{
  "type": "Domain",
  "indicator": "zoom.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/zoom.com",
    "alexa": "http://www.alexa.com/siteinfo/zoom.com",
    "indicator": "zoom.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [
      {
        "source": "akamai",
        "message": "Akamai rank: #9549",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain zoom.com",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3842469421,
      "indicator": "zoom.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 10,
      "pulses": [
        {
          "id": "69f3f6fc9ae9b2297964a5a4",
          "name": "VirusTotal report          for Test.docx + Other Civic Findings/CVE Linkings",
          "description": "1. CivicPlus.com Threat IndicatorsVT Status: Red Flagged [120+ references, 200+android APKS and tracking configs[js]].Suspicious MD5: 3f307fecb41ea75bb946e8fde73a3c36b548243411783c036a1e7ae6605e8223.Suspicious SHA1: 0ef5ceebb6efa99e12e888a993e56d557dff07fd.Behavioral Pattern: Multiple versions flagged with No Expiration (indicates persistent or hard-coded malicious components in related files).2. HitmanPro Findings (Feb 2025)File Action: Detected as Malware/Suspicious in C:\\Windows\\Installer and user data areas.Note: Typical of behavioral scanning identifying code injection or untrusted signatures, often flagged alongside browser data.3. SSO Autodesk Anomalies (Q1 2025)SAML Assertion Failure: Incorrect objectGUID mapping on IdP side, sending user.objectid as literal string instead of unique identifier. Potential credential abuse or IdP misconfiguration - Attached [Reportscivicplus_vt_red_flag_feb2025.loghmp_scan_022025] + test.docx which shows signs that resemble a test recall email.",
          "modified": "2026-05-31T05:19:13.706000",
          "created": "2026-05-01T00:42:36.613000",
          "tags": [
            "medium",
            "windows",
            "high",
            "alerts",
            "yara detections",
            "worm",
            "https domain",
            "tls sni",
            "io control",
            "installs",
            "virustotal",
            "copy",
            "explorer",
            "malware",
            "config by town",
            "civicplus",
            "beyond surveillance",
            "significant overreach"
          ],
          "references": [
            "multiple_versions\tSHA1 of 3f307fecb41ea75bb946e8fde73a3c36b548243411783c036a1e7ae6605e8223\tNo Expiration",
            "",
            "CVE-2025-10898/10899/10900: Out-of-Bounds Write vulnerabilities found in parsed MODEL files.",
            "More elaborate 'text' exploits now exist that allow texts are now being distributed via ai drops in chats in the form of what would appear to be a hyperlink. This is a new genre of elevation in exploit.",
            "The 'test' email aligns perfectly with CVE-2022-30190, as indicated in my findings"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1010,
            "FileHash-SHA1": 437,
            "FileHash-SHA256": 2319,
            "URL": 637,
            "email": 14,
            "hostname": 468,
            "domain": 101,
            "IPv4": 298,
            "IPv6": 96,
            "CVE": 9
          },
          "indicator_count": 5389,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "2 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69eae966e2994ca9410416e7",
          "name": "CAPE Sandbox - Watson",
          "description": "[full list of details about Akamai, the web hosting company, that has been abused on the internet for more than 20 years.. and the names of its users have been published.] pretext. Watson frequents. wizard8.",
          "modified": "2026-05-24T05:16:16.520000",
          "created": "2026-04-24T03:54:14.835000",
          "tags": [
            "akamai",
            "city",
            "noc united",
            "orgid",
            "akamai ref",
            "net23",
            "net230000",
            "cidr",
            "orgabusehandle",
            "orgtechhandle"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1406",
              "name": "Obfuscated Files or Information",
              "display_name": "T1406 - Obfuscated Files or Information"
            },
            {
              "id": "T1409",
              "name": "Access Stored Application Data",
              "display_name": "T1409 - Access Stored Application Data"
            },
            {
              "id": "T1421",
              "name": "System Network Connections Discovery",
              "display_name": "T1421 - System Network Connections Discovery"
            },
            {
              "id": "T1424",
              "name": "Process Discovery",
              "display_name": "T1424 - Process Discovery"
            },
            {
              "id": "T1426",
              "name": "System Information Discovery",
              "display_name": "T1426 - System Information Discovery"
            },
            {
              "id": "T1430",
              "name": "Location Tracking",
              "display_name": "T1430 - Location Tracking"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 382,
            "FileHash-SHA1": 361,
            "FileHash-SHA256": 1250,
            "URL": 1436,
            "domain": 425,
            "hostname": 783,
            "CIDR": 1,
            "email": 29,
            "CVE": 1,
            "URI": 2
          },
          "indicator_count": 4670,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "7 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f97a905451e3304319988b",
          "name": ".may 4 clone own on may 5",
          "description": "",
          "modified": "2026-05-07T02:57:38.229000",
          "created": "2026-05-05T05:05:20.493000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "69f7fa1a282840a6e0aa370c",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 341,
            "FileHash-SHA1": 368,
            "FileHash-SHA256": 3143,
            "hostname": 2037,
            "IPv4": 186,
            "URL": 3288,
            "CIDR": 12,
            "email": 43,
            "domain": 1645,
            "URI": 1,
            "SSLCertFingerprint": 18,
            "CVE": 1
          },
          "indicator_count": 11083,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f7fa1a282840a6e0aa370c",
          "name": "May the 4th be with... every destructed file that never died",
          "description": "[undreds of thousands of people have been signing a petition calling for the removal of the president, Barack Obama, from the White House and the UK's prime minister, Theresa May, to be remove] The wording here. Its also May3rd not May 4th.",
          "modified": "2026-05-05T05:04:02.911000",
          "created": "2026-05-04T01:44:57.811000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 341,
            "FileHash-SHA1": 368,
            "FileHash-SHA256": 3142,
            "hostname": 1890,
            "IPv4": 162,
            "URL": 3241,
            "CIDR": 12,
            "email": 37,
            "domain": 1616,
            "URI": 1,
            "SSLCertFingerprint": 18
          },
          "indicator_count": 10828,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69cf4aaed5e28797e2096a95",
          "name": "VirusTotal report\n                    for index.html",
          "description": "<NULL>",
          "modified": "2026-05-03T05:20:14.651000",
          "created": "2026-04-03T05:05:50.814000",
          "tags": [
            "mitre attack",
            "network info",
            "processes extra",
            "performs dns",
            "t1055 process",
            "overview",
            "overview zenbox",
            "verdict",
            "guest system",
            "ultimate file",
            "meta",
            "phishing",
            "next",
            "cohasset high school",
            "massachusetts",
            "nadeam nahas",
            "cryptomining",
            "wcvb",
            "cohasset",
            "gordon",
            "nahas",
            "department",
            "cohasset police",
            "crypto mining",
            "karen anderson",
            "high school",
            "school",
            "bitcoin",
            "copy",
            "https",
            "urls",
            "html page",
            "layer protocol",
            "united",
            "title",
            "air assault",
            "band",
            "script",
            "press",
            "hold",
            "doctype html",
            "access",
            "head",
            "perimeterx",
            "pxosx7m0dx",
            "import",
            "body",
            "android",
            "zip archive",
            "xapk android",
            "android package",
            "java archive",
            "sweet home",
            "design"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/5d18dde011474fb33b951576a4f40851a3edb37eed2c085cd54523d7205e9022_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192470&Signature=nKlj9vgreN7fYV3U1aG4fv22mUc84blejB1PyhBS4HoWpTcNOqIPDeDH2EU%2BDhrXFrxgNPDfk3m7ZF%2F2VFHNyw%2Fy18TAd1tQZFPmtvCToOOAhp4iER3r08E4vTUOKs4vvPog5yOhlCgy4CJ3K8HbuHA8QH70Xvh1Tuo%2Fi79a3%2FDzxZ5hNMVKsKLXJagoxjHCd22TcfjGcdxpo1%2BYcbwUEXdFba06B1lUSsD8A%2B5X%2BSQdX%2FYfiI8g",
            "https://www.wcvb.com/article/cohasset-massachusetts-school-employee-power-cryptocurrency-mine/43025932",
