{
  "type": "Domain",
  "indicator": "yeukitty.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/yeukitty.com",
    "alexa": "http://www.alexa.com/siteinfo/yeukitty.com",
    "indicator": "yeukitty.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3774543406,
      "indicator": "yeukitty.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "65c55ae268b5c4556694db9f",
          "name": "CapsaciPhone.com | Found in Denver Recording Studio Domain",
          "description": "Emotet,\nLockBit,\nMakop,\nRedLine Stealer,",
          "modified": "2024-03-09T22:05:06.644000",
          "created": "2024-02-08T22:51:14.111000",
          "tags": [
            "contacted",
            "december",
            "dropped",
            "cymulate",
            "url collection",
            "execution",
            "ssl certificate",
            "roundup",
            "threat roundup",
            "unknown",
            "a domains",
            "domain",
            "creation date",
            "search",
            "tnhh quan",
            "dau tu",
            "dat ngoc",
            "date",
            "showing",
            "body",
            "next",
            "nxdomain",
            "record type",
            "ttl value",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "issuer",
            "cbe cnalphassl",
            "sha256",
            "g2 oglobalsign",
            "validity",
            "public key",
            "info",
            "email",
            "code",
            "server",
            "registrar abuse",
            "available from",
            "country",
            "cong ty",
            "porn",
            "referrer",
            "whois record",
            "historical ssl",
            "resolutions",
            "urls http",
            "malware",
            "lockbit",
            "makop",
            "redline stealer",
            "core",
            "iframe",
            "whois whois",
            "maliciosa",
            "relacionada con",
            "january",
            "february",
            "attack",
            "bitrat",
            "hacktool",
            "malicious",
            "emotet",
            "wide"
          ],
          "references": [
            "capsaciphone.com",
            "nr-data.net. [Apple Private Data Collection]",
            "15b7e1434ba582ab85f7d7783093522e4bbae83b1f24a6388cd51852aa3d8aba bam [nr-data.net -apple data collection (new relic)]",
            "http://vortex-nlb-http2-fed-us-taut-purple.nr-data.net/        [nr-data.net -apple data collection (new relic)]",
            "www.pornhub.com [iOS password decryption]",
            "www.anyxxxtube.net",
            "https://www.anyxxxtube.net/search-porn/a-m-c-ate-xxx-videos/",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "golddesisex.com",
            "websexgay.net",
            "http://golddesisex.com/en/search/xxx-bloody-hymen",
            "http://golddesisex.com/en/search/boob-licking-gifs",
            "http://173.255.214.126:8080/oMhELssex",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "https://d500.userdrive.me/d/3wj67osl2as5ln23p3io5gjrhoxma3o42ioy2hjvs3dctulo5j76ugf7njke2nse6jzyjhra/Ableton-Live-Suite-2011.3.13%20+%20_-_gen.zip",
            "Found in https://side3.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            },
            {
              "id": "Makop",
              "display_name": "Makop",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 34,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 939,
            "URL": 5397,
            "FileHash-MD5": 78,
            "FileHash-SHA1": 78,
            "FileHash-SHA256": 2224,
            "hostname": 1294,
            "email": 3,
            "CVE": 3
          },
          "indicator_count": 10016,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "815 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65333dffc82990767f6982f6",
          "name": "CVE-2014-0514",
          "description": "The following is the full text of the report on the Adobe Reader vulnerability (CVE-2014-0514), compiled by the University of California, San Francisco, and published on 1 October 2017.",
          "modified": "2023-11-20T03:02:27.506000",
          "created": "2023-10-21T02:57:03.220000",
          "tags": [
            "adobe reader",
            "android",
            "javascript",
            "misc http",
            "scan endpoints",
            "all cve",
            "ellenmmm cve",
            "cve20140514 add",
            "new pulse",
            "existing pulse"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ellenmmm",
            "id": "233693",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 5,
            "URL": 134,
            "hostname": 307,
            "domain": 381,
            "FileHash-SHA256": 7111,
            "FileHash-MD5": 1474,
            "FileHash-SHA1": 1441,
            "SSLCertFingerprint": 4,
            "email": 18
          },
          "indicator_count": 10875,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 82,
          "modified_text": "925 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "http://vortex-nlb-http2-fed-us-taut-purple.nr-data.net/        [nr-data.net -apple data collection (new relic)]",
        "http://173.255.214.126:8080/oMhELssex",
        "nr-data.net. [Apple Private Data Collection]",
