{
  "type": "Domain",
  "indicator": "zetalytics.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/zetalytics.com",
    "alexa": "http://www.alexa.com/siteinfo/zetalytics.com",
    "indicator": "zetalytics.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3380823728,
      "indicator": "zetalytics.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 8,
      "pulses": [
        {
          "id": "69228447b9c71795633314df",
          "name": "Keep Corrupt - University of Alberta Incidents continue to escalate - 04.24.26",
          "description": "Recovered accounts that have been used & abused - courtesy of decisions by non-technical leadership = accounts for UAlberta students -> PW manager made inaccessible (tied to UAlberta account) during a Data-Breach.\nWhen PW manager & Accounts returned, was populated by these (many = fraudulent; some appear to be abuse of legitimate services, while others do not, yet don't know function or origin)\n\nNot representative of OG PW manager. Many (most) accts. used/abused (on-going). \n\nDon't have a backup of original = hard to compare. Don't quite know what the majority of these companies etc. are for and/or do exactly. Putting them together as they roll-in.\nCan't turn them off in most cases - I don't have access to the U of A accounts these originate from and/or original recovery methods. \n\n2 more batches to add to this pulse (Need to add into VT) 02.16.26\n\nCountries listed are where 2 victims (UAlberta Graduates) have citizenship or some tie with.",
          "modified": "2026-05-24T21:18:51.782000",
          "created": "2025-11-23T03:49:27.649000",
          "tags": [
            "geoip",
            "as54113",
            "fastly",
            "as20940",
            "as15169",
            "google",
            "as214401",
            "maincubesas",
            "gmbh",
            "apache geoip",
            "facebook",
            "UAlberta",
            "AHS",
            "Treaty 8",
            "GoA",
            "Alberta",
            "Edmonton",
            "YEG"
          ],
          "references": [
            "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a",
            "URLscanio, FSio, vT",
            "03.11.14: https://www.virustotal.com/graph/embed/ge2e309eb8bd34fcca56398089b2291058dfe1fca69dc4e5aa66db0365caf735b?theme=dark",
            "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/summary",
            "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/iocs",
            "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a (11.22.25)"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Cura\u00e7ao",
            "Guatemala",
            "Sint Maarten (Dutch part)",
            "Tanzania, United Republic of",
            "Barbados",
            "United States of America",
            "Bahamas",
            "Anguilla",
            "Canada",
            "Saint Vincent and the Grenadines",
            "United Kingdom of Great Britain and Northern Ireland",
            "Kenya",
            "France",
            "Aruba",
            "Mexico",
            "Poland",
            "Costa Rica",
            "Ireland",
            "Trinidad and Tobago",
            "Netherlands",
            "Slovakia",
            "Spain",
            "Philippines"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government",
            "Technology",
            "Telecommunications",
            "Education",
            "Healthcare",
            "Finance",
            "Retail",
            "Hospitality",
            "Transportation"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 3,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CIDR": 47,
            "FileHash-MD5": 53,
            "FileHash-SHA1": 16,
            "FileHash-SHA256": 1059,
            "URL": 6374,
            "domain": 3314,
            "email": 1395,
            "hostname": 3740,
            "CVE": 1
          },
          "indicator_count": 15999,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 136,
          "modified_text": "6 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d4db11500ea6dcbc2afd10",
          "name": "ZETALYTICS.COM PT2 CREATED 2 YEARS AGO by StreamMiningEx Public TLP:  Green clone",
          "description": "",
          "modified": "2026-04-07T10:23:13.255000",
          "created": "2026-04-07T10:23:13.255000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65707f425121331bce0945cd",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 547,
            "FileHash-SHA256": 932,
            "URL": 1267,
            "domain": 140
          },
          "indicator_count": 2886,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "54 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707f8475d8a8785dfc5a2f",
          "name": "Zetalytics API",
          "description": "",
          "modified": "2023-12-06T14:04:52.250000",
          "created": "2023-12-06T14:04:52.250000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 754,
            "hostname": 833,
            "domain": 441,
            "URL": 2375,