            "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192564&Signature=bI%2FmFLlckahzDU%2FSDsxXds3czan%2BiIJWhk9ISJRpdCEp7pezQxiWJLiEt13K1Rra8HT9gGSndmBMCsZ3NF46U1JNWcVLzOCiX9Munkk3nn%2BFYv5OJFsJgqkcWu%2F8Q0WDNu%2FURM8wWERVypqMET%2FQwRNd9YHCxjD0j7v0T3XoXaTlWlBFBrShH05u3XPLaW76S8zT69nl8TDRX59iXZrgFHm0v%2FbksZ10TIJ%2BkzCS7CRdNRaqmSI3",
            "https://www.facebook.com/groups/2387525621437001/posts/2775911069265119/",
            "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192713&Signature=iX6awMq82XItc5YWXGjoiAr6mGBE7yEqoAv6iPmemNzbuRwWI2nsDjbV5nEvfIl7MtjHOMVwDCRv%2BZ2sjFbIZrahyniPpoGrg69FjdfFMyQPzsYv1Bg5snry%2FW22ROJl%2BMYxKIK1x9hvxXnOtz3SCOY7a31RavAEL%2Fj1rXwDIjrOI%2BtBuen3TYw4ANLBvSUFgMc1FyJpbKIrA%2BIQFzSDTi%2Fa0d9iSrA0Y3shshUY3yMDCspB",
            "https://vtbehaviour.commondatastorage.googleapis.com/5d18dde011474fb33b951576a4f40851a3edb37eed2c085cd54523d7205e9022_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192866&Signature=GgQ76qxY14JaBRGE9w93sbvGI6fl4dPQTxyj4aZlFxsdTWtcYcrMMy5JoQR3aqlBBJrMh19x%2F7%2BJpxBOvHM4CIqSetvdLGlMyJoHTcYJODToEwpJW17TSTZAo5a%2F%2BFnQif%2BRaFVaF9sK6mcWhlcQ0LiRj4ZNO%2FhhAApJM0q3P6KXEuZ%2BTC%2FD%2Bcumt7r8nsdEXwRFQnIKr1dvupZqQVzDJ9%2BA9v7rFKrMcX0adiJp8Mgdih1Swf",
            "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192911&Signature=Iyin7WLwS5Yl%2BLqBc2hNsfMx0vCUDhnnRASgy%2FOR1INoV9I%2FEIwn%2B9EgbBOtpw61w58DMWehC2Zn4kDGLX1D0q1v%2F7i6nAnnTs6fGlksqivhTOBDJLxqo9H2RLeBcFmcT8UDJnz1iRhPvMXVZ%2FEmFDz3WBDyNeoALRLw3ak6DhNDKaxFbjnRHZrmc%2BeEEk9SPXctF7Qd597QPZUzzNLdXY9LvbK2VzgZSdtddTiut7lD1ZHA"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [
            "Electricity"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 70,
            "URL": 117,
            "domain": 13,
            "FileHash-MD5": 7,
            "FileHash-SHA1": 4,
            "hostname": 66
          },
          "indicator_count": 277,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "28 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69cf4aaf485e182cdfef51e0",
          "name": "VirusTotal report\n                    for index.html",
          "description": "<NULL>",
          "modified": "2026-05-03T05:20:14.651000",
          "created": "2026-04-03T05:05:51.290000",
          "tags": [
            "mitre attack",
            "network info",
            "processes extra",
            "performs dns",
            "t1055 process",
            "overview",
            "overview zenbox",
            "verdict",
            "guest system",
            "ultimate file",
            "meta",
            "phishing",
            "next",
            "cohasset high school",
            "massachusetts",
            "nadeam nahas",
            "cryptomining",
            "wcvb",
            "cohasset",
            "gordon",
            "nahas",
            "department",
            "cohasset police",
            "crypto mining",
            "karen anderson",
            "high school",
            "school",
            "bitcoin",
            "copy",
            "https",
            "urls",
            "html page",
            "layer protocol",
            "united",
            "title",
            "air assault",
            "band",
            "script",
            "press",
            "hold",
            "doctype html",
            "access",
            "head",
            "perimeterx",
            "pxosx7m0dx",
            "import",
            "body",
            "android",
            "zip archive",
            "xapk android",
            "android package",
            "java archive",
            "sweet home",
            "design"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/5d18dde011474fb33b951576a4f40851a3edb37eed2c085cd54523d7205e9022_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192470&Signature=nKlj9vgreN7fYV3U1aG4fv22mUc84blejB1PyhBS4HoWpTcNOqIPDeDH2EU%2BDhrXFrxgNPDfk3m7ZF%2F2VFHNyw%2Fy18TAd1tQZFPmtvCToOOAhp4iER3r08E4vTUOKs4vvPog5yOhlCgy4CJ3K8HbuHA8QH70Xvh1Tuo%2Fi79a3%2FDzxZ5hNMVKsKLXJagoxjHCd22TcfjGcdxpo1%2BYcbwUEXdFba06B1lUSsD8A%2B5X%2BSQdX%2FYfiI8g",
            "https://www.wcvb.com/article/cohasset-massachusetts-school-employee-power-cryptocurrency-mine/43025932",
            "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192564&Signature=bI%2FmFLlckahzDU%2FSDsxXds3czan%2BiIJWhk9ISJRpdCEp7pezQxiWJLiEt13K1Rra8HT9gGSndmBMCsZ3NF46U1JNWcVLzOCiX9Munkk3nn%2BFYv5OJFsJgqkcWu%2F8Q0WDNu%2FURM8wWERVypqMET%2FQwRNd9YHCxjD0j7v0T3XoXaTlWlBFBrShH05u3XPLaW76S8zT69nl8TDRX59iXZrgFHm0v%2FbksZ10TIJ%2BkzCS7CRdNRaqmSI3",
            "https://www.facebook.com/groups/2387525621437001/posts/2775911069265119/",
            "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192713&Signature=iX6awMq82XItc5YWXGjoiAr6mGBE7yEqoAv6iPmemNzbuRwWI2nsDjbV5nEvfIl7MtjHOMVwDCRv%2BZ2sjFbIZrahyniPpoGrg69FjdfFMyQPzsYv1Bg5snry%2FW22ROJl%2BMYxKIK1x9hvxXnOtz3SCOY7a31RavAEL%2Fj1rXwDIjrOI%2BtBuen3TYw4ANLBvSUFgMc1FyJpbKIrA%2BIQFzSDTi%2Fa0d9iSrA0Y3shshUY3yMDCspB",
            "https://vtbehaviour.commondatastorage.googleapis.com/5d18dde011474fb33b951576a4f40851a3edb37eed2c085cd54523d7205e9022_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192866&Signature=GgQ76qxY14JaBRGE9w93sbvGI6fl4dPQTxyj4aZlFxsdTWtcYcrMMy5JoQR3aqlBBJrMh19x%2F7%2BJpxBOvHM4CIqSetvdLGlMyJoHTcYJODToEwpJW17TSTZAo5a%2F%2BFnQif%2BRaFVaF9sK6mcWhlcQ0LiRj4ZNO%2FhhAApJM0q3P6KXEuZ%2BTC%2FD%2Bcumt7r8nsdEXwRFQnIKr1dvupZqQVzDJ9%2BA9v7rFKrMcX0adiJp8Mgdih1Swf",
            "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192911&Signature=Iyin7WLwS5Yl%2BLqBc2hNsfMx0vCUDhnnRASgy%2FOR1INoV9I%2FEIwn%2B9EgbBOtpw61w58DMWehC2Zn4kDGLX1D0q1v%2F7i6nAnnTs6fGlksqivhTOBDJLxqo9H2RLeBcFmcT8UDJnz1iRhPvMXVZ%2FEmFDz3WBDyNeoALRLw3ak6DhNDKaxFbjnRHZrmc%2BeEEk9SPXctF7Qd597QPZUzzNLdXY9LvbK2VzgZSdtddTiut7lD1ZHA"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [
            "Electricity"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 70,
            "URL": 117,
            "domain": 13,
            "FileHash-MD5": 7,
            "FileHash-SHA1": 4,
            "hostname": 66
          },
          "indicator_count": 277,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "28 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d34c8a64436a7aee2e25a1",
          "name": "Locky: File Deletion targeting incriminating archived files.",
          "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T12:41:46.707000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 65,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "801 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d34c91868744aa1449fef2",
          "name": "Locky: File Deletion targeting incriminating archived files.",
          "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T12:41:52.846000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 57,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "801 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d3acf32e1088e76165a307",
          "name": "Locky: File Deletion targeting incriminating archived files.",
          "description": "",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T19:33:07.504000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65d34c91868744aa1449fef2",
          "export_count": 64,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 234,
          "modified_text": "801 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65d3c31230455f6d8da3a9f0",
          "name": "Locky: File Deletion targeting incriminating archived files II",
          "description": "",
          "modified": "2024-03-20T12:00:39.809000",
          "created": "2024-02-19T21:07:30.887000",
          "tags": [
            "it consultant",
            "uk collection",
            "dns intel",
            "ips collection",
            "suspicous ip",
            "whois file",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "whois lookup",
            "region create",
            "domain",
            "name server",
            "registrant name",
            "technical city",
            "region update",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ck id",
            "cookie",
            "meta",
            "february",
            "hybrid",
            "general",
            "click",
            "strings",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls http",
            "dns replication",
            "code",
            "namecheap",
            "registrar abuse",
            "namecheap inc",
            "privacy service",
            "withheld",
            "privacy",
            "dnssec",
            "email",
            "first",
            "bodis",
            "unknown",
            "creation date",
            "search",
            "emails",
            "as397240",
            "date",
            "next",
            "all octoseek",
            "threat roundup",
            "january",
            "june",
            "historical ssl",
            "referrer",
            "contacted",
            "group",
            "execution",
            "phishing",
            "malware",
            "core",
            "malicious",
            "dark power",
            "play ransomware",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 linker",
            "gnu linker",
            "compiler",
            "info header",
            "name md5",
            "overlay",
            "passive dns",
