{
  "type": "Domain",
  "indicator": "zetalinks.tech",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/zetalinks.tech",
    "alexa": "http://www.alexa.com/siteinfo/zetalinks.tech",
    "indicator": "zetalinks.tech",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3908881465,
      "indicator": "zetalinks.tech",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 7,
      "pulses": [
        {
          "id": "6783308fc0b6e2bd8dfb209c",
          "name": "TTC-CERT_blocklist_recommended",
          "description": "",
          "modified": "2026-02-14T00:03:07.406000",
          "created": "2025-01-12T03:01:35.075000",
          "tags": [],
          "references": [
            "https://github.com/ttc-cert/TTC-CERT_blocklist_recommended/blob/master/domain_blocklist_recommended.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 606,
            "URL": 4,
            "domain": 25122,
            "hostname": 25306
          },
          "indicator_count": 51038,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 185,
          "modified_text": "106 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ba2d75ce154e1f60d7c2e5",
          "name": "Rafel RAT, Android Malware from Espionage to Ransomware Operations - Check Point Research",
          "description": "A study by security firm Check Point Research has identified a range of malicious software designed to target Android devices, and identified an espionage group using Rafel RAT to carry out such operations, as well as ransomware.",
          "modified": "2025-02-22T20:03:01.522000",
          "created": "2025-02-22T20:03:01.522000",
          "tags": [
            "android",
            "rafel rat",
            "rafel",
            "android malware",
            "check point",
            "pakistan",
            "device admin",
            "internalservice",
            "google",
            "research",
            "life",
            "loda",
            "ransom",
            "indonesia",
            "pixel",
            "nexus",
            "patch",
            "malware",
            "ransomware",
            "april",
            "threat",
            "trojans",
            "october",
            "august",
            "android version",
            "february",
            "attack"
          ],
          "references": [
            "https://research.checkpoint.com/2024/rafel-rat-android-malware-from-espionage-to-ransomware-operations/"
          ],
          "public": 1,
          "adversary": "Threat",
          "targeted_countries": [
            "United States of America",
            "China",
            "Indonesia",
            "Russian Federation",
            "Romania",
            "Pakistan"
          ],
          "malware_families": [
            {
              "id": "Trojans",
              "display_name": "Trojans",
              "target": null
            },
            {
              "id": "Android",
              "display_name": "Android",
              "target": null
            },
            {
              "id": "Threat",
              "display_name": "Threat",
              "target": null
            },
            {
              "id": "Rafel",
              "display_name": "Rafel",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [
            "Government",
            "Military"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Armature_TIP",
            "id": "308911",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_308911/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 6,
            "domain": 4
          },
          "indicator_count": 22,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 42,
          "modified_text": "462 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6654138435c5832ca2c4028f",
          "name": "DOH Domains IOCs",
          "description": "The following is a full list of items that you might not have known existed::..com, or, if you were interested in them, are the most likely ones to come up with",
          "modified": "2024-08-26T04:12:43.497000",
          "created": "2024-05-27T05:00:52.918000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fueledbycoffeeDXB",
            "id": "272228",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 7,
            "domain": 1335,
            "hostname": 667
          },
          "indicator_count": 2009,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 26,
          "modified_text": "643 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6679e1b5b2001e71bb2613a0",
          "name": "Rafel Rat: Android Malware Evolving From Espionage To Ransomware Attacks",
          "description": "Rafel RAT, an Android malware initially used for espionage but later adapted for ransomware operations. This malware, first discovered in early 2023, has undergone significant changes, expanding its functionality and becoming more versatile in its malicious activities. Initially, Rafel RAT was employed primarily for espionage, focusing on stealing sensitive information from infected devices. However, its developers have since enhanced its capabilities to include ransomware features, allowing it to encrypt files and demand ransom payments from victims.",
          "modified": "2024-06-24T21:14:29.912000",
          "created": "2024-06-24T21:14:29.912000",
          "tags": [
            "android",
            "rafel rat",
            "rafel",
            "android malware",
            "check point",
            "pakistan",
            "device admin",
            "internalservice",
            "google",
            "research",
            "life",
            "loda",
            "ransom",
            "indonesia",
            "pixel",
            "nexus",
            "patch",
            "malware",
            "ransomware",
            "april",
            "threat",
            "trojans"
          ],
          "references": [
            "https://research.checkpoint.com/2024/rafel-rat-android-malware-from-espionage-to-ransomware-operations/"
          ],
          "public": 1,
          "adversary": "Threat",
          "targeted_countries": [
            "United States of America",
            "China",
            "Indonesia",
            "Russian Federation",
            "Romania"
          ],
          "malware_families": [
            {
              "id": "Trojans",
              "display_name": "Trojans",
              "target": null
            },
            {
              "id": "Android",