            "CIDR": 5,
            "FileHash-MD5": 2,
            "email": 1
          },
          "indicator_count": 4411,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707f425121331bce0945cd",
          "name": "ZETALYTICS.COM PT2",
          "description": "",
          "modified": "2023-12-06T14:03:46.820000",
          "created": "2023-12-06T14:03:46.820000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 547,
            "FileHash-SHA256": 932,
            "URL": 1267,
            "domain": 140
          },
          "indicator_count": 2886,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707ea9c0f2231d524c00ae",
          "name": "www.zetalytics.com",
          "description": "",
          "modified": "2023-12-06T14:01:12.637000",
          "created": "2023-12-06T14:01:12.637000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 632,
            "URL": 747,
            "hostname": 368,
            "domain": 116,
            "email": 1,
            "FileHash-SHA1": 2
          },
          "indicator_count": 1866,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "621bc3aa050a6c5693595f25",
          "name": "Zetalytics API",
          "description": "",
          "modified": "2022-03-29T00:03:34.773000",
          "created": "2022-02-27T18:32:10.542000",
          "tags": [
            "google",
            "google llc",
            "detected",
            "expand overall",
            "http",
            "amazonaes",
            "openssl",
            "lookup go",
            "rescan add",
            "verdict report",
            "behaviour",
            "june",
            "apache",
            "search url",
            "search domain",
            "scan url",
            "url search",
            "domain scan",
            "url url",
            "us summary",
            "line",
            "google maps",
            "api warning",
            "redirects links",
            "similar dom",
            "content api",
            "domains",
            "Ransomware"
          ],
          "references": [
            "zetalytics .pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Win.Virus.PolyRansom-5704625-0",
              "display_name": "Win.Virus.PolyRansom-5704625-0",
              "target": null
            },
            {
              "id": "Win32:Cryptor",
              "display_name": "Win32:Cryptor",
              "target": null
            },
            {
              "id": "TELPER:CERT:SoftwareBundler:Win32/Bunpredelt",
              "display_name": "TELPER:CERT:SoftwareBundler:Win32/Bunpredelt",
              "target": null
            },
            {
              "id": "Trojan:Win32/Danabot.G",
              "display_name": "Trojan:Win32/Danabot.G",
              "target": "/malware/Trojan:Win32/Danabot.G"
            },
            {
              "id": "Backdoor:Win32/Poison.E",
              "display_name": "Backdoor:Win32/Poison.E",
              "target": "/malware/Backdoor:Win32/Poison.E"
            },
            {
              "id": "ALF:PUA:Block:IObit.R!MTB",
              "display_name": "ALF:PUA:Block:IObit.R!MTB",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 754,
            "URL": 2375,
            "domain": 441,
            "hostname": 833,
            "CIDR": 5,
            "FileHash-MD5": 2,
            "email": 1
          },
          "indicator_count": 4411,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 405,
          "modified_text": "1524 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6219004f53e3ae2316efea12",
          "name": "ZETALYTICS.COM PT2",
          "description": "",
          "modified": "2022-03-27T00:00:39.057000",
          "created": "2022-02-25T16:14:07.302000",
          "tags": [
            "ssl certificate",
            "whois",
            "whois record"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "China"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 547,
            "URL": 1267,
            "domain": 140,
            "FileHash-SHA256": 932
          },
          "indicator_count": 2886,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1526 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6211eaee20bc9b0534df6133",
          "name": "www.zetalytics.com",
          "description": "",
          "modified": "2022-03-24T00:00:00.271000",
          "created": "2022-02-20T07:17:02.872000",
          "tags": [
            "ssl certificate",
            "whois record",
            "whois",
            "key identifier",
            "x509v3 subject",
            "v3 serial",
            "number",
            "issuer",
            "cus cngo",
            "daddy secure",
            "g2 lscottsdale",
            "ouhttp",
            "validity",
            "info",
            "date",
            "tucows domains",
            "server",
            "algorithm",
            "iana id",
            "registrar url",
            "status",
            "registrar whois",
            "rank value",
            "ingestion time",
            "statvoo",