            "entries",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "trojan",
            "location united",
            "query",
            "activity dns",
            "observed dns",
            "msie",
            "high",
            "copy",
            "write",
            "win32",
            "hashes",
            "host interaction",
            "sabey type",
            "hallrender",
            "brian sabey",
            "memory pattern",
            "http requests",
            "http method",
            "get response",
            "dns resolutions",
            "ip traffic",
            "domains",
            "mutex",
            "samplepath",
            "created",
            "shell commands",
            "r processes",
            "tree",
            "analyze",
            "hostnames",
            "url https",
            "samples",
            "hostname",
            "pattern urls",
            "memory",
            "pattern",
            "pattern domains",
            "roundup",
            "formbook",
            "mirai",
            "ben c",
            "injection",
            "server",
            "scan endpoints",
            "show",
            "august",
            "bq feb",
            "chrome",
            "precondition",
            "virtool",
            "downloadmr",
            "body",
            "status",
            "servers",
            "record value",
            "name servers",
            "showing",
            "mailrubar",
            "trojanclicker",
            "slcc2",
            "media center",
            "delete c",
            "malware beacon",
            "suspicious",
            "class",
            "internal",
            "local",
            "encrypt",
            "as15169 google",
            "gmt cache",
            "twitter",
            "rostpay",
            "date hash",
            "avast avg",
            "mtb may",
            "susp",
            "cryp",
            "win32upatre may",
            "mtb showing",
            "lowfi",
            "aaaa",
            "win32pcmega jan",
            "urlshortner dec",
            "urlshortner sep",
            "as133618",
            "nxdomain",
            "as133775 xiamen",
            "germany unknown",
            "webtoolbar",
            "nanocore rat",
            "gamehack",
            "cobalt strike",
            "whois record",
            "ssl certificate",
            "tsara brashears",
            "resolutions",
            "critical risk",
            "apple phone",
            "unlocker",
            "shell code",
            "installer",
            "ursnif",
            "hacktool",
            "emotet",
            "tracker",
            "chaos",
            "ransomexx",
            "xor ddos",
            "xorddos",
            "mitre attack",
            "parent domain",
            "urls url",
            "siblings",
            "metro",
            "communicating",
            "collection",
            "dropped",
            "skynet",
            "youth",
            "com laude",
            "ltd dba",
            "utc submissions",
            "submitters",
            "cloudflarenet",
            "akamaias",
            "digitaloceanasn",
            "csc corporate",
            "pt mora",
            "univjos",
            "etisalat misr",
            "acurix networks",
            "pty ltd",
            "beijing baidu",
            "highly targeted",
            "http",
            "network hijacks",
            "redline stealer",
            "whois sslcert",
            "contacted urls",
            "whois whois",
            "september",
            "hidden cobra",
            "threats",
            "kimsuky",
            "service",
            "read c",
            "create c",
            "write c",
            "regsetvalueexa",
            "mozilla",
            "capture",
            "asnone",
            "domain http",
            "request",
            "malware dns",
            "lookup wannacry",
            "default",
            "ransom",
            "push",
            "playgame",
            "command",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "yara detections",
            "debug",
            "icmp traffic",
            "pdb path",
            "pe section",
            "low software",
            "packing t1045",
            "ransomware",
            "egregor",
            "find",
            "false",
            "psexec",
            "powershell",
            "qakbot",
            "qbot",
            "icedid"
          ],
          "references": [
            "redhatdelete.com",
            "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
            "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
            "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
            "Trojan-Ransom.Win32.Blocker.jgb Checkin",
            "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Australia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
              "target": null
            },
            {
              "id": "Rostpay",
              "display_name": "Rostpay",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Mitre Attack",
              "display_name": "Mitre Attack",
              "target": null
            },
            {
              "id": "Chaos (ELF)",
              "display_name": "Chaos (ELF)",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/GameHack",
              "display_name": "TrojanDropper:Win32/GameHack",
              "target": "/malware/TrojanDropper:Win32/GameHack"
            },
            {
              "id": "Win.Ransomware.Locky-7766366-0",
              "display_name": "Win.Ransomware.Locky-7766366-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt.A!rsm",
              "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
              "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_pid",
              "display_name": "ALF:E5.SpikeAex.rhh_pid",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1107",
              "name": "File Deletion",
              "display_name": "T1107 - File Deletion"
            },
            {
              "id": "T1563",
              "name": "Remote Service Session Hijacking",
              "display_name": "T1563 - Remote Service Session Hijacking"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65d34c8a64436a7aee2e25a1",
          "export_count": 73,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Enqrypted",
            "id": "272105",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_272105/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1848,
            "FileHash-SHA1": 1783,
            "FileHash-SHA256": 7170,
            "domain": 1649,
            "hostname": 1191,
            "email": 9,
            "URL": 729,
            "CVE": 2,
            "SSLCertFingerprint": 2,
            "CIDR": 1
          },
          "indicator_count": 14384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 62,
          "modified_text": "801 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "https://vtbehaviour.commondatastorage.googleapis.com/5d18dde011474fb33b951576a4f40851a3edb37eed2c085cd54523d7205e9022_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192470&Signature=nKlj9vgreN7fYV3U1aG4fv22mUc84blejB1PyhBS4HoWpTcNOqIPDeDH2EU%2BDhrXFrxgNPDfk3m7ZF%2F2VFHNyw%2Fy18TAd1tQZFPmtvCToOOAhp4iER3r08E4vTUOKs4vvPog5yOhlCgy4CJ3K8HbuHA8QH70Xvh1Tuo%2Fi79a3%2FDzxZ5hNMVKsKLXJagoxjHCd22TcfjGcdxpo1%2BYcbwUEXdFba06B1lUSsD8A%2B5X%2BSQdX%2FYfiI8g",
        "CVE-2025-10898/10899/10900: Out-of-Bounds Write vulnerabilities found in parsed MODEL files.",
        "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192564&Signature=bI%2FmFLlckahzDU%2FSDsxXds3czan%2BiIJWhk9ISJRpdCEp7pezQxiWJLiEt13K1Rra8HT9gGSndmBMCsZ3NF46U1JNWcVLzOCiX9Munkk3nn%2BFYv5OJFsJgqkcWu%2F8Q0WDNu%2FURM8wWERVypqMET%2FQwRNd9YHCxjD0j7v0T3XoXaTlWlBFBrShH05u3XPLaW76S8zT69nl8TDRX59iXZrgFHm0v%2FbksZ10TIJ%2BkzCS7CRdNRaqmSI3",
        "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192713&Signature=iX6awMq82XItc5YWXGjoiAr6mGBE7yEqoAv6iPmemNzbuRwWI2nsDjbV5nEvfIl7MtjHOMVwDCRv%2BZ2sjFbIZrahyniPpoGrg69FjdfFMyQPzsYv1Bg5snry%2FW22ROJl%2BMYxKIK1x9hvxXnOtz3SCOY7a31RavAEL%2Fj1rXwDIjrOI%2BtBuen3TYw4ANLBvSUFgMc1FyJpbKIrA%2BIQFzSDTi%2Fa0d9iSrA0Y3shshUY3yMDCspB",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695",
        "https://vtbehaviour.commondatastorage.googleapis.com/5d18dde011474fb33b951576a4f40851a3edb37eed2c085cd54523d7205e9022_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192866&Signature=GgQ76qxY14JaBRGE9w93sbvGI6fl4dPQTxyj4aZlFxsdTWtcYcrMMy5JoQR3aqlBBJrMh19x%2F7%2BJpxBOvHM4CIqSetvdLGlMyJoHTcYJODToEwpJW17TSTZAo5a%2F%2BFnQif%2BRaFVaF9sK6mcWhlcQ0LiRj4ZNO%2FhhAApJM0q3P6KXEuZ%2BTC%2FD%2Bcumt7r8nsdEXwRFQnIKr1dvupZqQVzDJ9%2BA9v7rFKrMcX0adiJp8Mgdih1Swf",
        "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192911&Signature=Iyin7WLwS5Yl%2BLqBc2hNsfMx0vCUDhnnRASgy%2FOR1INoV9I%2FEIwn%2B9EgbBOtpw61w58DMWehC2Zn4kDGLX1D0q1v%2F7i6nAnnTs6fGlksqivhTOBDJLxqo9H2RLeBcFmcT8UDJnz1iRhPvMXVZ%2FEmFDz3WBDyNeoALRLw3ak6DhNDKaxFbjnRHZrmc%2BeEEk9SPXctF7Qd597QPZUzzNLdXY9LvbK2VzgZSdtddTiut7lD1ZHA",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "More elaborate 'text' exploits now exist that allow texts are now being distributed via ai drops in chats in the form of what would appear to be a hyperlink. This is a new genre of elevation in exploit.",