              "display_name": "Android",
              "target": null
            },
            {
              "id": "Threat",
              "display_name": "Threat",
              "target": null
            },
            {
              "id": "Rafel",
              "display_name": "Rafel",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [
            "Government",
            "Military"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Superpro",
            "id": "61676",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 6,
            "domain": 4
          },
          "indicator_count": 22,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 213,
          "modified_text": "705 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6679706434d1dc2392fea7f6",
          "name": "Rafel RAT, Android Malware from Espionage to Ransomware Operations - Check Point Research",
          "description": "",
          "modified": "2024-06-24T13:11:00.165000",
          "created": "2024-06-24T13:11:00.165000",
          "tags": [
            "android",
            "rafel rat",
            "rafel",
            "android malware",
            "check point",
            "pakistan",
            "device admin",
            "internalservice",
            "google",
            "research",
            "life",
            "loda",
            "ransom",
            "indonesia",
            "pixel",
            "nexus",
            "patch",
            "malware",
            "ransomware",
            "april"
          ],
          "references": [
            "https://research.checkpoint.com/2024/rafel-rat-android-malware-from-espionage-to-ransomware-operations/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 6,
            "domain": 4,
            "hostname": 3
          },
          "indicator_count": 25,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "705 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66796f43d479539badac42bc",
          "name": "New Android Rafel RAT Takes Complete Control Of Android Device",
          "description": "",
          "modified": "2024-06-24T13:06:11.398000",
          "created": "2024-06-24T13:06:11.398000",
          "tags": [
            "rafel",
            "android",
            "android malware",
            "rafel rat",
            "source",
            "check point",
            "checkpoint",
            "android rafel",
            "rat check",
            "point research"
          ],
          "references": [
            "https://cybersecuritynews.com/android-rafel-rat/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 6,
            "domain": 4,
            "hostname": 3
          },
          "indicator_count": 25,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "705 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "667626a6500b2446c4dea1e1",
          "name": "Rafel RAT Evolves from Espionage to Ransomware Operations",
          "description": "",
          "modified": "2024-06-22T01:19:34.247000",
          "created": "2024-06-22T01:19:34.247000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 6,
            "domain": 4
          },
          "indicator_count": 10,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 500,
          "modified_text": "708 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://research.checkpoint.com/2024/rafel-rat-android-malware-from-espionage-to-ransomware-operations/",
        "https://github.com/ttc-cert/TTC-CERT_blocklist_recommended/blob/master/domain_blocklist_recommended.txt",
        "https://cybersecuritynews.com/android-rafel-rat/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Threat"
          ],
          "malware_families": [
            "Android",
            "Threat",
            "Trojans",
            "Rafel"
          ],
          "industries": [
            "Government",
            "Military"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 7,
  "pulses": [
    {
      "id": "6783308fc0b6e2bd8dfb209c",
      "name": "TTC-CERT_blocklist_recommended",
      "description": "",
      "modified": "2026-02-14T00:03:07.406000",
      "created": "2025-01-12T03:01:35.075000",
      "tags": [],
      "references": [
        "https://github.com/ttc-cert/TTC-CERT_blocklist_recommended/blob/master/domain_blocklist_recommended.txt"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 606,
        "URL": 4,
        "domain": 25122,
        "hostname": 25306
      },
      "indicator_count": 51038,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 185,
      "modified_text": "106 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67ba2d75ce154e1f60d7c2e5",
      "name": "Rafel RAT, Android Malware from Espionage to Ransomware Operations - Check Point Research",
      "description": "A study by security firm Check Point Research has identified a range of malicious software designed to target Android devices, and identified an espionage group using Rafel RAT to carry out such operations, as well as ransomware.",
      "modified": "2025-02-22T20:03:01.522000",
      "created": "2025-02-22T20:03:01.522000",
      "tags": [
        "android",
        "rafel rat",
        "rafel",
        "android malware",
        "check point",
        "pakistan",
        "device admin",
        "internalservice",
        "google",
        "research",
        "life",
        "loda",
        "ransom",
        "indonesia",
        "pixel",
        "nexus",
        "patch",
        "malware",
        "ransomware",
        "april",
        "threat",
        "trojans",
        "october",
        "august",
        "android version",
        "february",
        "attack"
      ],
      "references": [
        "https://research.checkpoint.com/2024/rafel-rat-android-malware-from-espionage-to-ransomware-operations/"
      ],
      "public": 1,
      "adversary": "Threat",
      "targeted_countries": [
        "United States of America",
        "China",
        "Indonesia",
        "Russian Federation",
        "Romania",
        "Pakistan"
      ],
      "malware_families": [
        {
          "id": "Trojans",
          "display_name": "Trojans",
          "target": null
        },
        {
          "id": "Android",
          "display_name": "Android",
          "target": null
        },
        {
          "id": "Threat",
          "display_name": "Threat",
          "target": null
        },
        {
          "id": "Rafel",
          "display_name": "Rafel",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [
