{
  "aliases": [
    "AlmondRAT",
    "BDarkRAT",
    "Hazy Tiger",
    "KugelBlitz",
    "MiyaRAT",
    "MuuyDownloader",
    "ORPCBackdoor",
    "Orange Yali",
    "WSCSPL",
    "apt-c-08",
    "apt-k-47",
    "apt-q-37",
    "apt-q-41",
    "artradownloader",
    "asyncshell",
    "chmghost",
    "kiwistealer",
    "manlinghua",
    "mysterious elephant",
    "splinter",
    "stomexfiltrator",
    "ta397",
    "turtlepower",
    "ung0002"
  ],
  "attack_id": "G1002",
  "attack_name": "BITTER",
  "attack_url": "https://attack.mitre.org/groups/G1002/",
  "counts": {
    "domain": 466,
    "ipv4": 78,
    "url": 24,
    "url_path": 102
  },
  "first_seen": {
    "domain": {
      "1drivestorage.com": "2022-08-14",
      "365cloudz.esanojinjasvc.com": "2026-01-02",
      "55five.lol": "2024-05-22",
      "888toto.com": "2024-05-22",
      "8toto.co": "2024-05-22",
      "918slot.top": "2024-05-22",
      "99media.com.pk": "2026-03-11",
      "99togel.org": "2024-05-22",
      "99toto.shop": "2024-05-22",
      "a.churchill91.com": "2019-02-27",
      "aadresourcing.com": "2024-09-06",
      "abelewebconnect.com": "2024-11-18",
      "activemobistore.ddns.net": "2020-04-21",
      "adamsresearchshare.com": "2024-01-04",
      "aday.primeservices.mobi": "2019-02-27",
      "aduhoki88.com": "2024-05-22",
      "affinitycapitalgp.com": "2024-09-13",
      "affinitycapitalgr.com": "2024-09-13",
      "alfiehealtcareservice.com": "2024-01-08",
      "alfiehealthcareservice.com": "2023-12-14",
      "alkhaleejpk.info": "2020-06-29",
      "alvesbarcelona.com": "2026-01-02",
      "andbouncersclub.com": "2024-09-10",
      "andrewswebstorage.com": "2026-01-02",
      "apifilestore.net": "2024-09-25",
      "app.chabaka.com": "2026-01-02",
      "app2.appvlc.com": "2022-08-12",
      "appbriar.com": "2022-08-12",
      "appprotonvpn.com": "2022-08-12",
      "appsupdate.net": "2022-08-14",
      "archiverst.com": "2022-08-14",
      "aroundtheworld123.net": "2019-02-27",
      "ashersoftlib.com": "2026-02-27",
      "autodefragapp.com": "2022-01-09",
      "bakuackermannfashions.com": "2024-07-03",
      "balkanclan.com": "2026-01-02",
      "bartelemarks.com": "2024-03-07",
      "benclickstudio.com": "2024-09-13",
      "bensnewfashionstyles.com": "2023-01-15",
      "bheragreens.com": "2021-08-06",
      "bickrickneoservice.com": "2024-08-06",
      "biocons.pk": "2019-09-07",
      "blth32serv.net": "2019-09-09",
      "blucollinsoutien.com": "2026-01-02",
      "bluelotus.mail-gdrive.com": "2023-03-24",
      "bootcampquest.com": "2026-01-02",
      "botanoolifeapp.net": "2022-06-08",
      "box.livevideosonlinepk.com": "2022-07-31",
      "bravojacksonmentor.com": "2026-04-30",
      "briarapppro.org": "2022-08-12",
      "broadsforthestate.com": "2026-01-13",
      "bsdqcaptureman.com": "2024-04-07",
      "btappclientsvc.net": "2019-08-09",
      "bulltrader.vip": "2024-05-22",
      "camncryptsvc.net": "2020-05-01",
      "caravelcruiser.com": "2026-03-27",
      "care.autodefragapp.com": "2022-01-09",
      "carlminiclub.com": "2026-01-02",
      "cbyxhuxo663.ddns.net": "2020-04-21",
      "ccltdcn.org": "2026-01-02",
      "cdaxpropsvc.net": "2019-08-09",
      "chabaka.com": "2026-01-02",
      "chinatel90.com": "2019-02-27",
      "churchill91.com": "2020-09-27",
      "cjcjegb9k5vg46vkns5g.sportsaccessstore.com": "2023-11-22",
      "clairsvanieclub.com": "2024-03-05",
      "cloud-storage-service.com": "2019-11-21",
      "cloudaff.net": "2024-07-30",
      "coauthcn.com": "2023-02-23",
      "coerciondigital.com": "2022-03-31",
      "colorsofnether.com": "2024-04-29",
      "com-ae.net": "2026-01-02",
      "commonlifesupport.com": "2026-04-06",
      "comnmsgwrapsvc.net": "2022-01-19",
      "confirm97.com": "2019-02-27",
      "converse-app.org": "2022-08-12",
      "cpcalendars.tomcruefrshsvc.com": "2022-01-10",
      "cpcontacts.tomcruefrshsvc.com": "2022-01-10",
      "createasocialcard.top": "2022-08-14",
      "crudestopics.com": "2026-01-23",
      "currweather.com": "2022-10-05",
      "dappscryp.com": "2024-11-19",
      "dashonlineclub.com": "2023-09-04",
      "daveonenewtestpanel.com": "2023-06-22",
      "deliverymailserver.com": "2022-06-08",
      "demolaservices.com": "2024-03-05",
      "deriksystemspartens.com": "2023-01-06",
      "destiny91.com": "2019-02-27",
      "devflowservice.com": "2024-08-22",
      "devqrytoprar.net": "2022-12-28",
      "diginurworld.com": "2026-01-02",
      "diyefosterfeeds.com": "2022-03-04",
      "dnldsalecraze.com": "2022-10-14",
      "domainnamevalidator.com": "2026-04-30",
      "domainregistationcheck.com": "2026-04-30",
      "downloadclouddata.com": "2026-06-11",
      "dracjohnsupport.com": "2023-02-07",
      "drogbachelsea.com": "2026-01-02",
      "dtzappaccount.com": "2023-12-14",
      "easyiplookup.com": "2024-09-26",
      "ebeninstallsvc.com": "2026-01-02",
      "ecoglide.site": "2026-01-02",
      "efgchartered.co.uk": "2024-05-22",
      "ekoconect.com": "2022-03-10",
      "elevateecom.com": "2024-09-21",
      "eliteteam.esanojinjasvc.com": "2026-01-02",
      "ellearningstore.com": "2023-01-09",
      "emmacloudsystem.com": "2023-08-08",
      "emshedulersvc.com": "2022-05-20",
      "epapbuizhost.net": "2021-12-29",
      "erswuniconsharing.com": "2023-03-27",
      "esanojinjasvc.com": "2026-01-02",
      "evert.autodefragapp.com": "2022-01-09",
      "evtessentials.com": "2024-04-09",
      "farleysmxpph.com": "2023-07-28",
      "farlookclinic.com": "2023-11-10",
      "fdcx32hostlaunchsvc.com": "2022-07-12",
      "federalrevenueboard.com": "2024-11-12",
      "fizzillacottages.com": "2024-10-26",
      "flashnewsservice.org": "2020-04-21",
      "florabrocuisine.com": "2026-01-02",
      "fogomyart.com": "2026-01-02",
      "folkmusicstreams.com": "2023-05-31",
      "font.jiangsuhost.com": "2019-02-27",
      "frameworksupport.net": "2019-02-05",
      "fswhardtools.com": "2026-05-06",
      "fusionjunction.link": "2024-07-03",
      "gallery.play-protect.com": "2022-08-12",
      "gandharaart.org": "2019-09-07",
      "gdatesystems.com": "2024-09-13",
      "getserviceupdates.com": "2026-04-30",
      "gewistaplaner.gewista.at": "2024-09-26",
      "ghayoorfilmstudio.com": "2024-11-19",
      "giov.officeweb.live": "2024-05-28",
      "glamorcliniques.com": "2024-09-05",
      "glamormusicwave.com": "2026-01-02",
      "goalvaidclub.com": "2024-05-20",
      "gocartwillium.com": "2024-08-11",
      "goldenaturalinc.com": "2026-01-02",
      "gongzuosousuo.net": "2019-09-05",
      "gorgxwebset.com": "2024-07-12",
      "gosignal.org": "2022-08-12",
      "gotiktikweb.com": "2024-01-05",
      "gpcpsvclog.net": "2022-01-11",
      "grandinaspectrum.com": "2026-04-24",
      "greenadelhouse.com": "2026-01-02",
      "greenspowerpanel.com": "2023-06-11",
      "grounpackcluepik.com": "2024-12-05",
      "gspcfdqtloe.sportsaccessstore.com": "2023-11-22",
      "guppu.pk": "2023-01-06",
      "gxwxtvonline.com": "2021-08-06",
      "haburyohoteam.com": "2026-03-27",
      "haileemecacademy.com": "2024-11-19",
      "hallanskylarks.com": "2024-01-12",
      "han.huandocimama.com": "2022-05-20",
      "hannahsgpsapp.com": "2026-01-02",
      "hatvax.com": "2022-08-14",
      "headntale.com": "2026-01-02",
      "healthdevicetracker.co": "2019-07-08",
      "healthnewsone.com": "2019-02-27",
      "healthtipsart.com": "2024-09-17",
      "helpdesk.autodefragapp.com": "2022-01-09",
      "herbsbrunabuiz.net": "2023-01-06",
      "hewle.kielsoservice.net": "2019-02-27",
      "huandocimama.com": "2022-05-20",
      "iboxencentrum.com": "2024-10-29",
      "idbcxnetmac.com": "2024-09-13",
      "inhostnetservice.com": "2024-10-15",
      "inizdesignstudio.com": "2026-01-02",
      "inspurcloudservice.com": "2026-01-02",
      "invstampvest.com": "2026-04-15",
      "islam-360-plus.com": "2022-08-12",
      "jacknwoods.com": "2024-12-04",
      "jetmains.com": "2024-09-16",
      "jgmfducservice.net": "2026-01-02",
      "jjwappconsole.com": "2023-12-14",
      "jlmusiklearn.com": "2023-02-08",
      "jmsatozplanning.com": "2024-09-13",
      "jmxdnqr8.mediumblog.online": "2026-01-02",
      "joelgardens.com": "2026-01-02",
      "johnfashionaccess.com": "2024-04-29",
      "johnywalter.webatu.com": "2019-02-27",
      "kaatmusiclab.com": "2024-02-21",
      "kaatsonlinesupport.com": "2023-08-02",
      "keeferbeautytrends.com": "2026-01-02",
      "kerbosim.com": "2019-11-28",
      "kertasiusaus.com": "2024-05-22",
      "khurram.com.pk": "2019-04-20",
      "kimfilippovision.com": "2024-08-15",
      "koliwooclients.com": "2026-01-02",
      "kryoblockbind.net": "2023-01-06",
      "laboratoreventsvc.com": "2024-11-12",
      "large-file-download-in-progress-page-loading-iuwt6sk34bs6543df.tartaakademi.com": "2026-01-02",
      "lbhandlesystem.com": "2023-03-08",
      "lcpcstudiover.com": "2024-01-02",
      "levarisnetqlsvc.net": "2022-05-09",
      "lezziezgrillcorner.com": "2024-07-22",
      "libraofficeonline.com": "2024-04-28",
      "libraofficeweb.com": "2024-03-21",
      "linphone-app.com": "2022-08-12",
      "littlehipsononline.com": "2024-07-17",
      "livevideosonlinepk.com": "2020-08-17",
      "liveways.pk": "2020-07-07",