        "The 'test' email aligns perfectly with CVE-2022-30190, as indicated in my findings",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "redhatdelete.com",
        "multiple_versions\tSHA1 of 3f307fecb41ea75bb946e8fde73a3c36b548243411783c036a1e7ae6605e8223\tNo Expiration",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://www.facebook.com/groups/2387525621437001/posts/2775911069265119/",
        "https://www.wcvb.com/article/cohasset-massachusetts-school-employee-power-cryptocurrency-mine/43025932",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Trojan-ransom.win32.blocker.jgb checkin",
            "Mitre attack",
            "Trojandropper:win32/gamehack",
            "Ransom:win32/wannacrypt.a!rsm",
            "Mirai",
            "Alf:e5.spikeaex.rhh_pid",
            "Chaos (elf)",
            "Virtool",
            "Rostpay",
            "Win.ransomware.locky-7766366-0"
          ],
          "industries": [
            "Electricity"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 10,
  "pulses": [
    {
      "id": "69f3f6fc9ae9b2297964a5a4",
      "name": "VirusTotal report          for Test.docx + Other Civic Findings/CVE Linkings",
      "description": "1. CivicPlus.com Threat IndicatorsVT Status: Red Flagged [120+ references, 200+android APKS and tracking configs[js]].Suspicious MD5: 3f307fecb41ea75bb946e8fde73a3c36b548243411783c036a1e7ae6605e8223.Suspicious SHA1: 0ef5ceebb6efa99e12e888a993e56d557dff07fd.Behavioral Pattern: Multiple versions flagged with No Expiration (indicates persistent or hard-coded malicious components in related files).2. HitmanPro Findings (Feb 2025)File Action: Detected as Malware/Suspicious in C:\\Windows\\Installer and user data areas.Note: Typical of behavioral scanning identifying code injection or untrusted signatures, often flagged alongside browser data.3. SSO Autodesk Anomalies (Q1 2025)SAML Assertion Failure: Incorrect objectGUID mapping on IdP side, sending user.objectid as literal string instead of unique identifier. Potential credential abuse or IdP misconfiguration - Attached [Reportscivicplus_vt_red_flag_feb2025.loghmp_scan_022025] + test.docx which shows signs that resemble a test recall email.",
      "modified": "2026-05-31T05:19:13.706000",
      "created": "2026-05-01T00:42:36.613000",
      "tags": [
        "medium",
        "windows",
        "high",
        "alerts",
        "yara detections",
        "worm",
        "https domain",
        "tls sni",
        "io control",
        "installs",
        "virustotal",
        "copy",
        "explorer",
        "malware",
        "config by town",
        "civicplus",
        "beyond surveillance",
        "significant overreach"
      ],
      "references": [
        "multiple_versions\tSHA1 of 3f307fecb41ea75bb946e8fde73a3c36b548243411783c036a1e7ae6605e8223\tNo Expiration",
        "",
        "CVE-2025-10898/10899/10900: Out-of-Bounds Write vulnerabilities found in parsed MODEL files.",
        "More elaborate 'text' exploits now exist that allow texts are now being distributed via ai drops in chats in the form of what would appear to be a hyperlink. This is a new genre of elevation in exploit.",
        "The 'test' email aligns perfectly with CVE-2022-30190, as indicated in my findings"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1010,
        "FileHash-SHA1": 437,
        "FileHash-SHA256": 2319,
        "URL": 637,
        "email": 14,
        "hostname": 468,
        "domain": 101,
        "IPv4": 298,
        "IPv6": 96,
        "CVE": 9
      },
      "indicator_count": 5389,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "2 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69eae966e2994ca9410416e7",
      "name": "CAPE Sandbox - Watson",
      "description": "[full list of details about Akamai, the web hosting company, that has been abused on the internet for more than 20 years.. and the names of its users have been published.] pretext. Watson frequents. wizard8.",
      "modified": "2026-05-24T05:16:16.520000",
      "created": "2026-04-24T03:54:14.835000",
      "tags": [
        "akamai",
        "city",
        "noc united",
        "orgid",
        "akamai ref",
        "net23",
        "net230000",
        "cidr",
        "orgabusehandle",
        "orgtechhandle"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1406",
          "name": "Obfuscated Files or Information",
          "display_name": "T1406 - Obfuscated Files or Information"
        },
        {
          "id": "T1409",
          "name": "Access Stored Application Data",
          "display_name": "T1409 - Access Stored Application Data"
        },
        {
          "id": "T1421",
          "name": "System Network Connections Discovery",
          "display_name": "T1421 - System Network Connections Discovery"
        },
        {
          "id": "T1424",
          "name": "Process Discovery",
          "display_name": "T1424 - Process Discovery"
        },
        {
          "id": "T1426",
          "name": "System Information Discovery",
          "display_name": "T1426 - System Information Discovery"
        },
        {
          "id": "T1430",
          "name": "Location Tracking",
          "display_name": "T1430 - Location Tracking"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 382,
        "FileHash-SHA1": 361,
        "FileHash-SHA256": 1250,
        "URL": 1436,
        "domain": 425,
        "hostname": 783,
        "CIDR": 1,
        "email": 29,
        "CVE": 1,
        "URI": 2
      },
      "indicator_count": 4670,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "7 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f97a905451e3304319988b",
      "name": ".may 4 clone own on may 5",
      "description": "",
      "modified": "2026-05-07T02:57:38.229000",
      "created": "2026-05-05T05:05:20.493000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "69f7fa1a282840a6e0aa370c",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 341,
        "FileHash-SHA1": 368,
        "FileHash-SHA256": 3143,
        "hostname": 2037,
        "IPv4": 186,
        "URL": 3288,
        "CIDR": 12,
        "email": 43,
        "domain": 1645,
        "URI": 1,
        "SSLCertFingerprint": 18,
        "CVE": 1
      },
      "indicator_count": 11083,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f7fa1a282840a6e0aa370c",
      "name": "May the 4th be with... every destructed file that never died",
      "description": "[undreds of thousands of people have been signing a petition calling for the removal of the president, Barack Obama, from the White House and the UK's prime minister, Theresa May, to be remove] The wording here. Its also May3rd not May 4th.",
      "modified": "2026-05-05T05:04:02.911000",
      "created": "2026-05-04T01:44:57.811000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 341,
        "FileHash-SHA1": 368,
        "FileHash-SHA256": 3142,
        "hostname": 1890,
        "IPv4": 162,
        "URL": 3241,
        "CIDR": 12,
        "email": 37,
        "domain": 1616,
        "URI": 1,
        "SSLCertFingerprint": 18
      },
      "indicator_count": 10828,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69cf4aaed5e28797e2096a95",
      "name": "VirusTotal report\n                    for index.html",
      "description": "<NULL>",
      "modified": "2026-05-03T05:20:14.651000",
      "created": "2026-04-03T05:05:50.814000",
      "tags": [
        "mitre attack",
        "network info",
        "processes extra",
        "performs dns",
        "t1055 process",
        "overview",
        "overview zenbox",
        "verdict",
        "guest system",
        "ultimate file",
        "meta",
        "phishing",
        "next",
        "cohasset high school",
        "massachusetts",
        "nadeam nahas",
        "cryptomining",
        "wcvb",
        "cohasset",
        "gordon",
        "nahas",
        "department",
        "cohasset police",
        "crypto mining",
        "karen anderson",
        "high school",
        "school",
        "bitcoin",
        "copy",
        "https",
        "urls",
        "html page",
        "layer protocol",
        "united",
        "title",
        "air assault",
        "band",
        "script",
        "press",
        "hold",
        "doctype html",
        "access",
        "head",
        "perimeterx",
        "pxosx7m0dx",
        "import",
        "body",
        "android",
        "zip archive",
        "xapk android",
        "android package",
        "java archive",
        "sweet home",
        "design"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/5d18dde011474fb33b951576a4f40851a3edb37eed2c085cd54523d7205e9022_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192470&Signature=nKlj9vgreN7fYV3U1aG4fv22mUc84blejB1PyhBS4HoWpTcNOqIPDeDH2EU%2BDhrXFrxgNPDfk3m7ZF%2F2VFHNyw%2Fy18TAd1tQZFPmtvCToOOAhp4iER3r08E4vTUOKs4vvPog5yOhlCgy4CJ3K8HbuHA8QH70Xvh1Tuo%2Fi79a3%2FDzxZ5hNMVKsKLXJagoxjHCd22TcfjGcdxpo1%2BYcbwUEXdFba06B1lUSsD8A%2B5X%2BSQdX%2FYfiI8g",
        "https://www.wcvb.com/article/cohasset-massachusetts-school-employee-power-cryptocurrency-mine/43025932",
        "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192564&Signature=bI%2FmFLlckahzDU%2FSDsxXds3czan%2BiIJWhk9ISJRpdCEp7pezQxiWJLiEt13K1Rra8HT9gGSndmBMCsZ3NF46U1JNWcVLzOCiX9Munkk3nn%2BFYv5OJFsJgqkcWu%2F8Q0WDNu%2FURM8wWERVypqMET%2FQwRNd9YHCxjD0j7v0T3XoXaTlWlBFBrShH05u3XPLaW76S8zT69nl8TDRX59iXZrgFHm0v%2FbksZ10TIJ%2BkzCS7CRdNRaqmSI3",
