": "Kaseya VSA REvil Indicators",
          "description": "",
          "modified": "2025-08-25T16:22:33.668000",
          "created": "2021-10-28T18:51:11.197000",
          "tags": [
            "REvil",
            "Kaseya",
            "VSA Server",
            "ransomware"
          ],
          "references": [
            "https://www.virustotal.com/gui/file/d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e/details",
            "https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers",
            "https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-200-companies-in-msp-supply-chain-attack/",
            "https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b",
            "https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/",
            "https://gist.github.com/fwosar/a63e1249bfccb8395b961d3d780c0354",
            "https://docs.google.com/spreadsheets/d/11AFPdK5A-7g484lfc0HmXdBrZpYI-Jhx4N1VwFXrcrQ/edit#gid=1201846661",
            "https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident?utm_campaign=CY21-Q3-RapidResponse-KaseyaVSA&utm_medium=email&_hsmi=138021297&_hsenc=p2ANqtz--HvqdKyS4A0PNoXQXXy44zns31VXVSOFaz97KXwFQMvl-wiRhktYL4l036tl-r5zmeY3RRVzgz2GqtktDCLPLQ8gB8vg&utm_content=138021297&utm_source=hs_email",
            "https://github.com/Neo23x0/signature-base/blob/master/yara/crime_revil_general.yar"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "REvil",
              "display_name": "REvil",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "60df80a7a665c1dd6baf7753",
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "VertekLabs",
            "id": "168455",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_168455/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 15,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 16,
            "URL": 1,
            "domain": 1177,
            "hostname": 5,
            "YARA": 4
          },
          "indicator_count": 1233,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 564,
          "modified_text": "278 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707c3be05f3a7ea9e654d4",
          "name": "Kaseya VSA REvil Indicators",
          "description": "",
          "modified": "2023-12-06T13:50:51.719000",
          "created": "2023-12-06T13:50:51.719000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 15,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 16,
            "URL": 1,
            "domain": 1178,
            "hostname": 5,
            "YARA": 4
          },
          "indicator_count": 1234,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707bedc2fbc934427f325c",
          "name": "Kaseya VSA REvil Indicators",
          "description": "",
          "modified": "2023-12-06T13:49:33.291000",
          "created": "2023-12-06T13:49:33.291000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 15,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 16,
            "URL": 1,
            "domain": 1179,
            "hostname": 5,
            "YARA": 4
          },
          "indicator_count": 1235,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64a27a551c9c6749a071a42a",
          "name": "Threat Intel Report - W27-2023",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2023-08-02T07:04:23.763000",
          "created": "2023-07-03T07:35:49.564000",
          "tags": [],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 13,
            "URL": 101,
            "domain": 27,
            "hostname": 56
          },
          "indicator_count": 203,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 108,
          "modified_text": "1033 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6458d0d70538e4954d72da72",
          "name": "Threat Intel Report - W19-2023",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2023-05-08T10:37:11.710000",
          "created": "2023-05-08T10:37:11.710000",
          "tags": [
            "kimsuky",
            "cactus",
            "akira",
            "workstation",
            "fusion software",
            "cvss",
            "cvss base",
            "vmware",
            "microsoft azure",
            "api management",
            "new android",
            "zyxel firewall",
            "code execution",
            "patch",
            "april",
            "terminal",
            "hashes domains",
            "russia",
            "ip address",
            "blacklist host",
            "ip country",
            "latest spambot",
            "visit",
            "activity",
            "germany",
            "india",
            "guatemala",
            "quakbot",
            "redlinestealer",
            "privateloader",
            "date",
            "malware url",
            "tags",
            "smokeloader",
            "bertnit",
            "sha1 file",
            "name submit"
          ],
          "references": [
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time",
            "https://www.dnsbl.info/",
            "https://psbl.org/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Akira",
              "display_name": "Akira",
              "target": null
            },
            {
              "id": "Cactus",
              "display_name": "Cactus",
              "target": null
            },
            {