      "lltdifslogsvc.net": "2022-04-07",
      "lmhostsvc.net": "2019-10-15",
      "locklearhealthapp.com": "2024-10-12",
      "log.huandocimama.com": "2022-05-20",
      "loganwcshost.com": "2023-12-12",
      "login.mynewellowstore.com": "2022-07-12",
      "lroliviapanel.com": "2023-12-07",
      "lsamapkitlaunch.com": "2024-10-12",
      "m.huandocimama.com": "2022-05-20",
      "mabizstockholm.com": "2022-12-29",
      "mail-gdrive.com": "2023-03-24",
      "mail-mfa-gov-cn-login.netlify.app": "2021-06-26",
      "mail.alvesbarcelona.com": "2026-01-02",
      "mail.autodefragapp.com": "2022-01-09",
      "mail.bootcampquest.com": "2026-01-02",
      "mail.com-ae.net": "2026-01-02",
      "mail.drogbachelsea.com": "2026-01-02",
      "mail.tomcruefrshsvc.com": "2022-01-10",
      "mail.wmiapcservice.com": "2024-10-12",
      "mail.youtubepremiumapp.com": "2026-01-02",
      "maildataserver.com": "2022-06-08",
      "manage.mediumblog.online": "2026-01-02",
      "manderikgamezilla.com": "2024-05-27",
      "mappservworldvide.16mb.com": "2019-02-27",
      "maq.com.pk": "2019-09-07",
      "mariasunistyle.com": "2024-05-27",
      "marine-research.space": "2026-01-02",
      "marvel89.com": "2019-02-27",
      "marvellighter.com": "2019-02-27",
      "maxcavelli.com": "2024-05-22",
      "maxdimservice.com": "2023-11-30",
      "maximasigns.greenadelhouse.com": "2026-01-02",
      "maxnursesolutions.com": "2024-10-12",
      "mcdavezonepanel.com": "2024-08-17",
      "mcxntoolsservice.com": "2024-09-13",
      "mediumblog.online": "2026-01-02",
      "medzone71.com": "2019-02-27",
      "mercifulnearyou.com": "2023-08-01",
      "mia.alkhaleejpk.info": "2020-07-07",
      "microsoft.officeweb.live": "2024-04-28",
      "microsoft365.sangellobrighthouse.com": "2026-01-02",
      "microworldus.com": "2024-10-12",
      "mikeyourevents.com": "2023-12-20",
      "mindgamecenter.com": "2024-07-22",
      "mirzadihatti.com": "2023-01-06",
      "miyamassagenklinik.com": "2024-10-15",
      "mnemautoregsvc.com": "2024-09-05",
      "mob.wirelesssolutions.mobi": "2019-02-27",
      "mobisharestock.com": "2022-12-01",
      "msdata.ddns.net": "2023-03-25",
      "msisspsvc.net": "2021-08-06",
      "msoffice.365cloudz.esanojinjasvc.com": "2026-01-02",
      "msofficeupdates.ddns.net": "2021-12-08",
      "muzicwonder.com": "2020-09-27",
      "mxmediasolutions.com": "2024-07-10",
      "mxsiclienteventlog.com": "2023-09-27",
      "mxuconlinegame.com": "2024-08-17",
      "mynewellowstore.com": "2022-07-12",
      "myprivatehostsvc.com": "2021-08-06",
      "narinesonlinelibrary.com": "2024-10-15",
      "nashmediawave.com": "2024-10-12",
      "nelavohomet.com": "2026-02-19",
      "neozelappconsole.com": "2023-09-27",
      "nesiallservice.net": "2024-01-08",
      "nethostsupport.ddns.net": "2019-10-25",
      "nethosttalk.com": "2019-02-27",
      "netmansrvdns.com": "2023-07-07",
      "netnsiservice.net": "2019-11-04",
      "newdesk.autodefragapp.com": "2022-01-09",
      "newlbfashions.com": "2023-11-30",
      "newmysticvision.com": "2018-09-29",
      "newsaxfluteclub.com": "2023-11-29",
      "noitfication-office-client.890m.com": "2019-12-02",
      "northgenstudios.com": "2024-02-02",
      "novaoutletclub.com": "2022-07-26",
      "novasapothecary.com": "2023-06-10",
      "ns1.nashmediawave.com": "2024-10-12",
      "ns2.easyiplookup.com": "2024-10-16",
      "nsiagenthoster.net": "2020-09-27",
      "nsipsvc.com": "2026-01-02",
      "ntplugnplay.com": "2026-01-02",
      "nurekleindesign.com": "2024-10-12",
      "nymedsvcsystems.com": "2022-05-14",
      "oakcreekbakers.com": "2026-01-02",
      "office360-pub.16mb.com": "2019-12-02",
      "officesignature.info": "2026-02-19",
      "officeweb.live": "2024-04-28",
      "olivershikerhelp.com": "2023-11-22",
      "olmajhnservice.com": "2021-09-17",
      "onlinehealthmatters.info": "2023-01-13",
      "onlinejohnline99.org": "2019-08-27",
      "onlinewebdebugsvc.com": "2024-09-04",
      "opfor.balkanclan.com": "2026-01-02",
      "oraclewebonline.com": "2024-04-25",
      "oscarskatingcoach.com": "2026-01-02",
      "ottawadesignlab.com": "2024-10-26",
      "otx.gxwxtvonline.com": "2021-08-06",
      "outlook-web.ddns.net": "2024-04-28",
      "outlook.officeweb.live": "2024-04-28",
      "parcaredrive.com": "2026-01-02",
      "paulalesiastyles.com": "2023-12-04",
      "pawsandtailcare.com": "2026-01-02",
      "pdcunaco.com": "2024-08-06",
      "pentree.online": "2026-01-02",
      "pflix.camdvr.org": "2022-08-12",
      "pichostfrm.net": "2020-12-14",
      "pinkrosesandmore.com": "2026-02-05",
      "play-protect.com": "2022-08-12",
      "play.google.com.whatsapp.playapps.ga": "2022-08-14",
      "playapps.ga": "2022-08-14",
      "plprasvchost.net": "2022-07-12",
      "plugins-support.com": "2024-05-22",
      "plymouthvibes.com": "2026-01-02",
      "pnptrafcroutsvc.net": "2022-06-08",
      "pololiberty.com": "2026-01-02",
      "premierinvestmentfund.com": "2024-12-04",
      "princecleanit.com": "2026-01-02",
      "procarcaresvc.com": "2024-11-12",
      "prolukemarion.com": "2026-02-05",
      "qdey4uvj.mediumblog.online": "2026-01-02",
      "quartzu.hol.es": "2019-11-28",
      "qwavemediaservice.net": "2022-10-21",
      "red5big.com": "2019-02-27",
      "rgevzuir.mediumblog.online": "2026-01-02",
      "rurushophoogtypnl.com": "2022-06-08",
      "rusjamystarapp.com": "2022-12-13",
      "rxnovelapps.info": "2023-02-08",
      "samsnewlooker.com": "2024-10-12",
      "sangellobrighthouse.com": "2026-01-02",
      "sanolegazy.com": "2026-01-02",
      "sartetextile.com": "2019-09-07",
      "sbss.com.pk": "2022-01-04",
      "seragoonupdates.com": "2026-01-02",
      "services.windowmediaplayer.media": "2026-01-02",
      "shareflx.com": "2022-08-14",
      "shareflx.createasocialcard.top": "2022-08-14",
      "shareflx.social-card-share.top": "2022-08-14",
      "shareflx.socialpreviews.top": "2022-08-14",
      "sharesmydrive.com": "2024-09-16",
      "shioyuilubiz.com": "2024-07-03",
      "shzjwxsns.qqcloud.coauthcn.com": "2023-08-29",
      "siasat.top": "2024-11-26",
      "signal-premium-app.org": "2022-08-10",
      "signal-premium.org": "2022-08-12",
      "signalpremium.com": "2022-08-10",
      "signalpro.org": "2022-08-12",
      "sikhsiyasatapp.net": "2022-08-12",
      "skyfare.site": "2026-01-02",
      "slrpnlcontrlintrface.com": "2022-01-08",
      "smartclouddirect.com": "2024-05-07",
      "snapsvcvirtual.net": "2022-02-16",
      "snsrsvchost.com": "2021-03-26",
      "snsrsvchost.net": "2021-11-26",
      "social-card-share.top": "2022-08-14",
      "socialpreviews.top": "2022-08-14",
      "sound.muzicwonder.com": "2019-02-27",
      "sporcketngearforu.com": "2024-09-13",
      "sportsaccessstore.com": "2023-11-22",
      "spring.tulipnetworks.net": "2019-02-27",
      "star.mynewellowstore.com": "2022-07-12",
      "stellacustomscreens.com": "2026-01-02",
      "sterling66.com": "2019-02-27",
      "stingray91.com": "2019-02-27",
      "storeupdates.net": "2022-08-14",
      "styl.crrerc.com": "2019-02-27",
      "styl.hairparker.com": "2019-02-27",
      "subscribe.tomcruefrshsvc.com": "2022-01-04",
      "support.autodefragapp.com": "2022-01-09",
      "supportteaminterface.esanojinjasvc.com": "2026-01-02",
      "supunitysharehost.net": "2022-12-16",
      "surininfiniumclub.com": "2024-09-13",
      "svc2mcxwave.net": "2021-08-06",
      "sysintservice.ddns.net": "2019-10-25",
      "tapeqcqoptions.com": "2026-01-02",
      "tartaakademi.com": "2026-01-02",
      "teamlogin.esanojinjasvc.com": "2026-01-02",
      "telegram-app.tech": "2022-08-12",
      "telegram-pro.org": "2022-08-12",
      "telegramapppro.org": "2022-08-12",
      "test.bulltrader.vip": "2024-05-22",
      "theambix.org": "2022-08-14",
      "thematrix.esy.es": "2019-02-27",
      "thenewmusictunes.com": "2023-08-02",
      "thepandaservices.nsiagenthoster.net": "2019-02-27",
      "tomcruefrshsvc.com": "2022-01-04",
      "tools.bootcampquest.com": "2026-01-02",
      "tradesmarkets.greenadelhouse.com": "2026-01-02",
      "traxbin.com": "2019-04-20",
      "trkswqsservice.com": "2026-01-02",
      "tulipnetworks.net": "2020-09-27",
      "turkeyapi.bio": "2024-07-30",
      "tvnservereventlog.net": "2019-11-07",
      "ultraflavors.com": "2026-06-26",
      "umsmssvc.com": "2023-12-14",
      "unr0wddj.mediumblog.online": "2026-01-02",
      "updateschedulers.com": "2024-11-20",
      "updnangelgroup.com": "2022-12-01",
      "upulllogistics.com": "2024-01-15",
      "urocakpmpanel.com": "2022-05-11",
      "usmservice.net": "2020-06-18",
      "utizviewstation.com": "2026-01-02",
      "uxmesysconsole.com": "2023-05-05",
      "v3solutions4all.com": "2019-08-09",
      "v3solutions4all.org": "2019-08-09",
      "vanessalove.com": "2024-09-20",
      "vdsappauthservice.net": "2020-09-04",
      "vercplsupport.net": "2022-07-12",
      "victory1983.ddns.net": "2019-02-27",
      "viewz.tomcruefrshsvc.com": "2022-01-10",
      "vividworld.net": "2022-11-21",
      "viyoappmapper.com": "2024-06-05",
      "vizylstatpro.com": "2024-08-14",
      "vpn146318720.softether.net": "2026-05-06",
      "vzgmbwva.mediumblog.online": "2026-01-02",