        "https://www.facebook.com/groups/2387525621437001/posts/2775911069265119/",
        "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192713&Signature=iX6awMq82XItc5YWXGjoiAr6mGBE7yEqoAv6iPmemNzbuRwWI2nsDjbV5nEvfIl7MtjHOMVwDCRv%2BZ2sjFbIZrahyniPpoGrg69FjdfFMyQPzsYv1Bg5snry%2FW22ROJl%2BMYxKIK1x9hvxXnOtz3SCOY7a31RavAEL%2Fj1rXwDIjrOI%2BtBuen3TYw4ANLBvSUFgMc1FyJpbKIrA%2BIQFzSDTi%2Fa0d9iSrA0Y3shshUY3yMDCspB",
        "https://vtbehaviour.commondatastorage.googleapis.com/5d18dde011474fb33b951576a4f40851a3edb37eed2c085cd54523d7205e9022_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192866&Signature=GgQ76qxY14JaBRGE9w93sbvGI6fl4dPQTxyj4aZlFxsdTWtcYcrMMy5JoQR3aqlBBJrMh19x%2F7%2BJpxBOvHM4CIqSetvdLGlMyJoHTcYJODToEwpJW17TSTZAo5a%2F%2BFnQif%2BRaFVaF9sK6mcWhlcQ0LiRj4ZNO%2FhhAApJM0q3P6KXEuZ%2BTC%2FD%2Bcumt7r8nsdEXwRFQnIKr1dvupZqQVzDJ9%2BA9v7rFKrMcX0adiJp8Mgdih1Swf",
        "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192911&Signature=Iyin7WLwS5Yl%2BLqBc2hNsfMx0vCUDhnnRASgy%2FOR1INoV9I%2FEIwn%2B9EgbBOtpw61w58DMWehC2Zn4kDGLX1D0q1v%2F7i6nAnnTs6fGlksqivhTOBDJLxqo9H2RLeBcFmcT8UDJnz1iRhPvMXVZ%2FEmFDz3WBDyNeoALRLw3ak6DhNDKaxFbjnRHZrmc%2BeEEk9SPXctF7Qd597QPZUzzNLdXY9LvbK2VzgZSdtddTiut7lD1ZHA"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [
        "Electricity"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 70,
        "URL": 117,
        "domain": 13,
        "FileHash-MD5": 7,
        "FileHash-SHA1": 4,
        "hostname": 66
      },
      "indicator_count": 277,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "28 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69cf4aaf485e182cdfef51e0",
      "name": "VirusTotal report\n                    for index.html",
      "description": "<NULL>",
      "modified": "2026-05-03T05:20:14.651000",
      "created": "2026-04-03T05:05:51.290000",
      "tags": [
        "mitre attack",
        "network info",
        "processes extra",
        "performs dns",
        "t1055 process",
        "overview",
        "overview zenbox",
        "verdict",
        "guest system",
        "ultimate file",
        "meta",
        "phishing",
        "next",
        "cohasset high school",
        "massachusetts",
        "nadeam nahas",
        "cryptomining",
        "wcvb",
        "cohasset",
        "gordon",
        "nahas",
        "department",
        "cohasset police",
        "crypto mining",
        "karen anderson",
        "high school",
        "school",
        "bitcoin",
        "copy",
        "https",
        "urls",
        "html page",
        "layer protocol",
        "united",
        "title",
        "air assault",
        "band",
        "script",
        "press",
        "hold",
        "doctype html",
        "access",
        "head",
        "perimeterx",
        "pxosx7m0dx",
        "import",
        "body",
        "android",
        "zip archive",
        "xapk android",
        "android package",
        "java archive",
        "sweet home",
        "design"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/5d18dde011474fb33b951576a4f40851a3edb37eed2c085cd54523d7205e9022_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192470&Signature=nKlj9vgreN7fYV3U1aG4fv22mUc84blejB1PyhBS4HoWpTcNOqIPDeDH2EU%2BDhrXFrxgNPDfk3m7ZF%2F2VFHNyw%2Fy18TAd1tQZFPmtvCToOOAhp4iER3r08E4vTUOKs4vvPog5yOhlCgy4CJ3K8HbuHA8QH70Xvh1Tuo%2Fi79a3%2FDzxZ5hNMVKsKLXJagoxjHCd22TcfjGcdxpo1%2BYcbwUEXdFba06B1lUSsD8A%2B5X%2BSQdX%2FYfiI8g",
        "https://www.wcvb.com/article/cohasset-massachusetts-school-employee-power-cryptocurrency-mine/43025932",
        "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192564&Signature=bI%2FmFLlckahzDU%2FSDsxXds3czan%2BiIJWhk9ISJRpdCEp7pezQxiWJLiEt13K1Rra8HT9gGSndmBMCsZ3NF46U1JNWcVLzOCiX9Munkk3nn%2BFYv5OJFsJgqkcWu%2F8Q0WDNu%2FURM8wWERVypqMET%2FQwRNd9YHCxjD0j7v0T3XoXaTlWlBFBrShH05u3XPLaW76S8zT69nl8TDRX59iXZrgFHm0v%2FbksZ10TIJ%2BkzCS7CRdNRaqmSI3",
        "https://www.facebook.com/groups/2387525621437001/posts/2775911069265119/",
        "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192713&Signature=iX6awMq82XItc5YWXGjoiAr6mGBE7yEqoAv6iPmemNzbuRwWI2nsDjbV5nEvfIl7MtjHOMVwDCRv%2BZ2sjFbIZrahyniPpoGrg69FjdfFMyQPzsYv1Bg5snry%2FW22ROJl%2BMYxKIK1x9hvxXnOtz3SCOY7a31RavAEL%2Fj1rXwDIjrOI%2BtBuen3TYw4ANLBvSUFgMc1FyJpbKIrA%2BIQFzSDTi%2Fa0d9iSrA0Y3shshUY3yMDCspB",
        "https://vtbehaviour.commondatastorage.googleapis.com/5d18dde011474fb33b951576a4f40851a3edb37eed2c085cd54523d7205e9022_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192866&Signature=GgQ76qxY14JaBRGE9w93sbvGI6fl4dPQTxyj4aZlFxsdTWtcYcrMMy5JoQR3aqlBBJrMh19x%2F7%2BJpxBOvHM4CIqSetvdLGlMyJoHTcYJODToEwpJW17TSTZAo5a%2F%2BFnQif%2BRaFVaF9sK6mcWhlcQ0LiRj4ZNO%2FhhAApJM0q3P6KXEuZ%2BTC%2FD%2Bcumt7r8nsdEXwRFQnIKr1dvupZqQVzDJ9%2BA9v7rFKrMcX0adiJp8Mgdih1Swf",
        "https://vtbehaviour.commondatastorage.googleapis.com/42898d2ebf09851fe965b7055c2ec3c0eb22f029ac013f7f1f0894f2dc9f56ec_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775192911&Signature=Iyin7WLwS5Yl%2BLqBc2hNsfMx0vCUDhnnRASgy%2FOR1INoV9I%2FEIwn%2B9EgbBOtpw61w58DMWehC2Zn4kDGLX1D0q1v%2F7i6nAnnTs6fGlksqivhTOBDJLxqo9H2RLeBcFmcT8UDJnz1iRhPvMXVZ%2FEmFDz3WBDyNeoALRLw3ak6DhNDKaxFbjnRHZrmc%2BeEEk9SPXctF7Qd597QPZUzzNLdXY9LvbK2VzgZSdtddTiut7lD1ZHA"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [
        "Electricity"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 70,
        "URL": 117,
        "domain": 13,
        "FileHash-MD5": 7,
        "FileHash-SHA1": 4,
        "hostname": 66
      },
      "indicator_count": 277,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "28 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65d34c8a64436a7aee2e25a1",
      "name": "Locky: File Deletion targeting incriminating archived files.",
      "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
      "modified": "2024-03-20T12:00:39.809000",
      "created": "2024-02-19T12:41:46.707000",
      "tags": [
        "it consultant",
        "uk collection",
        "dns intel",
        "ips collection",
        "suspicous ip",
        "whois file",
        "cname",
        "record type",
        "ttl value",
        "algorithm",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "whois lookup",
        "region create",
        "domain",
        "name server",
        "registrant name",
        "technical city",
        "region update",
        "united",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "ck id",
        "cookie",
        "meta",
        "february",
        "hybrid",
        "general",
        "click",
        "strings",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "dns replication",
        "code",
        "namecheap",
        "registrar abuse",
        "namecheap inc",
        "privacy service",
        "withheld",
        "privacy",
        "dnssec",
        "email",
        "first",
        "bodis",
        "unknown",
        "creation date",
        "search",
        "emails",
        "as397240",
        "date",
        "next",
        "all octoseek",
        "threat roundup",
        "january",
        "june",
        "historical ssl",
        "referrer",
        "contacted",
        "group",
        "execution",
        "phishing",
        "malware",
        "core",
        "malicious",
        "dark power",
        "play ransomware",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 linker",
        "gnu linker",
        "compiler",
        "info header",
        "name md5",
        "overlay",
        "passive dns",
        "entries",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "trojan",
        "location united",
        "query",
        "activity dns",
        "observed dns",
        "msie",
        "high",
        "copy",
        "write",
        "win32",
        "hashes",
        "host interaction",
        "sabey type",
        "hallrender",
        "brian sabey",
        "memory pattern",
        "http requests",
        "http method",
        "get response",
        "dns resolutions",
        "ip traffic",
        "domains",
        "mutex",
        "samplepath",
        "created",
        "shell commands",
        "r processes",
        "tree",
        "analyze",
        "hostnames",
        "url https",
        "samples",
        "hostname",
        "pattern urls",
        "memory",
        "pattern",
        "pattern domains",
        "roundup",
        "formbook",
        "mirai",
        "ben c",
        "injection",
        "server",
        "scan endpoints",
        "show",
        "august",
        "bq feb",
        "chrome",
        "precondition",
        "virtool",
        "downloadmr",
        "body",
        "status",
        "servers",
        "record value",
        "name servers",
        "showing",
        "mailrubar",
        "trojanclicker",
        "slcc2",
        "media center",
        "delete c",
        "malware beacon",
        "suspicious",
        "class",
        "internal",
        "local",
        "encrypt",
        "as15169 google",
        "gmt cache",
        "twitter",
        "rostpay",
        "date hash",
        "avast avg",
        "mtb may",
        "susp",
        "cryp",
        "win32upatre may",
        "mtb showing",
        "lowfi",
        "aaaa",
        "win32pcmega jan",
        "urlshortner dec",
        "urlshortner sep",