        "Government",
        "Military"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Armature_TIP",
        "id": "308911",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_308911/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 6,
        "FileHash-SHA1": 6,
        "FileHash-SHA256": 6,
        "domain": 4
      },
      "indicator_count": 22,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 42,
      "modified_text": "462 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6654138435c5832ca2c4028f",
      "name": "DOH Domains IOCs",
      "description": "The following is a full list of items that you might not have known existed::..com, or, if you were interested in them, are the most likely ones to come up with",
      "modified": "2024-08-26T04:12:43.497000",
      "created": "2024-05-27T05:00:52.918000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fueledbycoffeeDXB",
        "id": "272228",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 7,
        "domain": 1335,
        "hostname": 667
      },
      "indicator_count": 2009,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 26,
      "modified_text": "643 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6679e1b5b2001e71bb2613a0",
      "name": "Rafel Rat: Android Malware Evolving From Espionage To Ransomware Attacks",
      "description": "Rafel RAT, an Android malware initially used for espionage but later adapted for ransomware operations. This malware, first discovered in early 2023, has undergone significant changes, expanding its functionality and becoming more versatile in its malicious activities. Initially, Rafel RAT was employed primarily for espionage, focusing on stealing sensitive information from infected devices. However, its developers have since enhanced its capabilities to include ransomware features, allowing it to encrypt files and demand ransom payments from victims.",
      "modified": "2024-06-24T21:14:29.912000",
      "created": "2024-06-24T21:14:29.912000",
      "tags": [
        "android",
        "rafel rat",
        "rafel",
        "android malware",
        "check point",
        "pakistan",
        "device admin",
        "internalservice",
        "google",
        "research",
        "life",
        "loda",
        "ransom",
        "indonesia",
        "pixel",
        "nexus",
        "patch",
        "malware",
        "ransomware",
        "april",
        "threat",
        "trojans"
      ],
      "references": [
        "https://research.checkpoint.com/2024/rafel-rat-android-malware-from-espionage-to-ransomware-operations/"
      ],
      "public": 1,
      "adversary": "Threat",
      "targeted_countries": [
        "United States of America",
        "China",
        "Indonesia",
        "Russian Federation",
        "Romania"
      ],
      "malware_families": [
        {
          "id": "Trojans",
          "display_name": "Trojans",
          "target": null
        },
        {
          "id": "Android",
          "display_name": "Android",
          "target": null
        },
        {
          "id": "Threat",
          "display_name": "Threat",
          "target": null
        },
        {
          "id": "Rafel",
          "display_name": "Rafel",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [
        "Government",
        "Military"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Superpro",
        "id": "61676",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 6,
        "FileHash-SHA1": 6,
        "FileHash-SHA256": 6,
        "domain": 4
      },
      "indicator_count": 22,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 213,
      "modified_text": "705 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6679706434d1dc2392fea7f6",
      "name": "Rafel RAT, Android Malware from Espionage to Ransomware Operations - Check Point Research",
      "description": "",
      "modified": "2024-06-24T13:11:00.165000",
      "created": "2024-06-24T13:11:00.165000",
      "tags": [
        "android",
        "rafel rat",
        "rafel",
        "android malware",
        "check point",
        "pakistan",
        "device admin",
        "internalservice",
        "google",
        "research",
        "life",
        "loda",
        "ransom",
        "indonesia",
        "pixel",
        "nexus",
        "patch",
        "malware",
        "ransomware",
        "april"
      ],
      "references": [
        "https://research.checkpoint.com/2024/rafel-rat-android-malware-from-espionage-to-ransomware-operations/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 6,
        "FileHash-SHA1": 6,
        "FileHash-SHA256": 6,
        "domain": 4,
        "hostname": 3
      },
      "indicator_count": 25,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 863,
      "modified_text": "705 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66796f43d479539badac42bc",
      "name": "New Android Rafel RAT Takes Complete Control Of Android Device",
      "description": "",
      "modified": "2024-06-24T13:06:11.398000",
      "created": "2024-06-24T13:06:11.398000",
      "tags": [
        "rafel",
        "android",
        "android malware",
        "rafel rat",
        "source",
        "check point",
        "checkpoint",
        "android rafel",
        "rat check",
        "point research"
      ],
      "references": [
        "https://cybersecuritynews.com/android-rafel-rat/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 6,
        "FileHash-SHA1": 6,
        "FileHash-SHA256": 6,
        "domain": 4,
        "hostname": 3
      },
      "indicator_count": 25,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "705 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "667626a6500b2446c4dea1e1",
      "name": "Rafel RAT Evolves from Espionage to Ransomware Operations",
      "description": "",
      "modified": "2024-06-22T01:19:34.247000",
      "created": "2024-06-22T01:19:34.247000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "cryptocti",
        "id": "110256",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 6,
        "domain": 4
      },
      "indicator_count": 10,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 500,
      "modified_text": "708 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "zetalinks.tech",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "zetalinks.tech",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780221822.4257548
}