      "w32infinitisupports.net": "2019-09-10",
      "w32timeslicesvc.net": "2021-08-06",
      "wangluojiumingjingli.org": "2019-08-09",
      "warsanservices.com": "2026-01-02",
      "wbclientservice.ddns.net": "2020-02-03",
      "wbfashionshow.com": "2023-01-26",
      "wcnchost.ddns.net": "2019-04-20",
      "wcnsappword.com": "2023-01-12",
      "wdibitmapservice.net": "2020-04-21",
      "wdisvcnotifyhost.com": "2021-08-06",
      "weather-latest.com": "2022-10-04",
      "weather.play-protect.com": "2022-08-12",
      "webandersondesign.com": "2023-10-25",
      "webcarewellclinic.com": "2023-07-19",
      "webdisk.tomcruefrshsvc.com": "2022-01-10",
      "webmail.tomcruefrshsvc.com": "2022-01-10",
      "webmailcgwip.com": "2021-08-06",
      "whatsapp.playapps.ga": "2022-08-14",
      "whitelilyshop.com": "2024-03-06",
      "wills.hairparker.com": "2019-02-27",
      "windiagnosticsvc.net": "2021-08-06",
      "windowmediaplayer.media": "2026-01-02",
      "windowphotoviewer.com": "2024-08-15",
      "windowtemplates.info": "2022-04-04",
      "winfreecloud.net": "2024-09-25",
      "wingames2015.com": "2019-02-27",
      "winmanagerservice.net": "2019-08-09",
      "winmanagerservice.org": "2019-08-09",
      "wirelesssolutions.mobi": "2020-09-27",
      "wizbizkidshow.biz": "2022-06-15",
      "wmbwowxsvc.com": "2022-05-07",
      "wmiapcservice.com": "2024-10-12",
      "woodstocktutors.com": "2026-01-02",
      "woodwind71.com": "2019-02-27",
      "wusvcpsvc.com": "2024-11-01",
      "xiovo416.net": "2019-02-27",
      "xiuxonlinehost.com": "2023-09-12",
      "yalinasculetips.com": "2024-05-08",
      "yorkstar.mediumblog.online": "2026-01-02",
      "yoursdrive.com": "2022-08-14",
      "youtubepremiumapp.com": "2022-08-10",
      "youxiangxiezhu.com": "2021-08-06",
      "yuruhjforonjoigrvnbnrgoigoigoisannvmvnfnmkfd7.000webhostapp.com": "2021-06-26",
      "zensparkagent.com": "2024-11-19",
      "zhaodaolajiankang.com": "2022-05-01",
      "zhongwenchuantongqiye.com": "2019-09-07",
      "zingstockpicks.com": "2023-02-07",
      "zmwardrobe.com": "2019-02-27",
      "zoemagicbook.com": "2026-03-11"
    },
    "ipv4": {
      "103.57.251.154:4443": "2026-01-02",
      "107.172.39.100:44908": "2026-02-27",
      "107.173.63.218:58370": "2020-12-14",
      "110.42.64.137:9527": "2022-11-06",
      "134.255.210.127:443": "2026-01-28",
      "135.125.242.211:52112": "2024-01-12",
      "141.94.68.169:443": "2024-04-28",
      "147.124.223.140:41320": "2023-01-06",
      "151.236.14.173:443": "2026-01-02",
      "151.236.21.48:8080": "2026-01-02",
      "151.236.4.164:5010": "2026-04-30",
      "151.236.9.75:5080": "2024-09-26",
      "151.236.9.75:6396": "2024-10-16",
      "158.255.215.45:8899": "2025-01-08",
      "162.0.216.229:21443": "2026-01-02",
      "162.0.216.229:8888": "2026-01-02",
      "162.252.172.67:443": "2024-10-16",
      "162.252.175.131:6969": "2024-11-12",
      "162.252.175.131:8246": "2024-10-16",
      "163.245.220.108:8442": "2026-06-11",
      "167.88.15.93:61920": "2024-05-07",
      "185.106.123.198:40269": "2024-10-12",
      "185.117.72.87:10923": "2026-01-02",
      "185.117.73.195:59600": "2022-07-12",
      "185.117.73.209:49725": "2024-01-05",
      "185.141.25.244:33324": "2022-05-11",
      "185.193.48.135:8676": "2025-01-08",
      "185.193.50.233:443": "2026-01-09",
      "185.237.166.24:56218": "2026-01-02",
      "185.76.79.30:443": "2026-01-02",
      "188.214.33.170:443": "2026-03-31",
      "192.71.213.128:4431": "2026-01-02",
      "192.71.249.194:443": "2024-10-28",
      "193.142.58.38:34905": "2022-05-03",
      "193.29.58.210:15192": "2024-07-22",
      "194.110.246.254:443": "2026-01-02",
      "194.71.227.222:8855": "2025-01-08",
      "209.74.80.194:7699": "2026-01-02",
      "23.106.122.149:31174": "2023-01-06",
      "23.254.128.22:22812": "2023-12-14",
      "45.11.19.170:34318": "2021-08-06",
      "45.56.165.121:46346": "2024-11-01",
      "45.66.248.66:59142": "2023-12-14",
      "45.86.163.212:49920": "2022-02-16",
      "46.183.186.208:6060": "2024-10-16",
      "46.183.187.42:443": "2024-10-16",
      "46.183.25.24:52546": "2024-05-27",
      "46.249.38.18:41426": "2023-12-12",
      "46.249.38.18:52993": "2024-01-02",
      "46.30.188.43:51683": "2023-03-24",
      "46.30.190.137:51620": "2024-07-12",
      "46.30.190.160:60099": "2023-05-05",
      "46.30.191.221:443": "2026-01-02",
      "47.94.19.69:8080": "2024-05-02",
      "5.135.43.181:35598": "2024-10-12",
      "51.178.206.76:22812": "2023-12-14",
      "51.255.3.62:48152": "2022-07-12",
      "64.44.131.109:33638": "2022-06-15",
      "65.20.103.184:8080": "2024-07-30",
      "65.20.105.88:8082": "2024-09-16",
      "83.172.134.186:443": "2026-01-02",
      "83.243.121.87:443": "2026-01-09",
      "89.40.206.85:52529": "2023-11-30",
      "89.46.234.221:443": "2026-01-02",
      "89.46.234.221:9672": "2026-01-02",
      "89.46.236.152:443": "2026-04-30",
      "91.103.66.202:46882": "2025-01-08",
      "91.132.92.231:5959": "2024-10-16",
      "91.132.92.231:6060": "2024-09-26",
      "91.132.92.231:9314": "2024-11-12",
      "91.192.81.102:22981": "2024-02-21",
      "91.236.230.44:59310": "2023-11-22",
      "91.236.230.54:46056": "2023-12-14",
      "94.140.114.22:41322": "2022-08-10",
      "95.156.206.105:443": "2024-09-16",
      "95.169.180.122:443": "2024-11-07",
      "95.174.71.139:39006": "2023-12-14",
      "96.9.215.155:56172": "2024-10-12"
    },
    "url": {
      "http://149.154.153.184": "2026-01-02",
      "http://151.236.9.75": "2024-09-26",
      "http://159.100.30.103": "2024-11-28",
      "http://162.0.229.203": "2020-09-15",
      "http://173.254.204.72": "2024-11-28",
      "http://193.142.58.186": "2021-08-06",
      "http://196.251.84.150": "2026-01-02",
      "http://37.1.214.196": "2024-12-07",
      "http://45.11.19.170": "2022-03-18",
      "http://45.61.139.69": "2024-07-30",
      "http://46.229.55.63": "2026-01-02",
      "http://46.30.191.221": "2026-04-30",
      "http://47.245.111.83": "2024-10-26",
      "http://63.250.38.240": "2020-05-08",
      "http://72.11.134.216": "2020-12-14",
      "http://72.18.215.1": "2024-12-13",
      "http://82.221.136.27": "2020-12-14",
      "http://94.156.175.95": "2024-08-14",
      "http://95.169.180.122": "2024-11-07",
      "jgcest.com/css/": "2020-09-10",
      "oppak.com/one/eths": "2020-08-24",
      "oppak.com/one/opa": "2020-08-24",
      "tusdec.org.pk/ee": "2020-07-07",
      "uniengrisb.com/img/rt.msi": "2020-07-07"
    },
    "url_path": {
      "/45Ugty845nv7rt.php": "2021-08-06",
      "/CP/tre.php?pi=": "2023-12-20",
      "/CVBN/mzx.php": "2023-09-04",
      "/DMMA/hfo.php": "2023-11-10",
      "/DMMA/hfo.php?pi=": "2023-11-10",
      "/F1l3estPhPInf1.php": "2020-09-27",
      "/F1l3estPhPInf2.php": "2020-09-27",
      "/ML/vbn.php?pi=": "2024-02-02",
      "/Mcx2svc.php": "2019-09-08",
      "/OibytDsERt.php": "2022-07-12",
      "/OtPefhePbvw/": "2021-08-06",
      "/OtPefhePbvw/datarcvoninfile.php": "2021-08-06",
      "/OtPefhePbvw/nnodata3inf.php": "2021-08-06",
      "/OtPefhePbvw/onlinedata1inf.php": "2021-08-06",
      "/PerHyPfilbmiw1.php": "2020-08-17",
      "/PerHyPfilbmiw2.php": "2020-08-17",
      "/PsehestyvuPw/": "2020-09-27",
      "/PsehestyvuPw/F1l3estPhPInf1.php": "2020-09-27",
      "/ROAM/gret.php": "2023-09-27",
      "/RguhsT/": "2020-08-17",
      "/RguhsT/accept.php": "2020-05-01",
      "/RsdvgiMincSnyYu/": "2020-08-17",
      "/RsdvgiMincSnyYu/PerHyPfilbmiw1.php": "2020-08-17",
      "/RsdvgiMincSnyYu/PerHyPfilbmiw2.php": "2020-08-17",
      "/SzWvcxuer/": "2022-01-04",
      "/UihbywscTZ/": "2021-08-06",
      "/UihbywscTZ/45Ugty845nv7rt.php": "2021-08-06",
      "/VcvNbtgRrPopqSD/": "2022-01-04",
      "/VcvNbtgRrPopqSD/SzWvcxuer/": "2022-01-04",
      "/VcvNbtgRrPopqSD/SzWvcxuer/userlog.php": "2022-01-04",
      "/WORK/info.php?cve=": "2023-09-27",
      "/WVKA/qbv.php": "2023-08-02",
      "/anotherLife?credPart=": "2025-01-08",
      "/ceszvd.php": "2026-02-05",
      "/cloudzx/msweb/drdxcsv34.php": "2026-01-02",
      "/cloudzx/msweb/drxbds23.php": "2026-01-02",
      "/cloudzx/msweb/drxcvg45.php": "2026-01-02",
      "/cmpn/xing.php": "2026-01-02",
      "/cndrll.php": "2026-01-02",
      "/cndrll.php?er=": "2026-01-02",
      "/crvtyfgvwicidnex.php": "2026-01-02",
      "/dFFrt3856ByutTs/": "2022-02-08",
      "/dFFrt3856ByutTs/xnb/data1.php": "2022-02-08",
      "/datarcvoninfile.php": "2021-08-06",
      "/dozq/jkl.php": "2023-10-25",
      "/dozq/jkl.php?pi=": "2023-10-25",
      "/edgevrisinze.php": "2026-01-02",
      "/ergdfbd/": "2020-08-17",
      "/ergdfbd/wscspl": "2019-03-05",
      "/excerorderslistoncbook.php": "2026-01-02",
      "/frst.php?ys=": "2023-12-07",
      "/healthne/": "2020-08-17",
      "/healthne/accept.php": "2019-03-05",
      "/healthne/regdl": "2019-03-05",
      "/hgdtfjgtyf.php": "2026-04-24",
      "/imacnags/edgevrisinze.php": "2026-01-02",
      "/jdfgwe.php": "2026-01-13",
      "/jmv/jmd.php?st=": "2026-01-02",
      "/jsprc.php?h=": "2022-01-19",
      "/jvdmhawme.okjhvthfv": "2026-03-27",
      "/kna.php?ka=": "2023-11-30",
      "/kvs06v.php": "2019-08-27",
      "/lax05u.php": "2019-09-08",