        "as133618",
        "nxdomain",
        "as133775 xiamen",
        "germany unknown",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "whois record",
        "ssl certificate",
        "tsara brashears",
        "resolutions",
        "critical risk",
        "apple phone",
        "unlocker",
        "shell code",
        "installer",
        "ursnif",
        "hacktool",
        "emotet",
        "tracker",
        "chaos",
        "ransomexx",
        "xor ddos",
        "xorddos",
        "mitre attack",
        "parent domain",
        "urls url",
        "siblings",
        "metro",
        "communicating",
        "collection",
        "dropped",
        "skynet",
        "youth",
        "com laude",
        "ltd dba",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "akamaias",
        "digitaloceanasn",
        "csc corporate",
        "pt mora",
        "univjos",
        "etisalat misr",
        "acurix networks",
        "pty ltd",
        "beijing baidu",
        "highly targeted",
        "http",
        "network hijacks",
        "redline stealer",
        "whois sslcert",
        "contacted urls",
        "whois whois",
        "september",
        "hidden cobra",
        "threats",
        "kimsuky",
        "service",
        "read c",
        "create c",
        "write c",
        "regsetvalueexa",
        "mozilla",
        "capture",
        "asnone",
        "domain http",
        "request",
        "malware dns",
        "lookup wannacry",
        "default",
        "ransom",
        "push",
        "playgame",
        "command",
        "email document",
        "exploit domain",
        "owner exploit",
        "kit exploit",
        "source file",
        "hacking tools",
        "hunting macro",
        "malware hosting",
        "memory scanning",
        "yara detections",
        "debug",
        "icmp traffic",
        "pdb path",
        "pe section",
        "low software",
        "packing t1045",
        "ransomware",
        "egregor",
        "find",
        "false",
        "psexec",
        "powershell",
        "qakbot",
        "qbot",
        "icedid"
      ],
      "references": [
        "redhatdelete.com",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Australia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "target": null
        },
        {
          "id": "Rostpay",
          "display_name": "Rostpay",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Mitre Attack",
          "display_name": "Mitre Attack",
          "target": null
        },
        {
          "id": "Chaos (ELF)",
          "display_name": "Chaos (ELF)",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/GameHack",
          "display_name": "TrojanDropper:Win32/GameHack",
          "target": "/malware/TrojanDropper:Win32/GameHack"
        },
        {
          "id": "Win.Ransomware.Locky-7766366-0",
          "display_name": "Win.Ransomware.Locky-7766366-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "ALF:E5.SpikeAex.rhh_pid",
          "display_name": "ALF:E5.SpikeAex.rhh_pid",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1107",
          "name": "File Deletion",
          "display_name": "T1107 - File Deletion"
        },
        {
          "id": "T1563",
          "name": "Remote Service Session Hijacking",
          "display_name": "T1563 - Remote Service Session Hijacking"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 65,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1848,
        "FileHash-SHA1": 1783,
        "FileHash-SHA256": 7170,
        "domain": 1649,
        "hostname": 1191,
        "email": 9,
        "URL": 729,
        "CVE": 2,
        "SSLCertFingerprint": 2,
        "CIDR": 1
      },
      "indicator_count": 14384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "801 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65d34c91868744aa1449fef2",
      "name": "Locky: File Deletion targeting incriminating archived files.",
      "description": "redhatdelete.com : Adversaries are deleting files in bulk  from Virustotal, otx AlienVault, WebArchive, Perma.cc Urlscan.io, Archive.Today, Archive.ph, iCloud, apple data, photo deletion.\nVarious ransomware used. iOS service modified, cloud encrypted by adversary. Indicator point to a target with a zombie device. An iPhone and potentially other devices were targeted in a specific attack. | Locky Ransomware is a piece of malware that encrypts important files on your device, rendering them inaccessible and unusable.",
      "modified": "2024-03-20T12:00:39.809000",
      "created": "2024-02-19T12:41:52.846000",
      "tags": [
        "it consultant",
        "uk collection",
        "dns intel",
        "ips collection",
        "suspicous ip",
        "whois file",
        "cname",
        "record type",
        "ttl value",
        "algorithm",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "whois lookup",
        "region create",
        "domain",
        "name server",
        "registrant name",
        "technical city",
        "region update",
        "united",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "ck id",
        "cookie",
        "meta",
        "february",
        "hybrid",
        "general",
        "click",
        "strings",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "dns replication",
        "code",
        "namecheap",
        "registrar abuse",
        "namecheap inc",
        "privacy service",
        "withheld",
        "privacy",
        "dnssec",
        "email",
        "first",
        "bodis",
        "unknown",
        "creation date",
        "search",
        "emails",
        "as397240",
        "date",
        "next",
        "all octoseek",
        "threat roundup",
        "january",
        "june",
        "historical ssl",
        "referrer",
        "contacted",
        "group",
        "execution",
        "phishing",
        "malware",
        "core",
        "malicious",
        "dark power",
        "play ransomware",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 linker",
        "gnu linker",
        "compiler",
        "info header",
        "name md5",
        "overlay",
        "passive dns",
        "entries",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "trojan",
        "location united",
        "query",
        "activity dns",
        "observed dns",
        "msie",
        "high",
        "copy",
        "write",
        "win32",
        "hashes",
        "host interaction",
        "sabey type",
        "hallrender",
        "brian sabey",
        "memory pattern",
        "http requests",
        "http method",
        "get response",
        "dns resolutions",
        "ip traffic",
        "domains",
        "mutex",
        "samplepath",
        "created",
        "shell commands",
        "r processes",
        "tree",
        "analyze",
        "hostnames",
        "url https",
        "samples",
        "hostname",
        "pattern urls",
        "memory",
        "pattern",
        "pattern domains",
        "roundup",
        "formbook",
        "mirai",
        "ben c",
        "injection",
        "server",
        "scan endpoints",
        "show",
        "august",
        "bq feb",
        "chrome",
        "precondition",
        "virtool",
        "downloadmr",
        "body",
        "status",
        "servers",
        "record value",
        "name servers",
        "showing",
        "mailrubar",
        "trojanclicker",
        "slcc2",
        "media center",
        "delete c",
        "malware beacon",
        "suspicious",
        "class",
        "internal",
        "local",
        "encrypt",
        "as15169 google",
        "gmt cache",
        "twitter",
        "rostpay",
        "date hash",
        "avast avg",
        "mtb may",
        "susp",
        "cryp",
        "win32upatre may",
        "mtb showing",
        "lowfi",
        "aaaa",
        "win32pcmega jan",
        "urlshortner dec",
        "urlshortner sep",
        "as133618",
        "nxdomain",
        "as133775 xiamen",
        "germany unknown",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "whois record",
        "ssl certificate",
        "tsara brashears",
        "resolutions",
        "critical risk",
        "apple phone",
        "unlocker",
        "shell code",
        "installer",
        "ursnif",
        "hacktool",
        "emotet",
        "tracker",
        "chaos",
        "ransomexx",
        "xor ddos",
        "xorddos",
        "mitre attack",
        "parent domain",
        "urls url",
        "siblings",
        "metro",
        "communicating",
        "collection",
        "dropped",
        "skynet",
        "youth",
        "com laude",
        "ltd dba",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "akamaias",
        "digitaloceanasn",
        "csc corporate",
        "pt mora",
        "univjos",
        "etisalat misr",
        "acurix networks",
        "pty ltd",
        "beijing baidu",
        "highly targeted",
        "http",
        "network hijacks",
        "redline stealer",
        "whois sslcert",
        "contacted urls",
        "whois whois",
        "september",
        "hidden cobra",
        "threats",
        "kimsuky",
        "service",
        "read c",
        "create c",
        "write c",
        "regsetvalueexa",
        "mozilla",