              "id": "Kimsuky",
              "display_name": "Kimsuky",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Financial",
            "Banking"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 47,
            "FileHash-SHA1": 47,
            "FileHash-SHA256": 142,
            "IPv4": 73,
            "URL": 111,
            "domain": 116,
            "hostname": 44,
            "CVE": 1
          },
          "indicator_count": 581,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "1119 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63a01d5249897d1ce5fcc4c1",
          "name": "Threat Intel Report - W52-2022.pdf",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2023-01-18T08:00:04.374000",
          "created": "2022-12-19T08:14:10.713000",
          "tags": [
            "united"
          ],
          "references": [
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_ Real-time",
            "https://www.dnsbl.info/",
            "https://www.spamhaus.org/xbl/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 46,
            "domain": 106,
            "hostname": 53,
            "CVE": 2,
            "FileHash-MD5": 7,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 12
          },
          "indicator_count": 233,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 107,
          "modified_text": "1229 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63a01d55919d8c212243d1b3",
          "name": "Threat Intel Report - W52-2022.pdf",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2023-01-18T08:00:04.374000",
          "created": "2022-12-19T08:14:13.536000",
          "tags": [
            "united"
          ],
          "references": [
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_ Real-time",
            "https://www.dnsbl.info/",
            "https://www.spamhaus.org/xbl/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 46,
            "domain": 106,
            "hostname": 53,
            "CVE": 2,
            "FileHash-MD5": 7,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 12
          },
          "indicator_count": 233,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 107,
          "modified_text": "1229 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6317137bd474b32c0162c595",
          "name": "Threat Intel Report - W37-2022",
          "description": "",
          "modified": "2022-10-06T00:00:46.407000",
          "created": "2022-09-06T09:31:39.761000",
          "tags": [],
          "references": [
            "TechM-Threat Intel Report - W37-2022.pdf"
          ],
          "public": 1,
          "adversary": "Threat Intel Report - W37-2022",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 59,
            "hostname": 58,
            "URL": 71,
            "FileHash-MD5": 8,
            "FileHash-SHA1": 9,
            "FileHash-SHA256": 14,
            "CVE": 1
          },
          "indicator_count": 220,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "1333 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6211d35c9626605ef7c962d1",
          "name": "Zloader Malware Analysis, Overview by ANY.RUN",
          "description": "Zloader is a banking trojan that uses webinjects and VNC clients to steal the passwords of its victims, but has seen a surge in activity since its first appearance in 2016.",
          "modified": "2022-03-22T00:00:12.890000",
          "created": "2022-02-20T05:36:28.754000",
          "tags": [
            "remote access",
            "zeus",
            "zeus banking",
            "zloader",
            "agent tesla",
            "ave maria",
            "warzone",
            "danabot",
            "zloader malware",
            "hancitor",
            "march",
            "command",
            "terdot",
            "zbot",
            "zeus malware",
            "zeus code",
            "researchers",
            "trojan",
            "loader",
            "panda banker",
            "flawedammyy"
          ],
          "references": [
            "https://any.run/malware-trends/zloader"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "Canada"
          ],
          "malware_families": [
            {
              "id": "Remote Access",
              "display_name": "Remote Access",
              "target": null
            },
            {
              "id": "Danabot",
              "display_name": "Danabot",
              "target": null
            },
            {
              "id": "WARZONE",
              "display_name": "WARZONE",
              "target": null
            },
            {
              "id": "Ave Maria",
              "display_name": "Ave Maria",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "Zloader",
              "display_name": "Zloader",
              "target": null
            },
            {
              "id": "Zeus Banking",
              "display_name": "Zeus Banking",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            }
          ],
          "industries": [
            "Military",
            "Banking",
            "Financial"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "santhosh.kumar",
            "id": "175772",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 15,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 21,
            "URL": 1,