      "/loccs.php?cn=": "2026-01-02",
      "/lux.php?cv=": "2024-10-29",
      "/mloknj.php": "2024-08-17",
      "/mloknj.php?cv=": "2024-08-17",
      "/ms2u1p.php": "2019-09-08",
      "/mscu/lokc.php": "2024-10-15",
      "/mscu/lokc.php?wl=": "2024-10-15",
      "/n9brCs21/": "2021-08-06",
      "/n9brCs21/apprun": "2021-08-06",
      "/nina/anotherLife?credPart=": "2025-01-08",
      "/nnodata3inf.php": "2021-08-06",
      "/onlinedata1inf.php": "2021-08-06",
      "/ourtyaz/": "2020-08-17",
      "/ourtyaz/dwnack.php": "2019-03-05",
      "/ourtyaz/qwe.php": "2019-03-05",
      "/ourtyaz/qwf.php": "2020-08-17",
      "/shrd.php?vo=": "2024-09-13",
      "/taskshandlers/DBhandle/primary_main.php": "2020-09-04",
      "/taskshandlers/DBhandle/secondary.php": "2021-02-02",
      "/teamesano/drivers/teamzid.php": "2026-01-02",
      "/textcmd/cmd1.php": "2024-01-04",
      "/textcmd/text.php?id1=": "2024-01-04",
      "/tstPerHyPfilbmiw1.php": "2020-09-09",
      "/tstPerHyPfilbmiwts2t.php": "2020-09-09",
      "/tstRsdvgiMincSnyYutsphp/": "2020-09-09",
      "/tstRsdvgiMincSnyYutsphp/tstPerHyPfilbmiw1.php": "2020-09-09",
      "/tstRsdvgiMincSnyYutsphp/tstPerHyPfilbmiwts2t.php": "2020-09-09",
      "/tstRsdvgiMincSnyYutspph/": "2020-09-17",
      "/tstRsdvgiMincSnyYutspph/tstPerHyPfilbmiw1.php": "2020-09-17",
      "/tstRsdvgiMincSnyYutspph/tstPerHyPfilbmiwts2t.php": "2020-09-17",
      "/updateReqServ10893x.php": "2022-05-11",
      "/uplh4ppy.php": "2026-01-02",
      "/v10.066/egrf.php": "2026-01-02",
      "/vbdfsbad.php": "2026-02-05",
      "/wipe/ret.php?eer=": "2024-01-15",
      "/wmis/wave.php?xas=": "2024-03-05",
      "/xyzxyzhanoiwhb3237gb2wahabjiki/": "2024-11-26",
      "/zserr.php": "2024-12-07",
      "/zserr.php?li=": "2024-12-07"
    }
  },
  "first_seen_precision": {
    "domain": {
      "365cloudz.esanojinjasvc.com": "at-or-before",
      "alvesbarcelona.com": "at-or-before",
      "andrewswebstorage.com": "at-or-before",
      "app.chabaka.com": "at-or-before",
      "balkanclan.com": "at-or-before",
      "blucollinsoutien.com": "at-or-before",
      "bootcampquest.com": "at-or-before",
      "carlminiclub.com": "at-or-before",
      "ccltdcn.org": "at-or-before",
      "chabaka.com": "at-or-before",
      "com-ae.net": "at-or-before",
      "diginurworld.com": "at-or-before",
      "drogbachelsea.com": "at-or-before",
      "ebeninstallsvc.com": "at-or-before",
      "ecoglide.site": "at-or-before",
      "eliteteam.esanojinjasvc.com": "at-or-before",
      "esanojinjasvc.com": "at-or-before",
      "florabrocuisine.com": "at-or-before",
      "fogomyart.com": "at-or-before",
      "glamormusicwave.com": "at-or-before",
      "goldenaturalinc.com": "at-or-before",
      "greenadelhouse.com": "at-or-before",
      "hannahsgpsapp.com": "at-or-before",
      "headntale.com": "at-or-before",
      "inizdesignstudio.com": "at-or-before",
      "inspurcloudservice.com": "at-or-before",
      "jgmfducservice.net": "at-or-before",
      "jmxdnqr8.mediumblog.online": "at-or-before",
      "joelgardens.com": "at-or-before",
      "keeferbeautytrends.com": "at-or-before",
      "koliwooclients.com": "at-or-before",
      "large-file-download-in-progress-page-loading-iuwt6sk34bs6543df.tartaakademi.com": "at-or-before",
      "mail.alvesbarcelona.com": "at-or-before",
      "mail.bootcampquest.com": "at-or-before",
      "mail.com-ae.net": "at-or-before",
      "mail.drogbachelsea.com": "at-or-before",
      "mail.youtubepremiumapp.com": "at-or-before",
      "manage.mediumblog.online": "at-or-before",
      "marine-research.space": "at-or-before",
      "maximasigns.greenadelhouse.com": "at-or-before",
      "mediumblog.online": "at-or-before",
      "microsoft365.sangellobrighthouse.com": "at-or-before",
      "msoffice.365cloudz.esanojinjasvc.com": "at-or-before",
      "nsipsvc.com": "at-or-before",
      "ntplugnplay.com": "at-or-before",
      "oakcreekbakers.com": "at-or-before",
      "opfor.balkanclan.com": "at-or-before",
      "oscarskatingcoach.com": "at-or-before",
      "parcaredrive.com": "at-or-before",
      "pawsandtailcare.com": "at-or-before",
      "pentree.online": "at-or-before",
      "plymouthvibes.com": "at-or-before",
      "pololiberty.com": "at-or-before",
      "princecleanit.com": "at-or-before",
      "qdey4uvj.mediumblog.online": "at-or-before",
      "rgevzuir.mediumblog.online": "at-or-before",
      "sangellobrighthouse.com": "at-or-before",
      "sanolegazy.com": "at-or-before",
      "seragoonupdates.com": "at-or-before",
      "services.windowmediaplayer.media": "at-or-before",
      "skyfare.site": "at-or-before",
      "stellacustomscreens.com": "at-or-before",
      "supportteaminterface.esanojinjasvc.com": "at-or-before",
      "tapeqcqoptions.com": "at-or-before",
      "tartaakademi.com": "at-or-before",
      "teamlogin.esanojinjasvc.com": "at-or-before",
      "tools.bootcampquest.com": "at-or-before",
      "tradesmarkets.greenadelhouse.com": "at-or-before",
      "trkswqsservice.com": "at-or-before",
      "unr0wddj.mediumblog.online": "at-or-before",
      "utizviewstation.com": "at-or-before",
      "vzgmbwva.mediumblog.online": "at-or-before",
      "warsanservices.com": "at-or-before",
      "windowmediaplayer.media": "at-or-before",
      "woodstocktutors.com": "at-or-before",
      "yorkstar.mediumblog.online": "at-or-before"
    },
    "ipv4": {
      "103.57.251.154:4443": "at-or-before",
      "151.236.14.173:443": "at-or-before",
      "151.236.21.48:8080": "at-or-before",
      "162.0.216.229:21443": "at-or-before",
      "162.0.216.229:8888": "at-or-before",
      "185.117.72.87:10923": "at-or-before",
      "185.237.166.24:56218": "at-or-before",
      "185.76.79.30:443": "at-or-before",
      "192.71.213.128:4431": "at-or-before",
      "194.110.246.254:443": "at-or-before",
      "209.74.80.194:7699": "at-or-before",
      "46.30.191.221:443": "at-or-before",
      "83.172.134.186:443": "at-or-before",
      "89.46.234.221:443": "at-or-before",
      "89.46.234.221:9672": "at-or-before"
    },
    "url": {
      "http://149.154.153.184": "at-or-before",
      "http://196.251.84.150": "at-or-before",
      "http://46.229.55.63": "at-or-before"
    },
    "url_path": {
      "/cloudzx/msweb/drdxcsv34.php": "at-or-before",
      "/cloudzx/msweb/drxbds23.php": "at-or-before",
      "/cloudzx/msweb/drxcvg45.php": "at-or-before",
      "/cmpn/xing.php": "at-or-before",
      "/cndrll.php": "at-or-before",
      "/cndrll.php?er=": "at-or-before",
      "/crvtyfgvwicidnex.php": "at-or-before",
      "/edgevrisinze.php": "at-or-before",
      "/excerorderslistoncbook.php": "at-or-before",
      "/imacnags/edgevrisinze.php": "at-or-before",
      "/jmv/jmd.php?st=": "at-or-before",
      "/loccs.php?cn=": "at-or-before",
      "/teamesano/drivers/teamzid.php": "at-or-before",
      "/uplh4ppy.php": "at-or-before",
      "/v10.066/egrf.php": "at-or-before"
    }
  },
  "first_seen_range": {
    "earliest": "2018-09-29",
    "latest": "2026-06-26"
  },
  "generated_at": "2026-08-08T03:26:30+00:00",
  "indicators": {
    "domain": [
      "1drivestorage.com",
      "365cloudz.esanojinjasvc.com",
      "55five.lol",
      "888toto.com",
      "8toto.co",
      "918slot.top",
      "99media.com.pk",
      "99togel.org",
      "99toto.shop",
      "a.churchill91.com",
      "aadresourcing.com",
      "abelewebconnect.com",
      "activemobistore.ddns.net",
      "adamsresearchshare.com",
      "aday.primeservices.mobi",
      "aduhoki88.com",
      "affinitycapitalgp.com",
      "affinitycapitalgr.com",
      "alfiehealtcareservice.com",
      "alfiehealthcareservice.com",
      "alkhaleejpk.info",
      "alvesbarcelona.com",
      "andbouncersclub.com",
      "andrewswebstorage.com",
      "apifilestore.net",
      "app.chabaka.com",
      "app2.appvlc.com",
      "appbriar.com",
      "appprotonvpn.com",
      "appsupdate.net",
      "archiverst.com",
      "aroundtheworld123.net",
      "ashersoftlib.com",
      "autodefragapp.com",
      "bakuackermannfashions.com",
      "balkanclan.com",
      "bartelemarks.com",
      "benclickstudio.com",
      "bensnewfashionstyles.com",
      "bheragreens.com",
      "bickrickneoservice.com",
      "biocons.pk",
      "blth32serv.net",
      "blucollinsoutien.com",
      "bluelotus.mail-gdrive.com",
      "bootcampquest.com",
      "botanoolifeapp.net",
      "box.livevideosonlinepk.com",
      "bravojacksonmentor.com",
      "briarapppro.org",
      "broadsforthestate.com",
      "bsdqcaptureman.com",
      "btappclientsvc.net",
      "bulltrader.vip",
      "camncryptsvc.net",
      "caravelcruiser.com",
      "care.autodefragapp.com",
      "carlminiclub.com",
      "cbyxhuxo663.ddns.net",
      "ccltdcn.org",
      "cdaxpropsvc.net",
      "chabaka.com",
      "chinatel90.com",
      "churchill91.com",
      "cjcjegb9k5vg46vkns5g.sportsaccessstore.com",
      "clairsvanieclub.com",
      "cloud-storage-service.com",
      "cloudaff.net",
      "coauthcn.com",
      "coerciondigital.com",
      "colorsofnether.com",
      "com-ae.net",
      "commonlifesupport.com",
      "comnmsgwrapsvc.net",
      "confirm97.com",
      "converse-app.org",
      "cpcalendars.tomcruefrshsvc.com",