        "capture",
        "asnone",
        "domain http",
        "request",
        "malware dns",
        "lookup wannacry",
        "default",
        "ransom",
        "push",
        "playgame",
        "command",
        "email document",
        "exploit domain",
        "owner exploit",
        "kit exploit",
        "source file",
        "hacking tools",
        "hunting macro",
        "malware hosting",
        "memory scanning",
        "yara detections",
        "debug",
        "icmp traffic",
        "pdb path",
        "pe section",
        "low software",
        "packing t1045",
        "ransomware",
        "egregor",
        "find",
        "false",
        "psexec",
        "powershell",
        "qakbot",
        "qbot",
        "icedid"
      ],
      "references": [
        "redhatdelete.com",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Australia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "target": null
        },
        {
          "id": "Rostpay",
          "display_name": "Rostpay",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Mitre Attack",
          "display_name": "Mitre Attack",
          "target": null
        },
        {
          "id": "Chaos (ELF)",
          "display_name": "Chaos (ELF)",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/GameHack",
          "display_name": "TrojanDropper:Win32/GameHack",
          "target": "/malware/TrojanDropper:Win32/GameHack"
        },
        {
          "id": "Win.Ransomware.Locky-7766366-0",
          "display_name": "Win.Ransomware.Locky-7766366-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "ALF:E5.SpikeAex.rhh_pid",
          "display_name": "ALF:E5.SpikeAex.rhh_pid",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1107",
          "name": "File Deletion",
          "display_name": "T1107 - File Deletion"
        },
        {
          "id": "T1563",
          "name": "Remote Service Session Hijacking",
          "display_name": "T1563 - Remote Service Session Hijacking"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 57,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1848,
        "FileHash-SHA1": 1783,
        "FileHash-SHA256": 7170,
        "domain": 1649,
        "hostname": 1191,
        "email": 9,
        "URL": 729,
        "CVE": 2,
        "SSLCertFingerprint": 2,
        "CIDR": 1
      },
      "indicator_count": 14384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "801 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65d3acf32e1088e76165a307",
      "name": "Locky: File Deletion targeting incriminating archived files.",
      "description": "",
      "modified": "2024-03-20T12:00:39.809000",
      "created": "2024-02-19T19:33:07.504000",
      "tags": [
        "it consultant",
        "uk collection",
        "dns intel",
        "ips collection",
        "suspicous ip",
        "whois file",
        "cname",
        "record type",
        "ttl value",
        "algorithm",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "whois lookup",
        "region create",
        "domain",
        "name server",
        "registrant name",
        "technical city",
        "region update",
        "united",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "ck id",
        "cookie",
        "meta",
        "february",
        "hybrid",
        "general",
        "click",
        "strings",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "dns replication",
        "code",
        "namecheap",
        "registrar abuse",
        "namecheap inc",
        "privacy service",
        "withheld",
        "privacy",
        "dnssec",
        "email",
        "first",
        "bodis",
        "unknown",
        "creation date",
        "search",
        "emails",
        "as397240",
        "date",
        "next",
        "all octoseek",
        "threat roundup",
        "january",
        "june",
        "historical ssl",
        "referrer",
        "contacted",
        "group",
        "execution",
        "phishing",
        "malware",
        "core",
        "malicious",
        "dark power",
        "play ransomware",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 linker",
        "gnu linker",
        "compiler",
        "info header",
        "name md5",
        "overlay",
        "passive dns",
        "entries",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "trojan",
        "location united",
        "query",
        "activity dns",
        "observed dns",
        "msie",
        "high",
        "copy",
        "write",
        "win32",
        "hashes",
        "host interaction",
        "sabey type",
        "hallrender",
        "brian sabey",
        "memory pattern",
        "http requests",
        "http method",
        "get response",
        "dns resolutions",
        "ip traffic",
        "domains",
        "mutex",
        "samplepath",
        "created",
        "shell commands",
        "r processes",
        "tree",
        "analyze",
        "hostnames",
        "url https",
        "samples",
        "hostname",
        "pattern urls",
        "memory",
        "pattern",
        "pattern domains",
        "roundup",
        "formbook",
        "mirai",
        "ben c",
        "injection",
        "server",
        "scan endpoints",
        "show",
        "august",
        "bq feb",
        "chrome",
        "precondition",
        "virtool",
        "downloadmr",
        "body",
        "status",
        "servers",
        "record value",
        "name servers",
        "showing",
        "mailrubar",
        "trojanclicker",
        "slcc2",
        "media center",
        "delete c",
        "malware beacon",
        "suspicious",
        "class",
        "internal",
        "local",
        "encrypt",
        "as15169 google",
        "gmt cache",
        "twitter",
        "rostpay",
        "date hash",
        "avast avg",
        "mtb may",
        "susp",
        "cryp",
        "win32upatre may",
        "mtb showing",
        "lowfi",
        "aaaa",
        "win32pcmega jan",
        "urlshortner dec",
        "urlshortner sep",
        "as133618",
        "nxdomain",
        "as133775 xiamen",
        "germany unknown",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "whois record",
        "ssl certificate",
        "tsara brashears",
        "resolutions",
        "critical risk",
        "apple phone",
        "unlocker",
        "shell code",
        "installer",
        "ursnif",
        "hacktool",
        "emotet",
        "tracker",
        "chaos",
        "ransomexx",
        "xor ddos",
        "xorddos",
        "mitre attack",
        "parent domain",
        "urls url",
        "siblings",
        "metro",
        "communicating",
        "collection",
        "dropped",
        "skynet",
        "youth",
        "com laude",
        "ltd dba",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "akamaias",
        "digitaloceanasn",
        "csc corporate",
        "pt mora",
        "univjos",
        "etisalat misr",
        "acurix networks",
        "pty ltd",
        "beijing baidu",
        "highly targeted",
        "http",
        "network hijacks",
        "redline stealer",
        "whois sslcert",
        "contacted urls",
        "whois whois",
        "september",
        "hidden cobra",
        "threats",
        "kimsuky",
        "service",
        "read c",
        "create c",
        "write c",
        "regsetvalueexa",
        "mozilla",
        "capture",
        "asnone",
        "domain http",
        "request",
        "malware dns",
        "lookup wannacry",
        "default",
        "ransom",
        "push",
        "playgame",
        "command",
        "email document",
        "exploit domain",
        "owner exploit",
        "kit exploit",
        "source file",
        "hacking tools",
        "hunting macro",
        "malware hosting",
        "memory scanning",
        "yara detections",
        "debug",
        "icmp traffic",
        "pdb path",
        "pe section",
        "low software",
        "packing t1045",
        "ransomware",
        "egregor",
        "find",
        "false",
        "psexec",
        "powershell",
        "qakbot",
        "qbot",
        "icedid"
      ],
      "references": [
        "redhatdelete.com",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Australia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "target": null
        },
        {
          "id": "Rostpay",
          "display_name": "Rostpay",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Mitre Attack",
          "display_name": "Mitre Attack",
          "target": null
        },
        {
          "id": "Chaos (ELF)",
          "display_name": "Chaos (ELF)",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/GameHack",
          "display_name": "TrojanDropper:Win32/GameHack",
          "target": "/malware/TrojanDropper:Win32/GameHack"
        },
        {
          "id": "Win.Ransomware.Locky-7766366-0",
          "display_name": "Win.Ransomware.Locky-7766366-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "ALF:E5.SpikeAex.rhh_pid",
          "display_name": "ALF:E5.SpikeAex.rhh_pid",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1107",
          "name": "File Deletion",
          "display_name": "T1107 - File Deletion"
        },
        {
          "id": "T1563",