            "utc alexa",
            "utc cisco",
            "umbrella",
            "submission",
            "history first",
            "analysis",
            "utc http",
            "response final",
            "url https",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "tools",
            "Ransomware",
            "POSSIBLE ETERNAL BLUE"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "China",
            "Australia",
            "Belgium"
          ],
          "malware_families": [
            {
              "id": "TEL:NoPowShell!msil",
              "display_name": "TEL:NoPowShell!msil",
              "target": null
            },
            {
              "id": "PWS:Win32/QQPass.GP",
              "display_name": "PWS:Win32/QQPass.GP",
              "target": "/malware/PWS:Win32/QQPass.GP"
            },
            {
              "id": "Win.Malware.Razy-6783523-0",
              "display_name": "Win.Malware.Razy-6783523-0",
              "target": null
            },
            {
              "id": "Win.Trojan.Pasta-827",
              "display_name": "Win.Trojan.Pasta-827",
              "target": null
            },
            {
              "id": "Ransom:Win32/Wannaren.A",
              "display_name": "Ransom:Win32/Wannaren.A",
              "target": "/malware/Ransom:Win32/Wannaren.A"
            },
            {
              "id": "Win.Malware.Zusy-6840460-0",
              "display_name": "Win.Malware.Zusy-6840460-0",
              "target": null
            },
            {
              "id": "Win.Trojan.Agent-1201096",
              "display_name": "Win.Trojan.Agent-1201096",
              "target": null
            },
            {
              "id": "Win32:Dropper-GUP\\ [Drp]",
              "display_name": "Win32:Dropper-GUP\\ [Drp]",
              "target": null
            },
            {
              "id": "Worm:Win32/Macoute",
              "display_name": "Worm:Win32/Macoute",
              "target": "/malware/Worm:Win32/Macoute"
            },
            {
              "id": "Win32:Sobig-H\\ [Wrm]",
              "display_name": "Win32:Sobig-H\\ [Wrm]",
              "target": null
            },
            {
              "id": "Win.Worm.Sobig-5",
              "display_name": "Win.Worm.Sobig-5",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Berbew",
              "display_name": "Backdoor:Win32/Berbew",
              "target": "/malware/Backdoor:Win32/Berbew"
            },
            {
              "id": "Win.Trojan.Crypted-30",
              "display_name": "Win.Trojan.Crypted-30",
              "target": null
            },
            {
              "id": "#VirTool:Win32/Obfuscator.ADB",
              "display_name": "#VirTool:Win32/Obfuscator.ADB",
              "target": "/malware/#VirTool:Win32/Obfuscator.ADB"
            },
            {
              "id": "Win.Trojan.Kazy-6878",
              "display_name": "Win.Trojan.Kazy-6878",
              "target": null
            },
            {
              "id": "Win32:VB-FBX",
              "display_name": "Win32:VB-FBX",
              "target": null
            },
            {
              "id": "Win.Worm.Pajetbin-6726648-0",
              "display_name": "Win.Worm.Pajetbin-6726648-0",
              "target": null
            },
            {
              "id": "Trojan:Win32/Vindor.B",
              "display_name": "Trojan:Win32/Vindor.B",
              "target": "/malware/Trojan:Win32/Vindor.B"
            },
            {
              "id": "MSIL:BrowseFox-FC\\ [Adw]",
              "display_name": "MSIL:BrowseFox-FC\\ [Adw]",
              "target": null
            },
            {
              "id": "Win.Ransomware.Teslacrypt-7082109-1",
              "display_name": "Win.Ransomware.Teslacrypt-7082109-1",
              "target": null
            },
            {
              "id": "ALF:HSTR:Trojan:Win32/Injector.YY!bit",
              "display_name": "ALF:HSTR:Trojan:Win32/Injector.YY!bit",
              "target": null
            },
            {
              "id": "Win32:Papras-AX\\ [Trj]",
              "display_name": "Win32:Papras-AX\\ [Trj]",
              "target": null
            },
            {
              "id": "ALF:HSTR:MITM:UtilAds",
              "display_name": "ALF:HSTR:MITM:UtilAds",
              "target": null
            },
            {
              "id": "Win.Malware.Autoit-6753917-0",
              "display_name": "Win.Malware.Autoit-6753917-0",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 368,
            "URL": 747,
            "domain": 116,
            "FileHash-SHA256": 632,
            "email": 1,
            "FileHash-SHA1": 2
          },
          "indicator_count": 1866,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 408,
          "modified_text": "1529 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "03.11.14: https://www.virustotal.com/graph/embed/ge2e309eb8bd34fcca56398089b2291058dfe1fca69dc4e5aa66db0365caf735b?theme=dark",
        "URLscanio, FSio, vT",