      "cpcontacts.tomcruefrshsvc.com",
      "createasocialcard.top",
      "crudestopics.com",
      "currweather.com",
      "dappscryp.com",
      "dashonlineclub.com",
      "daveonenewtestpanel.com",
      "deliverymailserver.com",
      "demolaservices.com",
      "deriksystemspartens.com",
      "destiny91.com",
      "devflowservice.com",
      "devqrytoprar.net",
      "diginurworld.com",
      "diyefosterfeeds.com",
      "dnldsalecraze.com",
      "domainnamevalidator.com",
      "domainregistationcheck.com",
      "downloadclouddata.com",
      "dracjohnsupport.com",
      "drogbachelsea.com",
      "dtzappaccount.com",
      "easyiplookup.com",
      "ebeninstallsvc.com",
      "ecoglide.site",
      "efgchartered.co.uk",
      "ekoconect.com",
      "elevateecom.com",
      "eliteteam.esanojinjasvc.com",
      "ellearningstore.com",
      "emmacloudsystem.com",
      "emshedulersvc.com",
      "epapbuizhost.net",
      "erswuniconsharing.com",
      "esanojinjasvc.com",
      "evert.autodefragapp.com",
      "evtessentials.com",
      "farleysmxpph.com",
      "farlookclinic.com",
      "fdcx32hostlaunchsvc.com",
      "federalrevenueboard.com",
      "fizzillacottages.com",
      "flashnewsservice.org",
      "florabrocuisine.com",
      "fogomyart.com",
      "folkmusicstreams.com",
      "font.jiangsuhost.com",
      "frameworksupport.net",
      "fswhardtools.com",
      "fusionjunction.link",
      "gallery.play-protect.com",
      "gandharaart.org",
      "gdatesystems.com",
      "getserviceupdates.com",
      "gewistaplaner.gewista.at",
      "ghayoorfilmstudio.com",
      "giov.officeweb.live",
      "glamorcliniques.com",
      "glamormusicwave.com",
      "goalvaidclub.com",
      "gocartwillium.com",
      "goldenaturalinc.com",
      "gongzuosousuo.net",
      "gorgxwebset.com",
      "gosignal.org",
      "gotiktikweb.com",
      "gpcpsvclog.net",
      "grandinaspectrum.com",
      "greenadelhouse.com",
      "greenspowerpanel.com",
      "grounpackcluepik.com",
      "gspcfdqtloe.sportsaccessstore.com",
      "guppu.pk",
      "gxwxtvonline.com",
      "haburyohoteam.com",
      "haileemecacademy.com",
      "hallanskylarks.com",
      "han.huandocimama.com",
      "hannahsgpsapp.com",
      "hatvax.com",
      "headntale.com",
      "healthdevicetracker.co",
      "healthnewsone.com",
      "healthtipsart.com",
      "helpdesk.autodefragapp.com",
      "herbsbrunabuiz.net",
      "hewle.kielsoservice.net",
      "huandocimama.com",
      "iboxencentrum.com",
      "idbcxnetmac.com",
      "inhostnetservice.com",
      "inizdesignstudio.com",
      "inspurcloudservice.com",
      "invstampvest.com",
      "islam-360-plus.com",
      "jacknwoods.com",
      "jetmains.com",
      "jgmfducservice.net",
      "jjwappconsole.com",
      "jlmusiklearn.com",
      "jmsatozplanning.com",
      "jmxdnqr8.mediumblog.online",
      "joelgardens.com",
      "johnfashionaccess.com",
      "johnywalter.webatu.com",
      "kaatmusiclab.com",
      "kaatsonlinesupport.com",
      "keeferbeautytrends.com",
      "kerbosim.com",
      "kertasiusaus.com",
      "khurram.com.pk",
      "kimfilippovision.com",
      "koliwooclients.com",
      "kryoblockbind.net",
      "laboratoreventsvc.com",
      "large-file-download-in-progress-page-loading-iuwt6sk34bs6543df.tartaakademi.com",
      "lbhandlesystem.com",
      "lcpcstudiover.com",
      "levarisnetqlsvc.net",
      "lezziezgrillcorner.com",
      "libraofficeonline.com",
      "libraofficeweb.com",
      "linphone-app.com",
      "littlehipsononline.com",
      "livevideosonlinepk.com",
      "liveways.pk",
      "lltdifslogsvc.net",
      "lmhostsvc.net",
      "locklearhealthapp.com",
      "log.huandocimama.com",
      "loganwcshost.com",
      "login.mynewellowstore.com",
      "lroliviapanel.com",
      "lsamapkitlaunch.com",
      "m.huandocimama.com",
      "mabizstockholm.com",
      "mail-gdrive.com",
      "mail-mfa-gov-cn-login.netlify.app",
      "mail.alvesbarcelona.com",
      "mail.autodefragapp.com",
      "mail.bootcampquest.com",
      "mail.com-ae.net",
      "mail.drogbachelsea.com",
      "mail.tomcruefrshsvc.com",
      "mail.wmiapcservice.com",
      "mail.youtubepremiumapp.com",
      "maildataserver.com",
      "manage.mediumblog.online",
      "manderikgamezilla.com",
      "mappservworldvide.16mb.com",
      "maq.com.pk",
      "mariasunistyle.com",
      "marine-research.space",
      "marvel89.com",
      "marvellighter.com",
      "maxcavelli.com",
      "maxdimservice.com",
      "maximasigns.greenadelhouse.com",
      "maxnursesolutions.com",
      "mcdavezonepanel.com",
      "mcxntoolsservice.com",
      "mediumblog.online",
      "medzone71.com",
      "mercifulnearyou.com",
      "mia.alkhaleejpk.info",
      "microsoft.officeweb.live",
      "microsoft365.sangellobrighthouse.com",
      "microworldus.com",
      "mikeyourevents.com",
      "mindgamecenter.com",
      "mirzadihatti.com",
      "miyamassagenklinik.com",
      "mnemautoregsvc.com",
      "mob.wirelesssolutions.mobi",
      "mobisharestock.com",
      "msdata.ddns.net",
      "msisspsvc.net",
      "msoffice.365cloudz.esanojinjasvc.com",
      "msofficeupdates.ddns.net",
      "muzicwonder.com",
      "mxmediasolutions.com",
      "mxsiclienteventlog.com",
      "mxuconlinegame.com",
      "mynewellowstore.com",
      "myprivatehostsvc.com",
      "narinesonlinelibrary.com",
      "nashmediawave.com",
      "nelavohomet.com",
      "neozelappconsole.com",
      "nesiallservice.net",
      "nethostsupport.ddns.net",
      "nethosttalk.com",
      "netmansrvdns.com",
      "netnsiservice.net",
      "newdesk.autodefragapp.com",
      "newlbfashions.com",
      "newmysticvision.com",
      "newsaxfluteclub.com",
      "noitfication-office-client.890m.com",
      "northgenstudios.com",
      "novaoutletclub.com",
      "novasapothecary.com",
      "ns1.nashmediawave.com",
      "ns2.easyiplookup.com",
      "nsiagenthoster.net",
      "nsipsvc.com",
      "ntplugnplay.com",
      "nurekleindesign.com",
      "nymedsvcsystems.com",
      "oakcreekbakers.com",
      "office360-pub.16mb.com",
      "officesignature.info",
      "officeweb.live",
      "olivershikerhelp.com",
      "olmajhnservice.com",
      "onlinehealthmatters.info",
      "onlinejohnline99.org",
      "onlinewebdebugsvc.com",
      "opfor.balkanclan.com",
      "oraclewebonline.com",
      "oscarskatingcoach.com",
      "ottawadesignlab.com",
      "otx.gxwxtvonline.com",
      "outlook-web.ddns.net",
      "outlook.officeweb.live",
      "parcaredrive.com",
      "paulalesiastyles.com",
      "pawsandtailcare.com",
      "pdcunaco.com",
      "pentree.online",
      "pflix.camdvr.org",
      "pichostfrm.net",
      "pinkrosesandmore.com",
      "play-protect.com",
      "play.google.com.whatsapp.playapps.ga",
      "playapps.ga",
      "plprasvchost.net",
      "plugins-support.com",
      "plymouthvibes.com",
      "pnptrafcroutsvc.net",
      "pololiberty.com",
      "premierinvestmentfund.com",
      "princecleanit.com",
      "procarcaresvc.com",
      "prolukemarion.com",
      "qdey4uvj.mediumblog.online",
      "quartzu.hol.es",
      "qwavemediaservice.net",
      "red5big.com",
      "rgevzuir.mediumblog.online",
      "rurushophoogtypnl.com",
      "rusjamystarapp.com",
      "rxnovelapps.info",
      "samsnewlooker.com",
      "sangellobrighthouse.com",
      "sanolegazy.com",
      "sartetextile.com",
      "sbss.com.pk",
      "seragoonupdates.com",
      "services.windowmediaplayer.media",
      "shareflx.com",
      "shareflx.createasocialcard.top",
      "shareflx.social-card-share.top",
      "shareflx.socialpreviews.top",
      "sharesmydrive.com",
      "shioyuilubiz.com",
      "shzjwxsns.qqcloud.coauthcn.com",
      "siasat.top",
      "signal-premium-app.org",
      "signal-premium.org",
      "signalpremium.com",
      "signalpro.org",
      "sikhsiyasatapp.net",
      "skyfare.site",
      "slrpnlcontrlintrface.com",
      "smartclouddirect.com",
      "snapsvcvirtual.net",
      "snsrsvchost.com",
      "snsrsvchost.net",
      "social-card-share.top",
      "socialpreviews.top",
      "sound.muzicwonder.com",
      "sporcketngearforu.com",
      "sportsaccessstore.com",
      "spring.tulipnetworks.net",
      "star.mynewellowstore.com",
      "stellacustomscreens.com",
      "sterling66.com",
      "stingray91.com",
      "storeupdates.net",
      "styl.crrerc.com",
      "styl.hairparker.com",
      "subscribe.tomcruefrshsvc.com",
      "support.autodefragapp.com",
      "supportteaminterface.esanojinjasvc.com",
      "supunitysharehost.net",
      "surininfiniumclub.com",
      "svc2mcxwave.net",
      "sysintservice.ddns.net",
      "tapeqcqoptions.com",
      "tartaakademi.com",
      "teamlogin.esanojinjasvc.com",
      "telegram-app.tech",
      "telegram-pro.org",
      "telegramapppro.org",
      "test.bulltrader.vip",
      "theambix.org",
      "thematrix.esy.es",
      "thenewmusictunes.com",
      "thepandaservices.nsiagenthoster.net",
      "tomcruefrshsvc.com",
      "tools.bootcampquest.com",
      "tradesmarkets.greenadelhouse.com",
      "traxbin.com",
      "trkswqsservice.com",
      "tulipnetworks.net",
      "turkeyapi.bio",
      "tvnservereventlog.net",