          "name": "Remote Service Session Hijacking",
          "display_name": "T1563 - Remote Service Session Hijacking"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65d34c91868744aa1449fef2",
      "export_count": 64,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1848,
        "FileHash-SHA1": 1783,
        "FileHash-SHA256": 7170,
        "domain": 1649,
        "hostname": 1191,
        "email": 9,
        "URL": 729,
        "CVE": 2,
        "SSLCertFingerprint": 2,
        "CIDR": 1
      },
      "indicator_count": 14384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 234,
      "modified_text": "801 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65d3c31230455f6d8da3a9f0",
      "name": "Locky: File Deletion targeting incriminating archived files II",
      "description": "",
      "modified": "2024-03-20T12:00:39.809000",
      "created": "2024-02-19T21:07:30.887000",
      "tags": [
        "it consultant",
        "uk collection",
        "dns intel",
        "ips collection",
        "suspicous ip",
        "whois file",
        "cname",
        "record type",
        "ttl value",
        "algorithm",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "whois lookup",
        "region create",
        "domain",
        "name server",
        "registrant name",
        "technical city",
        "region update",
        "united",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "ck id",
        "cookie",
        "meta",
        "february",
        "hybrid",
        "general",
        "click",
        "strings",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls http",
        "dns replication",
        "code",
        "namecheap",
        "registrar abuse",
        "namecheap inc",
        "privacy service",
        "withheld",
        "privacy",
        "dnssec",
        "email",
        "first",
        "bodis",
        "unknown",
        "creation date",
        "search",
        "emails",
        "as397240",
        "date",
        "next",
        "all octoseek",
        "threat roundup",
        "january",
        "june",
        "historical ssl",
        "referrer",
        "contacted",
        "group",
        "execution",
        "phishing",
        "malware",
        "core",
        "malicious",
        "dark power",
        "play ransomware",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 linker",
        "gnu linker",
        "compiler",
        "info header",
        "name md5",
        "overlay",
        "passive dns",
        "entries",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "trojan",
        "location united",
        "query",
        "activity dns",
        "observed dns",
        "msie",
        "high",
        "copy",
        "write",
        "win32",
        "hashes",
        "host interaction",
        "sabey type",
        "hallrender",
        "brian sabey",
        "memory pattern",
        "http requests",
        "http method",
        "get response",
        "dns resolutions",
        "ip traffic",
        "domains",
        "mutex",
        "samplepath",
        "created",
        "shell commands",
        "r processes",
        "tree",
        "analyze",
        "hostnames",
        "url https",
        "samples",
        "hostname",
        "pattern urls",
        "memory",
        "pattern",
        "pattern domains",
        "roundup",
        "formbook",
        "mirai",
        "ben c",
        "injection",
        "server",
        "scan endpoints",
        "show",
        "august",
        "bq feb",
        "chrome",
        "precondition",
        "virtool",
        "downloadmr",
        "body",
        "status",
        "servers",
        "record value",
        "name servers",
        "showing",
        "mailrubar",
        "trojanclicker",
        "slcc2",
        "media center",
        "delete c",
        "malware beacon",
        "suspicious",
        "class",
        "internal",
        "local",
        "encrypt",
        "as15169 google",
        "gmt cache",
        "twitter",
        "rostpay",
        "date hash",
        "avast avg",
        "mtb may",
        "susp",
        "cryp",
        "win32upatre may",
        "mtb showing",
        "lowfi",
        "aaaa",
        "win32pcmega jan",
        "urlshortner dec",
        "urlshortner sep",
        "as133618",
        "nxdomain",
        "as133775 xiamen",
        "germany unknown",
        "webtoolbar",
        "nanocore rat",
        "gamehack",
        "cobalt strike",
        "whois record",
        "ssl certificate",
        "tsara brashears",
        "resolutions",
        "critical risk",
        "apple phone",
        "unlocker",
        "shell code",
        "installer",
        "ursnif",
        "hacktool",
        "emotet",
        "tracker",
        "chaos",
        "ransomexx",
        "xor ddos",
        "xorddos",
        "mitre attack",
        "parent domain",
        "urls url",
        "siblings",
        "metro",
        "communicating",
        "collection",
        "dropped",
        "skynet",
        "youth",
        "com laude",
        "ltd dba",
        "utc submissions",
        "submitters",
        "cloudflarenet",
        "akamaias",
        "digitaloceanasn",
        "csc corporate",
        "pt mora",
        "univjos",
        "etisalat misr",
        "acurix networks",
        "pty ltd",
        "beijing baidu",
        "highly targeted",
        "http",
        "network hijacks",
        "redline stealer",
        "whois sslcert",
        "contacted urls",
        "whois whois",
        "september",
        "hidden cobra",
        "threats",
        "kimsuky",
        "service",
        "read c",
        "create c",
        "write c",
        "regsetvalueexa",
        "mozilla",
        "capture",
        "asnone",
        "domain http",
        "request",
        "malware dns",
        "lookup wannacry",
        "default",
        "ransom",
        "push",
        "playgame",
        "command",
        "email document",
        "exploit domain",
        "owner exploit",
        "kit exploit",
        "source file",
        "hacking tools",
        "hunting macro",
        "malware hosting",
        "memory scanning",
        "yara detections",
        "debug",
        "icmp traffic",
        "pdb path",
        "pe section",
        "low software",
        "packing t1045",
        "ransomware",
        "egregor",
        "find",
        "false",
        "psexec",
        "powershell",
        "qakbot",
        "qbot",
        "icedid"
      ],
      "references": [
        "redhatdelete.com",
        "Mutexes Opened {0C8E6D89-EA51-848A-7775-6C2CC072CA88}",
        "explorer.exe \u2022  Explorer.EXE \u2022\tupnaneat-xex.exe \u2022 akgibik.exe \u2022 wmiadap.exe \u2022 wmiprvse.exe \u2022 winlogon.exe \u2022 tmpo3rfa1vg.exe",
        "https://otx.alienvault.com/indicator/file/f58f360a1f6b5e3e28fa64dd88ec2c9893f2f1d290f4a8cf67ac49952e32cc60",
        "Trojan-Ransom.Win32.Blocker.jgb Checkin",
        "https://otx.alienvault.com/indicator/file/000ad3f22cedbd36e425ca046b2aa0c228754b6fd94d30105ad9343ad9742695"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Australia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "display_name": "Trojan-Ransom.Win32.Blocker.jgb Checkin",
          "target": null
        },
        {
          "id": "Rostpay",
          "display_name": "Rostpay",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Mitre Attack",
          "display_name": "Mitre Attack",
          "target": null
        },
        {
          "id": "Chaos (ELF)",
          "display_name": "Chaos (ELF)",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/GameHack",
          "display_name": "TrojanDropper:Win32/GameHack",
          "target": "/malware/TrojanDropper:Win32/GameHack"
        },
        {
          "id": "Win.Ransomware.Locky-7766366-0",
          "display_name": "Win.Ransomware.Locky-7766366-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt.A!rsm",
          "display_name": "Ransom:Win32/WannaCrypt.A!rsm",
          "target": "/malware/Ransom:Win32/WannaCrypt.A!rsm"
        },
        {
          "id": "ALF:E5.SpikeAex.rhh_pid",
          "display_name": "ALF:E5.SpikeAex.rhh_pid",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1107",
          "name": "File Deletion",
          "display_name": "T1107 - File Deletion"
        },
        {
          "id": "T1563",
          "name": "Remote Service Session Hijacking",
          "display_name": "T1563 - Remote Service Session Hijacking"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65d34c8a64436a7aee2e25a1",
      "export_count": 73,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Enqrypted",
        "id": "272105",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_272105/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1848,
        "FileHash-SHA1": 1783,
        "FileHash-SHA256": 7170,
        "domain": 1649,
        "hostname": 1191,
        "email": 9,
        "URL": 729,
        "CVE": 2,
        "SSLCertFingerprint": 2,
        "CIDR": 1
      },
      "indicator_count": 14384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 62,
      "modified_text": "801 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "zoom.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "zoom.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780212476.5828881
}