            "domain": 12,
            "hostname": 9
          },
          "indicator_count": 73,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 49,
          "modified_text": "1531 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62257e5ead7f907ae5b1e394",
          "name": "Sodinkibi_Rasomware",
          "description": "Rasomwares detectados en base a dominios, en su mayor\u00eda tienen como actor Sodin",
          "modified": "2022-03-07T03:39:10.696000",
          "created": "2022-03-07T03:39:10.696000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "kant0017",
            "id": "183806",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 22,
            "hostname": 1
          },
          "indicator_count": 23,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 6,
          "modified_text": "1546 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "60df80a7a665c1dd6baf7753",
          "name": "Kaseya VSA REvil Indicators",
          "description": "",
          "modified": "2022-02-18T14:52:05.251000",
          "created": "2021-07-02T21:09:59.361000",
          "tags": [
            "REvil",
            "Kaseya",
            "VSA Server",
            "ransomware"
          ],
          "references": [
            "https://www.virustotal.com/gui/file/d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e/details",
            "https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers",
            "https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-200-companies-in-msp-supply-chain-attack/",
            "https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b",
            "https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/",
            "https://gist.github.com/fwosar/a63e1249bfccb8395b961d3d780c0354",
            "https://docs.google.com/spreadsheets/d/11AFPdK5A-7g484lfc0HmXdBrZpYI-Jhx4N1VwFXrcrQ/edit#gid=1201846661",
            "https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident?utm_campaign=CY21-Q3-RapidResponse-KaseyaVSA&utm_medium=email&_hsmi=138021297&_hsenc=p2ANqtz--HvqdKyS4A0PNoXQXXy44zns31VXVSOFaz97KXwFQMvl-wiRhktYL4l036tl-r5zmeY3RRVzgz2GqtktDCLPLQ8gB8vg&utm_content=138021297&utm_source=hs_email",
            "https://github.com/Neo23x0/signature-base/blob/master/yara/crime_revil_general.yar"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "REvil",
              "display_name": "REvil",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 63,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "vthelpdesk",
            "id": "1766",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_1766/resized/80/avatar_0be7a35fab.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 15,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 16,
            "URL": 1,
            "domain": 1179,
            "hostname": 5,
            "YARA": 4
          },
          "indicator_count": 1235,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 624,
          "modified_text": "1562 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://docs.google.com/spreadsheets/d/11AFPdK5A-7g484lfc0HmXdBrZpYI-Jhx4N1VwFXrcrQ/edit#gid=1201846661",
        "https://urlhaus.abuse.ch/browse/",
        "https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident?utm_campaign=CY21-Q3-RapidResponse-KaseyaVSA&utm_medium=email&_hsmi=138021297&_hsenc=p2ANqtz--HvqdKyS4A0PNoXQXXy44zns31VXVSOFaz97KXwFQMvl-wiRhktYL4l036tl-r5zmeY3RRVzgz2GqtktDCLPLQ8gB8vg&utm_content=138021297&utm_source=hs_email",
        "https://any.run/malware-trends/zloader",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_ Real-time",
        "https://www.virustotal.com/gui/file/d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e/details",
        "https://gist.github.com/fwosar/a63e1249bfccb8395b961d3d780c0354",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time",
        "https://github.com/Neo23x0/signature-base/blob/master/yara/crime_revil_general.yar",
        "https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers",
        "https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/",
        "https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-200-companies-in-msp-supply-chain-attack/",
        "https://www.dnsbl.info/",
        "https://www.spamhaus.org/xbl/",
        "TechM-Threat Intel Report - W37-2022.pdf",
        "https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b",
        "https://psbl.org/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Threat Intel Report - W37-2022"
          ],
          "malware_families": [
            "Akira",
            "Ave maria",
            "Zeus banking",
            "Zloader",
            "Kimsuky",
            "Remote access",
            "Agent tesla",
            "Cactus",
            "Danabot",
            "Revil",
            "Warzone",
            "Zeus"
          ],
          "industries": [
            "Banking",
            "Financial",
            "Military"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 11,
  "pulses": [
    {
      "id": "617af11f370d993aeff26e71",
      "name": "Kaseya VSA REvil Indicators",
      "description": "",
      "modified": "2025-08-25T16:22:33.668000",
      "created": "2021-10-28T18:51:11.197000",
      "tags": [
        "REvil",
        "Kaseya",
        "VSA Server",
        "ransomware"
      ],