      "ultraflavors.com",
      "umsmssvc.com",
      "unr0wddj.mediumblog.online",
      "updateschedulers.com",
      "updnangelgroup.com",
      "upulllogistics.com",
      "urocakpmpanel.com",
      "usmservice.net",
      "utizviewstation.com",
      "uxmesysconsole.com",
      "v3solutions4all.com",
      "v3solutions4all.org",
      "vanessalove.com",
      "vdsappauthservice.net",
      "vercplsupport.net",
      "victory1983.ddns.net",
      "viewz.tomcruefrshsvc.com",
      "vividworld.net",
      "viyoappmapper.com",
      "vizylstatpro.com",
      "vpn146318720.softether.net",
      "vzgmbwva.mediumblog.online",
      "w32infinitisupports.net",
      "w32timeslicesvc.net",
      "wangluojiumingjingli.org",
      "warsanservices.com",
      "wbclientservice.ddns.net",
      "wbfashionshow.com",
      "wcnchost.ddns.net",
      "wcnsappword.com",
      "wdibitmapservice.net",
      "wdisvcnotifyhost.com",
      "weather-latest.com",
      "weather.play-protect.com",
      "webandersondesign.com",
      "webcarewellclinic.com",
      "webdisk.tomcruefrshsvc.com",
      "webmail.tomcruefrshsvc.com",
      "webmailcgwip.com",
      "whatsapp.playapps.ga",
      "whitelilyshop.com",
      "wills.hairparker.com",
      "windiagnosticsvc.net",
      "windowmediaplayer.media",
      "windowphotoviewer.com",
      "windowtemplates.info",
      "winfreecloud.net",
      "wingames2015.com",
      "winmanagerservice.net",
      "winmanagerservice.org",
      "wirelesssolutions.mobi",
      "wizbizkidshow.biz",
      "wmbwowxsvc.com",
      "wmiapcservice.com",
      "woodstocktutors.com",
      "woodwind71.com",
      "wusvcpsvc.com",
      "xiovo416.net",
      "xiuxonlinehost.com",
      "yalinasculetips.com",
      "yorkstar.mediumblog.online",
      "yoursdrive.com",
      "youtubepremiumapp.com",
      "youxiangxiezhu.com",
      "yuruhjforonjoigrvnbnrgoigoigoisannvmvnfnmkfd7.000webhostapp.com",
      "zensparkagent.com",
      "zhaodaolajiankang.com",
      "zhongwenchuantongqiye.com",
      "zingstockpicks.com",
      "zmwardrobe.com",
      "zoemagicbook.com"
    ],
    "ipv4": [
      "103.57.251.154:4443",
      "107.172.39.100:44908",
      "107.173.63.218:58370",
      "110.42.64.137:9527",
      "134.255.210.127:443",
      "135.125.242.211:52112",
      "141.94.68.169:443",
      "147.124.223.140:41320",
      "151.236.14.173:443",
      "151.236.21.48:8080",
      "151.236.4.164:5010",
      "151.236.9.75:5080",
      "151.236.9.75:6396",
      "158.255.215.45:8899",
      "162.0.216.229:21443",
      "162.0.216.229:8888",
      "162.252.172.67:443",
      "162.252.175.131:6969",
      "162.252.175.131:8246",
      "163.245.220.108:8442",
      "167.88.15.93:61920",
      "185.106.123.198:40269",
      "185.117.72.87:10923",
      "185.117.73.195:59600",
      "185.117.73.209:49725",
      "185.141.25.244:33324",
      "185.193.48.135:8676",
      "185.193.50.233:443",
      "185.237.166.24:56218",
      "185.76.79.30:443",
      "188.214.33.170:443",
      "192.71.213.128:4431",
      "192.71.249.194:443",
      "193.142.58.38:34905",
      "193.29.58.210:15192",
      "194.110.246.254:443",
      "194.71.227.222:8855",
      "209.74.80.194:7699",
      "23.106.122.149:31174",
      "23.254.128.22:22812",
      "45.11.19.170:34318",
      "45.56.165.121:46346",
      "45.66.248.66:59142",
      "45.86.163.212:49920",
      "46.183.186.208:6060",
      "46.183.187.42:443",
      "46.183.25.24:52546",
      "46.249.38.18:41426",
      "46.249.38.18:52993",
      "46.30.188.43:51683",
      "46.30.190.137:51620",
      "46.30.190.160:60099",
      "46.30.191.221:443",
      "47.94.19.69:8080",
      "5.135.43.181:35598",
      "51.178.206.76:22812",
      "51.255.3.62:48152",
      "64.44.131.109:33638",
      "65.20.103.184:8080",
      "65.20.105.88:8082",
      "83.172.134.186:443",
      "83.243.121.87:443",
      "89.40.206.85:52529",
      "89.46.234.221:443",
      "89.46.234.221:9672",
      "89.46.236.152:443",
      "91.103.66.202:46882",
      "91.132.92.231:5959",
      "91.132.92.231:6060",
      "91.132.92.231:9314",
      "91.192.81.102:22981",
      "91.236.230.44:59310",
      "91.236.230.54:46056",
      "94.140.114.22:41322",
      "95.156.206.105:443",
      "95.169.180.122:443",
      "95.174.71.139:39006",
      "96.9.215.155:56172"
    ],
    "url": [
      "http://149.154.153.184",
      "http://151.236.9.75",
      "http://159.100.30.103",
      "http://162.0.229.203",
      "http://173.254.204.72",
      "http://193.142.58.186",
      "http://196.251.84.150",
      "http://37.1.214.196",
      "http://45.11.19.170",
      "http://45.61.139.69",
      "http://46.229.55.63",
      "http://46.30.191.221",
      "http://47.245.111.83",
      "http://63.250.38.240",
      "http://72.11.134.216",
      "http://72.18.215.1",
      "http://82.221.136.27",
      "http://94.156.175.95",
      "http://95.169.180.122",
      "jgcest.com/css/",
      "oppak.com/one/eths",
      "oppak.com/one/opa",
      "tusdec.org.pk/ee",
      "uniengrisb.com/img/rt.msi"
    ],
    "url_path": [
      "/45Ugty845nv7rt.php",
      "/CP/tre.php?pi=",
      "/CVBN/mzx.php",
      "/DMMA/hfo.php",
      "/DMMA/hfo.php?pi=",
      "/F1l3estPhPInf1.php",
      "/F1l3estPhPInf2.php",
      "/ML/vbn.php?pi=",
      "/Mcx2svc.php",
      "/OibytDsERt.php",
      "/OtPefhePbvw/",
      "/OtPefhePbvw/datarcvoninfile.php",
      "/OtPefhePbvw/nnodata3inf.php",
      "/OtPefhePbvw/onlinedata1inf.php",
      "/PerHyPfilbmiw1.php",
      "/PerHyPfilbmiw2.php",
      "/PsehestyvuPw/",
      "/PsehestyvuPw/F1l3estPhPInf1.php",
      "/ROAM/gret.php",
      "/RguhsT/",
      "/RguhsT/accept.php",
      "/RsdvgiMincSnyYu/",
      "/RsdvgiMincSnyYu/PerHyPfilbmiw1.php",
      "/RsdvgiMincSnyYu/PerHyPfilbmiw2.php",
      "/SzWvcxuer/",
      "/UihbywscTZ/",
      "/UihbywscTZ/45Ugty845nv7rt.php",
      "/VcvNbtgRrPopqSD/",
      "/VcvNbtgRrPopqSD/SzWvcxuer/",
      "/VcvNbtgRrPopqSD/SzWvcxuer/userlog.php",
      "/WORK/info.php?cve=",
      "/WVKA/qbv.php",
      "/anotherLife?credPart=",
      "/ceszvd.php",
      "/cloudzx/msweb/drdxcsv34.php",
      "/cloudzx/msweb/drxbds23.php",
      "/cloudzx/msweb/drxcvg45.php",
      "/cmpn/xing.php",
      "/cndrll.php",
      "/cndrll.php?er=",
      "/crvtyfgvwicidnex.php",
      "/dFFrt3856ByutTs/",
      "/dFFrt3856ByutTs/xnb/data1.php",
      "/datarcvoninfile.php",
      "/dozq/jkl.php",
      "/dozq/jkl.php?pi=",
      "/edgevrisinze.php",
      "/ergdfbd/",
      "/ergdfbd/wscspl",
      "/excerorderslistoncbook.php",
      "/frst.php?ys=",
      "/healthne/",
      "/healthne/accept.php",
      "/healthne/regdl",
      "/hgdtfjgtyf.php",
      "/imacnags/edgevrisinze.php",
      "/jdfgwe.php",
      "/jmv/jmd.php?st=",
      "/jsprc.php?h=",
      "/jvdmhawme.okjhvthfv",
      "/kna.php?ka=",
      "/kvs06v.php",
      "/lax05u.php",
      "/loccs.php?cn=",
      "/lux.php?cv=",
      "/mloknj.php",
      "/mloknj.php?cv=",
      "/ms2u1p.php",
      "/mscu/lokc.php",
      "/mscu/lokc.php?wl=",
      "/n9brCs21/",
      "/n9brCs21/apprun",
      "/nina/anotherLife?credPart=",
      "/nnodata3inf.php",
      "/onlinedata1inf.php",
      "/ourtyaz/",
      "/ourtyaz/dwnack.php",
      "/ourtyaz/qwe.php",
      "/ourtyaz/qwf.php",
      "/shrd.php?vo=",
      "/taskshandlers/DBhandle/primary_main.php",
      "/taskshandlers/DBhandle/secondary.php",
      "/teamesano/drivers/teamzid.php",
      "/textcmd/cmd1.php",
      "/textcmd/text.php?id1=",
      "/tstPerHyPfilbmiw1.php",
      "/tstPerHyPfilbmiwts2t.php",
      "/tstRsdvgiMincSnyYutsphp/",
      "/tstRsdvgiMincSnyYutsphp/tstPerHyPfilbmiw1.php",
      "/tstRsdvgiMincSnyYutsphp/tstPerHyPfilbmiwts2t.php",
      "/tstRsdvgiMincSnyYutspph/",
      "/tstRsdvgiMincSnyYutspph/tstPerHyPfilbmiw1.php",
      "/tstRsdvgiMincSnyYutspph/tstPerHyPfilbmiwts2t.php",
      "/updateReqServ10893x.php",
      "/uplh4ppy.php",
      "/v10.066/egrf.php",
      "/vbdfsbad.php",
      "/wipe/ret.php?eer=",
      "/wmis/wave.php?xas=",
      "/xyzxyzhanoiwhb3237gb2wahabjiki/",
      "/zserr.php",
      "/zserr.php?li="
    ]
  },
  "last_modified": "2026-06-26T12:15:09+00:00",
  "maltrail_groups": [
    "BITTER"
  ],
  "references": [
    "https://about.fb.com/wp-content/uploads/2022/08/Quarterly-Adversarial-Threat-Report-Q2-2022.pdf",
    "https://app.any.run/tasks/383a15aa-63b0-48ee-9a90-2cb64da9134f/",
    "https://app.any.run/tasks/a755b624-d146-4a49-acd5-c25e6b07aa3f",
    "https://app.docguard.io/fc72bd3e21cddcb3c181d7bdf1cacd2886701cdf9cc12be63061c2eeeda47ce9/results/dashboard",
    "https://app.validin.com/detail?type=dom&find=aduhoki88.com#tab=host_pairs_v2",
    "https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware/",
    "https://blog.pulsedive.com/unpacking-kiwistealer-diving-into-bitter-apts-malware-for-file-exfiltration/",
    "https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html",
    "https://blogs.blackberry.com/en/2024/11/suspected-nation-state-adversary-targets-pakistan-navy-in-cyber-espionage-campaign",
    "https://cert.360.cn/report/detail?id=137867e159331b7a968aa45050502d13",
    "https://cloud.tencent.com/developer/article/1826900",
    "https://github.com/blackorbird/APT_REPORT/tree/master/bitter/2022",