        "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a",
        "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/summary",
        "zetalytics .pdf",
        "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/iocs",
        "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a (11.22.25)"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Win.worm.pajetbin-6726648-0",
            "Win32:vb-fbx",
            "Trojan:win32/vindor.b",
            "Alf:hstr:trojan:win32/injector.yy!bit",
            "Win.trojan.crypted-30",
            "Backdoor:win32/poison.e",
            "#virtool:win32/obfuscator.adb",
            "Win.trojan.agent-1201096",
            "Alf:hstr:mitm:utilads",
            "Worm:win32/macoute",
            "Win.virus.polyransom-5704625-0",
            "Tel:nopowshell!msil",
            "Win.malware.zusy-6840460-0",
            "Win32:sobig-h\\ [wrm]",
            "Msil:browsefox-fc\\ [adw]",
            "Ransom:win32/wannaren.a",
            "Win32:papras-ax\\ [trj]",
            "Telper:cert:softwarebundler:win32/bunpredelt",
            "Win.malware.razy-6783523-0",
            "Win.malware.autoit-6753917-0",
            "Win32:dropper-gup\\ [drp]",
            "Trojan:win32/danabot.g",
            "Win.trojan.kazy-6878",
            "Win.ransomware.teslacrypt-7082109-1",
            "Win.worm.sobig-5",
            "Win.trojan.pasta-827",
            "Alf:pua:block:iobit.r!mtb",
            "Pws:win32/qqpass.gp",
            "Backdoor:win32/berbew",
            "Win32:cryptor"
          ],
          "industries": [
            "Finance",
            "Telecommunications",
            "Technology",
            "Healthcare",
            "Transportation",
            "Hospitality",
            "Retail",
            "Education",
            "Government"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 8,
  "pulses": [
    {
      "id": "69228447b9c71795633314df",
      "name": "Keep Corrupt - University of Alberta Incidents continue to escalate - 04.24.26",
      "description": "Recovered accounts that have been used & abused - courtesy of decisions by non-technical leadership = accounts for UAlberta students -> PW manager made inaccessible (tied to UAlberta account) during a Data-Breach.\nWhen PW manager & Accounts returned, was populated by these (many = fraudulent; some appear to be abuse of legitimate services, while others do not, yet don't know function or origin)\n\nNot representative of OG PW manager. Many (most) accts. used/abused (on-going). \n\nDon't have a backup of original = hard to compare. Don't quite know what the majority of these companies etc. are for and/or do exactly. Putting them together as they roll-in.\nCan't turn them off in most cases - I don't have access to the U of A accounts these originate from and/or original recovery methods. \n\n2 more batches to add to this pulse (Need to add into VT) 02.16.26\n\nCountries listed are where 2 victims (UAlberta Graduates) have citizenship or some tie with.",
      "modified": "2026-05-24T21:18:51.782000",
      "created": "2025-11-23T03:49:27.649000",
      "tags": [
        "geoip",
        "as54113",
        "fastly",
        "as20940",
        "as15169",
        "google",
        "as214401",
        "maincubesas",
        "gmbh",
        "apache geoip",
        "facebook",
        "UAlberta",
        "AHS",
        "Treaty 8",
        "GoA",
        "Alberta",
        "Edmonton",
        "YEG"
      ],
      "references": [
        "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a",
        "URLscanio, FSio, vT",
        "03.11.14: https://www.virustotal.com/graph/embed/ge2e309eb8bd34fcca56398089b2291058dfe1fca69dc4e5aa66db0365caf735b?theme=dark",
        "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/summary",
        "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/iocs",
        "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a (11.22.25)"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Cura\u00e7ao",
        "Guatemala",
        "Sint Maarten (Dutch part)",
        "Tanzania, United Republic of",
        "Barbados",
        "United States of America",
        "Bahamas",
        "Anguilla",
        "Canada",
        "Saint Vincent and the Grenadines",
        "United Kingdom of Great Britain and Northern Ireland",
        "Kenya",
        "France",
        "Aruba",
        "Mexico",
        "Poland",
        "Costa Rica",
        "Ireland",
        "Trinidad and Tobago",
        "Netherlands",
        "Slovakia",
        "Spain",
        "Philippines"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Government",
        "Technology",
        "Telecommunications",
        "Education",
        "Healthcare",
        "Finance",
        "Retail",
        "Hospitality",
        "Transportation"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 3,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CIDR": 47,
        "FileHash-MD5": 53,
        "FileHash-SHA1": 16,
        "FileHash-SHA256": 1059,
        "URL": 6374,
        "domain": 3314,
        "email": 1395,