      "references": [
        "https://www.virustotal.com/gui/file/d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e/details",
        "https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers",
        "https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-200-companies-in-msp-supply-chain-attack/",
        "https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b",
        "https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/",
        "https://gist.github.com/fwosar/a63e1249bfccb8395b961d3d780c0354",
        "https://docs.google.com/spreadsheets/d/11AFPdK5A-7g484lfc0HmXdBrZpYI-Jhx4N1VwFXrcrQ/edit#gid=1201846661",
        "https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident?utm_campaign=CY21-Q3-RapidResponse-KaseyaVSA&utm_medium=email&_hsmi=138021297&_hsenc=p2ANqtz--HvqdKyS4A0PNoXQXXy44zns31VXVSOFaz97KXwFQMvl-wiRhktYL4l036tl-r5zmeY3RRVzgz2GqtktDCLPLQ8gB8vg&utm_content=138021297&utm_source=hs_email",
        "https://github.com/Neo23x0/signature-base/blob/master/yara/crime_revil_general.yar"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "REvil",
          "display_name": "REvil",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "60df80a7a665c1dd6baf7753",
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "VertekLabs",
        "id": "168455",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_168455/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 15,
        "FileHash-SHA1": 15,
        "FileHash-SHA256": 16,
        "URL": 1,
        "domain": 1177,
        "hostname": 5,
        "YARA": 4
      },
      "indicator_count": 1233,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 564,
      "modified_text": "278 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707c3be05f3a7ea9e654d4",
      "name": "Kaseya VSA REvil Indicators",
      "description": "",
      "modified": "2023-12-06T13:50:51.719000",
      "created": "2023-12-06T13:50:51.719000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 15,
        "FileHash-SHA1": 15,
        "FileHash-SHA256": 16,
        "URL": 1,
        "domain": 1178,
        "hostname": 5,
        "YARA": 4
      },
      "indicator_count": 1234,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707bedc2fbc934427f325c",
      "name": "Kaseya VSA REvil Indicators",
      "description": "",
      "modified": "2023-12-06T13:49:33.291000",
      "created": "2023-12-06T13:49:33.291000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 15,
        "FileHash-SHA1": 15,
        "FileHash-SHA256": 16,
        "URL": 1,
        "domain": 1179,
        "hostname": 5,
        "YARA": 4
      },
      "indicator_count": 1235,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "64a27a551c9c6749a071a42a",
      "name": "Threat Intel Report - W27-2023",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2023-08-02T07:04:23.763000",
      "created": "2023-07-03T07:35:49.564000",
      "tags": [],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 3,
        "FileHash-SHA1": 3,
        "FileHash-SHA256": 13,
        "URL": 101,
        "domain": 27,
        "hostname": 56
      },
      "indicator_count": 203,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 108,
      "modified_text": "1033 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6458d0d70538e4954d72da72",
      "name": "Threat Intel Report - W19-2023",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2023-05-08T10:37:11.710000",
      "created": "2023-05-08T10:37:11.710000",
      "tags": [
        "kimsuky",
        "cactus",
        "akira",
        "workstation",
        "fusion software",
        "cvss",
        "cvss base",
        "vmware",
        "microsoft azure",
        "api management",
        "new android",
        "zyxel firewall",
        "code execution",
        "patch",
        "april",
        "terminal",
        "hashes domains",
        "russia",
        "ip address",
        "blacklist host",
        "ip country",
        "latest spambot",
        "visit",
        "activity",
        "germany",
        "india",
        "guatemala",
        "quakbot",
        "redlinestealer",
        "privateloader",
        "date",
        "malware url",
        "tags",
        "smokeloader",
        "bertnit",
        "sha1 file",
        "name submit"
      ],
      "references": [
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time",
        "https://www.dnsbl.info/",
        "https://psbl.org/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Akira",
          "display_name": "Akira",
          "target": null
        },
        {
          "id": "Cactus",
          "display_name": "Cactus",
          "target": null
        },
        {
          "id": "Kimsuky",
          "display_name": "Kimsuky",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Financial",
        "Banking"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 47,
        "FileHash-SHA1": 47,
        "FileHash-SHA256": 142,
        "IPv4": 73,
        "URL": 111,
        "domain": 116,
        "hostname": 44,
        "CVE": 1
      },
      "indicator_count": 581,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "1119 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63a01d5249897d1ce5fcc4c1",
      "name": "Threat Intel Report - W52-2022.pdf",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2023-01-18T08:00:04.374000",