    "https://github.com/pan-unit42/iocs/blob/master/bitter/iocs.csv",
    "https://medium.com/@knownsec404team/unveiling-the-past-and-present-of-apt-k-47-weapon-asyncshell-5a98f75c2d68",
    "https://meltx0r.github.io/tech/2019/09/06/bitter-apt-not-so-sweet.html",
    "https://mp.weixin.qq.com/s/0iiCwpxNnd8akoT8RjU84A?ref=www.ctfiot.com",
    "https://mp.weixin.qq.com/s/8j_rHA7gdMxY1_X8alj8Zg (Chinese)",
    "https://mp.weixin.qq.com/s/CI1g4iaYxHhO925V15LvIQ",
    "https://mp.weixin.qq.com/s/HVhXyIB4sKuG6dDwwe4Pcw",
    "https://mp.weixin.qq.com/s/ItcbKuoH0KjJjzSTG7YSrA",
    "https://mp.weixin.qq.com/s/eseliIVHqiWI-Q1CoCA81g",
    "https://mp.weixin.qq.com/s/jH60_sYtZjJZWtVc5d277g",
    "https://mp.weixin.qq.com/s/kkl0jh14M9DtDGtSGQ4gag",
    "https://mp.weixin.qq.com/s/tkOMIHY36TujPKjWKVa6kA",
    "https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508516&idx=1&sn=a869f67294b5777615ad597c3730105e&chksm=f9c1912dceb6183b4f7f359de87814c613d58b671245307a99857eb03847a0860743516e7fae&scene=178&cur_album_id=1955835290309230595&search_click_id",
    "https://otx.alienvault.com/pulse/5d4d82f21a9bb34d2b0e65f7",
    "https://otx.alienvault.com/pulse/5fd7a716e178ff014c630ecb",
    "https://otx.alienvault.com/pulse/62f2344533e6cfe5e975f573",
    "https://strikeready.com/blog/open-sesame/",
    "https://ti.360.net/blog/articles/analysis-of-targeted-attack-against-pakistan-by-exploiting-inpage-vulnerability-and-related-apt-groups/ (Chinese)",
    "https://ti.qianxin.com/blog/articles/%22operation-magichm%22:CHM-file-release-and-subsequent-operation-of-BITTER-organization/ (Chenese)",
    "https://ti.qianxin.com/blog/articles/Blocking-APT:-Qianxin's-QOWL-Engine-Defeats-Bitter's-Targeted-Attack-on-Domestic-Government-and-Enterprises/",
    "https://tria.ge/250511-kptycahm6s/behavioral1",
    "https://tria.ge/251030-t3ev1s1khn/behavioral1",
    "https://twitter.com/AnonySecAgency/status/1423510463212523521",
    "https://twitter.com/Des00464472/status/1348964050076540928",
    "https://twitter.com/Des00464472/status/1607962294222454784",
    "https://twitter.com/Des00464472/status/1608357353589735425",
    "https://twitter.com/GGGGh0st/status/1512002541370097664",
    "https://twitter.com/HONKONE_K/status/1297829657568407554",
    "https://twitter.com/HONKONE_K/status/1464090084349669382",
    "https://twitter.com/HONKONE_K/status/1533694370805063680",
    "https://twitter.com/JVPv5sIM3eFmGyi/status/1654318267002163202",
    "https://twitter.com/JVPv5sIM3eFmGyi/status/1729760374960927051",
    "https://twitter.com/JVPv5sIM3eFmGyi/status/1765651279093612644",
    "https://twitter.com/James_inthe_box/status/1166128688175300608",
    "https://twitter.com/James_inthe_box/status/1183927764778274816",
    "https://twitter.com/LukasStefanko/status/1577553669700083714",
    "https://twitter.com/MeltX0R/status/1170183286712340482",
    "https://twitter.com/MeltX0R/status/1171245112082481153",
    "https://twitter.com/MeltX0R/status/1258870289066319872",
    "https://twitter.com/RedDrip7/status/1170988245561294850",
    "https://twitter.com/RedDrip7/status/1468420250245136390",
    "https://twitter.com/RedDrip7/status/1493905786354892801",
    "https://twitter.com/RedDrip7/status/1536987661939773440",
    "https://twitter.com/RedDrip7/status/1536989979229835265",
    "https://twitter.com/RedDrip7/status/1613474917038837764",
    "https://twitter.com/RexorVc0/status/1727230322855833657",
    "https://twitter.com/RexorVc0/status/1744276666782716098",
    "https://twitter.com/Richard_S81/status/1557419346078666752",
    "https://twitter.com/Rmy_Reserve/status/1224289465872502789",
    "https://twitter.com/SethKingHi/status/1522867750481408001",
    "https://twitter.com/SethKingHi/status/1523592393249136640",
    "https://twitter.com/SethKingHi/status/1583039595524259841",
    "https://twitter.com/ShadowChasing1/status/1256036038331387904",
    "https://twitter.com/ShadowChasing1/status/1303628547366350848",
    "https://twitter.com/ShadowChasing1/status/1304017919655858177",
    "https://twitter.com/ShadowChasing1/status/1305879886473474048",
    "https://twitter.com/ShadowChasing1/status/1306422911972958210",
    "https://twitter.com/ShadowChasing1/status/1306858164277526528",
    "https://twitter.com/ShadowChasing1/status/1356412596430233603",
    "https://twitter.com/ShadowChasing1/status/1375227175226368006",
    "https://twitter.com/ShadowChasing1/status/1408579870230126592",
    "https://twitter.com/ShadowChasing1/status/1408579947417927687",
    "https://twitter.com/ShadowChasing1/status/1438706652522303489",
    "https://twitter.com/ShadowChasing1/status/1474005551818313729",
    "https://twitter.com/ShadowChasing1/status/1478259210110775297",
    "https://twitter.com/ShadowChasing1/status/1479641732169932801",
    "https://twitter.com/ShadowChasing1/status/1480193191299084288",
    "https://twitter.com/ShadowChasing1/status/1480853604609126403",
    "https://twitter.com/ShadowChasing1/status/1521401317360513025",
    "https://twitter.com/StopMalvertisin/status/1613833615984721922",
    "https://twitter.com/StopMalvertisin/status/1614460800680472579",
    "https://twitter.com/StopMalvertisin/status/1618434887220105216",
    "https://twitter.com/StopMalvertisin/status/1622200643787309056",
    "https://twitter.com/StopMalvertisin/status/1623199772810301447",
    "https://twitter.com/StopMalvertisin/status/1623199776476131328",
    "https://twitter.com/StopMalvertisin/status/1628694986140311552",
    "https://twitter.com/StopMalvertisin/status/1633398160843485185",
    "https://twitter.com/StopMalvertisin/status/1639339836225253377",
    "https://twitter.com/StopMalvertisin/status/1639340323200733184",
    "https://twitter.com/StopMalvertisin/status/1666834231983767558",
    "https://twitter.com/StopMalvertisin/status/1722944218015179147",
    "https://twitter.com/ThreatBookLabs/status/1602611437326991360",
    "https://twitter.com/ThreatBookLabs/status/1603675610504499200",
    "https://twitter.com/ThreatBookLabs/status/1611260753151164417",
    "https://twitter.com/ThreatBookLabs/status/1622884433945829376",
    "https://twitter.com/ThreatBookLabs/status/1662266116247552001",
    "https://twitter.com/ThreatBookLabs/status/1676953190913433607",
    "https://twitter.com/ThreatBookLabs/status/1677666593982271488",
    "https://twitter.com/ThreatBookLabs/status/1681656384071376897",
    "https://twitter.com/ThreatBookLabs/status/1688902207566196736",
    "https://twitter.com/Timele9527/status/1169430987832344576",
    "https://twitter.com/Timele9527/status/1169785910881218560",
    "https://twitter.com/Timele9527/status/1201477767352553472",
    "https://twitter.com/Timele9527/status/1201477848852090881",
    "https://twitter.com/Timele9527/status/1201477876236701696",
    "https://twitter.com/Timele9527/status/1277843761318354944",
    "https://twitter.com/Timele9527/status/1280315854094123008",
    "https://twitter.com/__0XYC__/status/1501847173864083458",
    "https://twitter.com/__0XYC__/status/1501852899491852288",
    "https://twitter.com/__0XYC__/status/1770689612031164671",
    "https://twitter.com/_re_fox/status/1301887287765225477",
    "https://twitter.com/_re_fox/status/1305925337004601345",
    "https://twitter.com/alex_lanstein/status/1765088371108639175",
    "https://twitter.com/alex_lanstein/status/1785026144246325630",
    "https://twitter.com/binlmmhc/status/1377080167881924608",
    "https://twitter.com/binlmmhc/status/1437704326789488642",
    "https://twitter.com/binlmmhc/status/1485545135882784768",
    "https://twitter.com/binlmmhc/status/1529782539199868928",
    "https://twitter.com/binlmmhc/status/1539094292064784384",
    "https://twitter.com/binlmmhc/status/1555002494593679361",
    "https://twitter.com/binlmmhc/status/1610969202722242561",
    "https://twitter.com/binlmmhc/status/1686659755622924288",
    "https://twitter.com/binlmmhc/status/1686661719261958144",
    "https://twitter.com/blackorbird/status/1169925232255090689",
    "https://twitter.com/blackorbird/status/1182479754965876737",
    "https://twitter.com/blackorbird/status/1187662590224191489",
    "https://twitter.com/blackorbird/status/1295265067173163010",
    "https://twitter.com/blackorbird/status/1520688352286052352",
    "https://twitter.com/blackorbird/status/1534373342446202881",
    "https://twitter.com/ccxsaber/status/1192326844529422337",
    "https://twitter.com/ccxsaber/status/1273442309816770560",
    "https://twitter.com/doc_guard/status/1729861690613989781",
    "https://twitter.com/fmc_nan/status/1638874363335409667",
    "https://twitter.com/fmc_nan/status/1639175633019478017",
    "https://twitter.com/ginkgo_g/status/1598138502017085440",
    "https://twitter.com/ginkgo_g/status/1696470343979012600",
    "https://twitter.com/ginkgo_g/status/1729698368987787591",
    "https://twitter.com/ginkgo_g/status/1746827915306909954",
    "https://twitter.com/ginkgo_g/status/1753259443675156855",
    "https://twitter.com/ginkgo_g/status/1783386949765718155",
    "https://twitter.com/ginkgo_g/status/1784505204391739493",
    "https://twitter.com/h2jazi/status/1499501002743062539",
    "https://twitter.com/h2jazi/status/1509636768504717313",
    "https://twitter.com/h2jazi/status/1551980359990104064",