        "hostname": 3740,
        "CVE": 1
      },
      "indicator_count": 15999,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 136,
      "modified_text": "6 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d4db11500ea6dcbc2afd10",
      "name": "ZETALYTICS.COM PT2 CREATED 2 YEARS AGO by StreamMiningEx Public TLP:  Green clone",
      "description": "",
      "modified": "2026-04-07T10:23:13.255000",
      "created": "2026-04-07T10:23:13.255000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65707f425121331bce0945cd",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 547,
        "FileHash-SHA256": 932,
        "URL": 1267,
        "domain": 140
      },
      "indicator_count": 2886,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "54 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707f8475d8a8785dfc5a2f",
      "name": "Zetalytics API",
      "description": "",
      "modified": "2023-12-06T14:04:52.250000",
      "created": "2023-12-06T14:04:52.250000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 754,
        "hostname": 833,
        "domain": 441,
        "URL": 2375,
        "CIDR": 5,
        "FileHash-MD5": 2,
        "email": 1
      },
      "indicator_count": 4411,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707f425121331bce0945cd",
      "name": "ZETALYTICS.COM PT2",
      "description": "",
      "modified": "2023-12-06T14:03:46.820000",
      "created": "2023-12-06T14:03:46.820000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 547,
        "FileHash-SHA256": 932,
        "URL": 1267,
        "domain": 140
      },
      "indicator_count": 2886,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707ea9c0f2231d524c00ae",
      "name": "www.zetalytics.com",
      "description": "",
      "modified": "2023-12-06T14:01:12.637000",
      "created": "2023-12-06T14:01:12.637000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 632,
        "URL": 747,
        "hostname": 368,
        "domain": 116,
        "email": 1,
        "FileHash-SHA1": 2
      },
      "indicator_count": 1866,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "621bc3aa050a6c5693595f25",
      "name": "Zetalytics API",
      "description": "",
      "modified": "2022-03-29T00:03:34.773000",
      "created": "2022-02-27T18:32:10.542000",
      "tags": [
        "google",
        "google llc",
        "detected",
        "expand overall",
        "http",
        "amazonaes",
        "openssl",
        "lookup go",
        "rescan add",
        "verdict report",
        "behaviour",
        "june",
        "apache",
        "search url",
        "search domain",
        "scan url",
        "url search",
        "domain scan",
        "url url",
        "us summary",
        "line",
        "google maps",
        "api warning",
        "redirects links",
        "similar dom",
        "content api",
        "domains",
        "Ransomware"
      ],
      "references": [
        "zetalytics .pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Win.Virus.PolyRansom-5704625-0",
          "display_name": "Win.Virus.PolyRansom-5704625-0",
          "target": null
        },
        {
          "id": "Win32:Cryptor",
          "display_name": "Win32:Cryptor",
          "target": null
        },
        {
          "id": "TELPER:CERT:SoftwareBundler:Win32/Bunpredelt",
          "display_name": "TELPER:CERT:SoftwareBundler:Win32/Bunpredelt",
          "target": null
        },
        {
          "id": "Trojan:Win32/Danabot.G",
          "display_name": "Trojan:Win32/Danabot.G",
          "target": "/malware/Trojan:Win32/Danabot.G"
        },
        {
          "id": "Backdoor:Win32/Poison.E",
          "display_name": "Backdoor:Win32/Poison.E",
          "target": "/malware/Backdoor:Win32/Poison.E"
        },
        {
          "id": "ALF:PUA:Block:IObit.R!MTB",
          "display_name": "ALF:PUA:Block:IObit.R!MTB",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 754,
        "URL": 2375,
        "domain": 441,
        "hostname": 833,
        "CIDR": 5,
        "FileHash-MD5": 2,
        "email": 1
      },
      "indicator_count": 4411,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 405,
      "modified_text": "1524 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6219004f53e3ae2316efea12",
      "name": "ZETALYTICS.COM PT2",
      "description": "",
      "modified": "2022-03-27T00:00:39.057000",
      "created": "2022-02-25T16:14:07.302000",
      "tags": [
        "ssl certificate",
        "whois",
        "whois record"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "China"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 547,
        "URL": 1267,
        "domain": 140,
        "FileHash-SHA256": 932
      },
      "indicator_count": 2886,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 406,
      "modified_text": "1526 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6211eaee20bc9b0534df6133",
      "name": "www.zetalytics.com",
      "description": "",
      "modified": "2022-03-24T00:00:00.271000",