      "created": "2022-12-19T08:14:10.713000",
      "tags": [
        "united"
      ],
      "references": [
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_ Real-time",
        "https://www.dnsbl.info/",
        "https://www.spamhaus.org/xbl/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 46,
        "domain": 106,
        "hostname": 53,
        "CVE": 2,
        "FileHash-MD5": 7,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 12
      },
      "indicator_count": 233,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 107,
      "modified_text": "1229 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63a01d55919d8c212243d1b3",
      "name": "Threat Intel Report - W52-2022.pdf",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2023-01-18T08:00:04.374000",
      "created": "2022-12-19T08:14:13.536000",
      "tags": [
        "united"
      ],
      "references": [
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_ Real-time",
        "https://www.dnsbl.info/",
        "https://www.spamhaus.org/xbl/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 46,
        "domain": 106,
        "hostname": 53,
        "CVE": 2,
        "FileHash-MD5": 7,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 12
      },
      "indicator_count": 233,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 107,
      "modified_text": "1229 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6317137bd474b32c0162c595",
      "name": "Threat Intel Report - W37-2022",
      "description": "",
      "modified": "2022-10-06T00:00:46.407000",
      "created": "2022-09-06T09:31:39.761000",
      "tags": [],
      "references": [
        "TechM-Threat Intel Report - W37-2022.pdf"
      ],
      "public": 1,
      "adversary": "Threat Intel Report - W37-2022",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 59,
        "hostname": 58,
        "URL": 71,
        "FileHash-MD5": 8,
        "FileHash-SHA1": 9,
        "FileHash-SHA256": 14,
        "CVE": 1
      },
      "indicator_count": 220,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "1333 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6211d35c9626605ef7c962d1",
      "name": "Zloader Malware Analysis, Overview by ANY.RUN",
      "description": "Zloader is a banking trojan that uses webinjects and VNC clients to steal the passwords of its victims, but has seen a surge in activity since its first appearance in 2016.",
      "modified": "2022-03-22T00:00:12.890000",
      "created": "2022-02-20T05:36:28.754000",
      "tags": [
        "remote access",
        "zeus",
        "zeus banking",
        "zloader",
        "agent tesla",
        "ave maria",
        "warzone",
        "danabot",
        "zloader malware",
        "hancitor",
        "march",
        "command",
        "terdot",
        "zbot",
        "zeus malware",
        "zeus code",
        "researchers",
        "trojan",
        "loader",
        "panda banker",
        "flawedammyy"
      ],
      "references": [
        "https://any.run/malware-trends/zloader"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Australia",
        "Canada"
      ],
      "malware_families": [
        {
          "id": "Remote Access",
          "display_name": "Remote Access",
          "target": null
        },
        {
          "id": "Danabot",
          "display_name": "Danabot",
          "target": null
        },
        {
          "id": "WARZONE",
          "display_name": "WARZONE",
          "target": null
        },
        {
          "id": "Ave Maria",
          "display_name": "Ave Maria",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "Zloader",
          "display_name": "Zloader",
          "target": null
        },
        {
          "id": "Zeus Banking",
          "display_name": "Zeus Banking",
          "target": null
        },
        {
          "id": "ZeuS",
          "display_name": "ZeuS",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        }
      ],
      "industries": [
        "Military",
        "Banking",
        "Financial"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "santhosh.kumar",
        "id": "175772",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 15,
        "FileHash-SHA1": 15,
        "FileHash-SHA256": 21,
        "URL": 1,
        "domain": 12,
        "hostname": 9
      },
      "indicator_count": 73,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 49,
      "modified_text": "1531 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62257e5ead7f907ae5b1e394",
      "name": "Sodinkibi_Rasomware",
      "description": "Rasomwares detectados en base a dominios, en su mayor\u00eda tienen como actor Sodin",
      "modified": "2022-03-07T03:39:10.696000",
      "created": "2022-03-07T03:39:10.696000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "kant0017",
        "id": "183806",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 22,
        "hostname": 1
      },
      "indicator_count": 23,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 6,
      "modified_text": "1546 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "worldhealthbasicinfo.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "worldhealthbasicinfo.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780226918.700209
}