        "https://d500.userdrive.me/d/3wj67osl2as5ln23p3io5gjrhoxma3o42ioy2hjvs3dctulo5j76ugf7njke2nse6jzyjhra/Ableton-Live-Suite-2011.3.13%20+%20_-_gen.zip",
        "Found in https://side3.com",
        "www.pornhub.com [iOS password decryption]",
        "http://golddesisex.com/en/search/xxx-bloody-hymen",
        "websexgay.net",
        "http://golddesisex.com/en/search/boob-licking-gifs",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "www.anyxxxtube.net",
        "capsaciphone.com",
        "15b7e1434ba582ab85f7d7783093522e4bbae83b1f24a6388cd51852aa3d8aba bam [nr-data.net -apple data collection (new relic)]",
        "https://www.anyxxxtube.net/search-porn/a-m-c-ate-xxx-videos/",
        "golddesisex.com"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Redline stealer",
            "Emotet",
            "Lockbit",
            "Makop"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "65c55ae268b5c4556694db9f",
      "name": "CapsaciPhone.com | Found in Denver Recording Studio Domain",
      "description": "Emotet,\nLockBit,\nMakop,\nRedLine Stealer,",
      "modified": "2024-03-09T22:05:06.644000",
      "created": "2024-02-08T22:51:14.111000",
      "tags": [
        "contacted",
        "december",
        "dropped",
        "cymulate",
        "url collection",
        "execution",
        "ssl certificate",
        "roundup",
        "threat roundup",
        "unknown",
        "a domains",
        "domain",
        "creation date",
        "search",
        "tnhh quan",
        "dau tu",
        "dat ngoc",
        "date",
        "showing",
        "body",
        "next",
        "nxdomain",
        "record type",
        "ttl value",
        "algorithm",
        "data",
        "v3 serial",
        "number",
        "issuer",
        "cbe cnalphassl",
        "sha256",
        "g2 oglobalsign",
        "validity",
        "public key",
        "info",
        "email",
        "code",
        "server",
        "registrar abuse",
        "available from",
        "country",
        "cong ty",
        "porn",
        "referrer",
        "whois record",
        "historical ssl",
        "resolutions",
        "urls http",
        "malware",
        "lockbit",
        "makop",
        "redline stealer",
        "core",
        "iframe",
        "whois whois",
        "maliciosa",
        "relacionada con",
        "january",
        "february",
        "attack",
        "bitrat",
        "hacktool",
        "malicious",
        "emotet",
        "wide"
      ],
      "references": [
        "capsaciphone.com",
        "nr-data.net. [Apple Private Data Collection]",
        "15b7e1434ba582ab85f7d7783093522e4bbae83b1f24a6388cd51852aa3d8aba bam [nr-data.net -apple data collection (new relic)]",
        "http://vortex-nlb-http2-fed-us-taut-purple.nr-data.net/        [nr-data.net -apple data collection (new relic)]",
        "www.pornhub.com [iOS password decryption]",
        "www.anyxxxtube.net",
        "https://www.anyxxxtube.net/search-porn/a-m-c-ate-xxx-videos/",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "golddesisex.com",
        "websexgay.net",
        "http://golddesisex.com/en/search/xxx-bloody-hymen",
        "http://golddesisex.com/en/search/boob-licking-gifs",
        "http://173.255.214.126:8080/oMhELssex",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "https://d500.userdrive.me/d/3wj67osl2as5ln23p3io5gjrhoxma3o42ioy2hjvs3dctulo5j76ugf7njke2nse6jzyjhra/Ableton-Live-Suite-2011.3.13%20+%20_-_gen.zip",
        "Found in https://side3.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "LockBit",
          "display_name": "LockBit",
          "target": null
        },
        {
          "id": "Makop",
          "display_name": "Makop",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 34,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 939,
        "URL": 5397,
        "FileHash-MD5": 78,
        "FileHash-SHA1": 78,
        "FileHash-SHA256": 2224,
        "hostname": 1294,
        "email": 3,
        "CVE": 3
      },
      "indicator_count": 10016,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "815 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65333dffc82990767f6982f6",
      "name": "CVE-2014-0514",
      "description": "The following is the full text of the report on the Adobe Reader vulnerability (CVE-2014-0514), compiled by the University of California, San Francisco, and published on 1 October 2017.",
      "modified": "2023-11-20T03:02:27.506000",
      "created": "2023-10-21T02:57:03.220000",
      "tags": [
        "adobe reader",
        "android",
        "javascript",
        "misc http",
        "scan endpoints",
        "all cve",
        "ellenmmm cve",
        "cve20140514 add",
        "new pulse",
        "existing pulse"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "ellenmmm",
        "id": "233693",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 5,
        "URL": 134,
        "hostname": 307,
        "domain": 381,
        "FileHash-SHA256": 7111,
        "FileHash-MD5": 1474,
        "FileHash-SHA1": 1441,
        "SSLCertFingerprint": 4,
        "email": 18
      },
      "indicator_count": 10875,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 82,
      "modified_text": "925 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "yeukitty.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "yeukitty.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780444728.4298682
}