      "created": "2022-02-20T07:17:02.872000",
      "tags": [
        "ssl certificate",
        "whois record",
        "whois",
        "key identifier",
        "x509v3 subject",
        "v3 serial",
        "number",
        "issuer",
        "cus cngo",
        "daddy secure",
        "g2 lscottsdale",
        "ouhttp",
        "validity",
        "info",
        "date",
        "tucows domains",
        "server",
        "algorithm",
        "iana id",
        "registrar url",
        "status",
        "registrar whois",
        "rank value",
        "ingestion time",
        "statvoo",
        "utc alexa",
        "utc cisco",
        "umbrella",
        "submission",
        "history first",
        "analysis",
        "utc http",
        "response final",
        "url https",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "tools",
        "Ransomware",
        "POSSIBLE ETERNAL BLUE"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "China",
        "Australia",
        "Belgium"
      ],
      "malware_families": [
        {
          "id": "TEL:NoPowShell!msil",
          "display_name": "TEL:NoPowShell!msil",
          "target": null
        },
        {
          "id": "PWS:Win32/QQPass.GP",
          "display_name": "PWS:Win32/QQPass.GP",
          "target": "/malware/PWS:Win32/QQPass.GP"
        },
        {
          "id": "Win.Malware.Razy-6783523-0",
          "display_name": "Win.Malware.Razy-6783523-0",
          "target": null
        },
        {
          "id": "Win.Trojan.Pasta-827",
          "display_name": "Win.Trojan.Pasta-827",
          "target": null
        },
        {
          "id": "Ransom:Win32/Wannaren.A",
          "display_name": "Ransom:Win32/Wannaren.A",
          "target": "/malware/Ransom:Win32/Wannaren.A"
        },
        {
          "id": "Win.Malware.Zusy-6840460-0",
          "display_name": "Win.Malware.Zusy-6840460-0",
          "target": null
        },
        {
          "id": "Win.Trojan.Agent-1201096",
          "display_name": "Win.Trojan.Agent-1201096",
          "target": null
        },
        {
          "id": "Win32:Dropper-GUP\\ [Drp]",
          "display_name": "Win32:Dropper-GUP\\ [Drp]",
          "target": null
        },
        {
          "id": "Worm:Win32/Macoute",
          "display_name": "Worm:Win32/Macoute",
          "target": "/malware/Worm:Win32/Macoute"
        },
        {
          "id": "Win32:Sobig-H\\ [Wrm]",
          "display_name": "Win32:Sobig-H\\ [Wrm]",
          "target": null
        },
        {
          "id": "Win.Worm.Sobig-5",
          "display_name": "Win.Worm.Sobig-5",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Berbew",
          "display_name": "Backdoor:Win32/Berbew",
          "target": "/malware/Backdoor:Win32/Berbew"
        },
        {
          "id": "Win.Trojan.Crypted-30",
          "display_name": "Win.Trojan.Crypted-30",
          "target": null
        },
        {
          "id": "#VirTool:Win32/Obfuscator.ADB",
          "display_name": "#VirTool:Win32/Obfuscator.ADB",
          "target": "/malware/#VirTool:Win32/Obfuscator.ADB"
        },
        {
          "id": "Win.Trojan.Kazy-6878",
          "display_name": "Win.Trojan.Kazy-6878",
          "target": null
        },
        {
          "id": "Win32:VB-FBX",
          "display_name": "Win32:VB-FBX",
          "target": null
        },
        {
          "id": "Win.Worm.Pajetbin-6726648-0",
          "display_name": "Win.Worm.Pajetbin-6726648-0",
          "target": null
        },
        {
          "id": "Trojan:Win32/Vindor.B",
          "display_name": "Trojan:Win32/Vindor.B",
          "target": "/malware/Trojan:Win32/Vindor.B"
        },
        {
          "id": "MSIL:BrowseFox-FC\\ [Adw]",
          "display_name": "MSIL:BrowseFox-FC\\ [Adw]",
          "target": null
        },
        {
          "id": "Win.Ransomware.Teslacrypt-7082109-1",
          "display_name": "Win.Ransomware.Teslacrypt-7082109-1",
          "target": null
        },
        {
          "id": "ALF:HSTR:Trojan:Win32/Injector.YY!bit",
          "display_name": "ALF:HSTR:Trojan:Win32/Injector.YY!bit",
          "target": null
        },
        {
          "id": "Win32:Papras-AX\\ [Trj]",
          "display_name": "Win32:Papras-AX\\ [Trj]",
          "target": null
        },
        {
          "id": "ALF:HSTR:MITM:UtilAds",
          "display_name": "ALF:HSTR:MITM:UtilAds",
          "target": null
        },
        {
          "id": "Win.Malware.Autoit-6753917-0",
          "display_name": "Win.Malware.Autoit-6753917-0",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 368,
        "URL": 747,
        "domain": 116,
        "FileHash-SHA256": 632,
        "email": 1,
        "FileHash-SHA1": 2
      },
      "indicator_count": 1866,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 408,
      "modified_text": "1529 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "zetalytics.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "zetalytics.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780241600.8694956
}