    "https://twitter.com/h2jazi/status/1594688392314474502",
    "https://twitter.com/h2jazi/status/1765117935469658451",
    "https://twitter.com/h4ckak/status/1147710998817542145",
    "https://twitter.com/k3yp0d/status/1490994886338027527",
    "https://twitter.com/k3yp0d/status/1525508775980957698",
    "https://twitter.com/k3yp0d/status/1527656133837594624",
    "https://twitter.com/kyleehmke/status/1510958302800318467",
    "https://twitter.com/lightC07379408/status/1706965936098390431",
    "https://twitter.com/liqingjia1989/status/1656105672365477888",
    "https://twitter.com/liqingjia1989/status/1672787159424835585",
    "https://twitter.com/liqingjia1989/status/1672792060007714816",
    "https://twitter.com/liqingjia1989/status/1694531703505813618",
    "https://twitter.com/liqingjia1989/status/1706835231536525805",
    "https://twitter.com/liqingjia1989/status/1724011550825136526",
    "https://twitter.com/liqingjia1989/status/1734459198245867732",
    "https://twitter.com/liqingjia1989/status/1742010387481121156",
    "https://twitter.com/liqingjia1989/status/1743080624196661436",
    "https://twitter.com/liqingjia1989/status/1745729324349825131",
    "https://twitter.com/liqingjia1989/status/1760112384071606393",
    "https://twitter.com/liqingjia1989/status/1776779248524755435",
    "https://twitter.com/liqingjia1989/status/1777622247936491681",
    "https://twitter.com/liqingjia1989/status/1784846105416708314",
    "https://twitter.com/liqingjia1989/status/1787752297461846466",
    "https://twitter.com/liqingjia1989/status/1788123283931717847",
    "https://twitter.com/malwrhunterteam/status/1408491293207154696",
    "https://twitter.com/malwrhunterteam/status/1577401341768568854",
    "https://twitter.com/malwrhunterteam/status/1742941632922624097",
    "https://twitter.com/suyog41/status/1640346154205343747",
    "https://twitter.com/suyog41/status/1663857230616186881",
    "https://twitter.com/suyog41/status/1671452383879081984",
    "https://twitter.com/suyog41/status/1684892151316955136",
    "https://twitter.com/suyog41/status/1686298387455283200",
    "https://twitter.com/suyog41/status/1698568505535414578",
    "https://twitter.com/suyog41/status/1717061493068640648",
    "https://twitter.com/suyog41/status/1730172467094983083",
    "https://twitter.com/suyog41/status/1731632299618525471",
    "https://twitter.com/suyog41/status/1732637340299104556",
    "https://twitter.com/suyog41/status/1737375533250511276",
    "https://twitter.com/suyog41/status/1765296640028774450",
    "https://twitter.com/suyog41/status/1785925227337375766",
    "https://www.anomali.com/blog/suspected-bitter-apt-continues-targeting-government-of-china-and-chinese-organizations",
    "https://www.blackberry.com/content/dam/blackberry-com/asset/enterprise/pdf/direct/mobile-malware-report.pdf",
    "https://www.bleepingcomputer.com/news/security/hackers-install-dracarys-android-malware-using-modified-signal-app/",
    "https://www.proofpoint.com/us/blog/threat-insight/bitter-end-unraveling-eight-years-espionage-antics-part-one (# ta397)",
    "https://www.seqrite.com/blog/ung0002-espionage-campaigns-south-asia/",
    "https://www.threatray.com/blog/the-bitter-end-unraveling-eight-years-of-espionage-antics-part-two (# ta397)",
    "https://www.virustotal.com/gui/collection/f6f862c588961ae94c5c23d92331b85e5023ed7064c00d1299f73d47aadf699d/iocs",
    "https://www.virustotal.com/gui/file/06dd9a7aebe0995b23526f04eabc85db3d2d98def9be58c1012a1280f5aa63f1/detection",
    "https://www.virustotal.com/gui/file/07504fcef717e6b74ed381e94eab5a9140171572b5572cda87b275e3873c8a88/detection",
    "https://www.virustotal.com/gui/file/08674b806c13a1dab09645483021708e9eef6dd6d5fa7ece2955a096d68e9477/detection",
    "https://www.virustotal.com/gui/file/08d12b65525d05e6c4e2d308a1e1edc1329ac29d39cf71b1ce883b03ace7d406/detection",
    "https://www.virustotal.com/gui/file/090b1691a623cc6e8d956ed41ab3efdae98ab9db1bb95cbcbea3162f7a54abf9/detection",
    "https://www.virustotal.com/gui/file/09647fabb086acf09fdc72f3e8703c77c65e27fa52de14c9976389ef1bf4a843/detection",
    "https://www.virustotal.com/gui/file/0b230b83c0b4af6e13ad837c35121d0827f5a243855a5d8a80e299b9c91ad5ae/detection",
    "https://www.virustotal.com/gui/file/0b6d4f7a545e6fc1bfc907f76e9291a75f1fbb679dcb87c5a72cf2dcadf4aa6f/detection",
    "https://www.virustotal.com/gui/file/0ca1ce61d917771ed344f8345a81610e4c03eb9d186353e2f339e38345e3296d/detection",
    "https://www.virustotal.com/gui/file/0ce047bb77073990a8810f8d6f178dc0d4fc5257603790f80d3d84b0b2405a6c/detection",
    "https://www.virustotal.com/gui/file/0db680ad035e30a4d17716538ab56af73492c722480da1ff683b550dbacf45bd/detection",
    "https://www.virustotal.com/gui/file/1126916c98b7801175375827fb5e8b8cee23e4bd920691ff7acd9a648ec13b67/detection",
    "https://www.virustotal.com/gui/file/117ae7b2d08c8f11be7e4c4f27e54fa1d3a816073502241f1bb6277c89c67d85/detection",
    "https://www.virustotal.com/gui/file/11dff82741190cdb7934fd996796ad8b9e564ebc7e903036824acba99fb7d6af/detection",
    "https://www.virustotal.com/gui/file/121c3917e7b2e00d7c6e15f09370d21e2531e3dff27b177e69a10aa234a1bf37/detection",
    "https://www.virustotal.com/gui/file/132098213b5923463611e6fc77bfce0cfad3d727566ce0e87e9723456c698ae6/detection",
    "https://www.virustotal.com/gui/file/14986da600df26fdb4e435cf01b6be4e5fffcc001059609070a2de701496bdde/detection",
    "https://www.virustotal.com/gui/file/14ce282ffeaa5cc3d214acae33785795ae63021158305a7d6d305296539936d9/detection",
    "https://www.virustotal.com/gui/file/14e43110cc3c40bf56d95df0079cc744055b1568dbceac05b50a2c0159bef872/detection",
    "https://www.virustotal.com/gui/file/15161231be575991c70252cc33cdd2c41b5c3b255d6510790bef32be9b6ff5a2/detection",
    "https://www.virustotal.com/gui/file/15337ad45a65f8f9eae57f76d6cff314968417665750f336c6154a2c05991582/detection",
    "https://www.virustotal.com/gui/file/15a58d7223761f8386c902ae2d55a1313b4744e543f8f228851d0376dce721fe/detection",
    "https://www.virustotal.com/gui/file/15db9daa175d506c3e1eaee339eecde8771599ed81adfac48fa99aa5c2322436/detection",
    "https://www.virustotal.com/gui/file/1854e0e0a59a82e4d9629dd54a506eb442a4d71e0b8c9984b444cb9407a89f42/detection",
    "https://www.virustotal.com/gui/file/195682cc8a6318d3eb2af83faaff76dc925e3e382b13729b9e03cf6d8f5435b0/detection",
    "https://www.virustotal.com/gui/file/1ac7f4cee8b614359cb0997c1934e8b2e4cab0bbfddfa84bedb6d1b2f55e26f3/detection",
    "https://www.virustotal.com/gui/file/1b60ef6900dc790f2565e4fd27b14742ed6bec53252e3b142f0af6a246d94837/detection",
    "https://www.virustotal.com/gui/file/1dd50966db005e30f7a69b6d16dfe8b9810dba3cdbe43bebb136f8786d027ed1/detection",
    "https://www.virustotal.com/gui/file/1e7ce7c530a1cf4d74a356592f99bde2ca359ed4b4144f32cc69ab705f52e4e2/detection",
    "https://www.virustotal.com/gui/file/1ea9e9ecd0e5b0ac4aedc1b5515484a372dd8aefb1dbeb00f243a0a3ce40fab9/detection",
    "https://www.virustotal.com/gui/file/1f262d5838e29f56eb190100f0753f2ae9c6a2b56954b0fef0f5481a2014fe00/detection",
    "https://www.virustotal.com/gui/file/1fd8ba64a687247466fa6e8b7d194154439ef527746fdb8c18b3c3d65b6d2390/detection",
    "https://www.virustotal.com/gui/file/20bf58300532c55c46c19ff9c634bd8f3d48c577b1d8414cb6d4d2fbb1716087/detection",
    "https://www.virustotal.com/gui/file/220fcfa47a11e7e3f179a96258a5bb69914c17e8ca7d0fdce44d13f1f3229548/detection (# Dracarys)",
    "https://www.virustotal.com/gui/file/22dd82c94cadf5cf31b3e9519e8149d4a68fe13bac13eaef91bf283a4beb8101/detection",
    "https://www.virustotal.com/gui/file/243e4d1e53a805f61d2c4e8cabdd02e99a51fba37101b3e0535f219383871091/detection",
    "https://www.virustotal.com/gui/file/2544d79e47c01c9714264550b9e31151f66a9384d6aca33ee83cdfa8649dbb46/detection",
    "https://www.virustotal.com/gui/file/258918e48a7aaf393af89858f95af666d260c4035b63195f29c8ecfb3291ccb5/detection",
    "https://www.virustotal.com/gui/file/25aeec4c58f740c62664c757987902981c9676d0f58f9337f852fa9dd8a874d9",
    "https://www.virustotal.com/gui/file/28b586cf4f84eeb6ced3e5b40451e0075b6b0250ab7936a1147f6858b217fae1/detection",
    "https://www.virustotal.com/gui/file/28cb51c171d591b2bb35bc9a4379010fd37f66cfcd317a67cb73b24262dc17c6/detection",
    "https://www.virustotal.com/gui/file/294323c2611edeb7bae0ff3993ac48eed50c16abe04ff6afbf735b16cf8bcd10/detection",
    "https://www.virustotal.com/gui/file/2b0f8c6261b4e9e97732efadad14fcb66872474f092f8c7fd69b941cd4796912/detection",
    "https://www.virustotal.com/gui/file/2b25469b0e23fc024f5ca147948292cd4175a18625cb8a5b67ab04300082866f/detection",
    "https://www.virustotal.com/gui/file/2ba30469c3cbe13aa02073ae6c48114d2902450c3745857946b30d811eff6e6d/detection",
    "https://www.virustotal.com/gui/file/2c5a14edacc03a57458d82607067207911b0b92003641e0b973d90630483d4ce/detection",
    "https://www.virustotal.com/gui/file/2eca2f7a1fb4654dd73bf4a999ce155b2303e47340b26a49623f5b32948060c3/detection",
    "https://www.virustotal.com/gui/file/2fe49d93b5dcf19a2b60e91756246b051adc89303151c9e0b875c3f21c698be9/detection",
    "https://www.virustotal.com/gui/file/3037f41f422033a11ed86871ea7f6dbba8b910dbee3212eb33165e488eecde14/detection",
    "https://www.virustotal.com/gui/file/303bc4bce9555b02d9b1c0b96eb5736561d70fca3b994b353db2cc1b2eca66ca/detection",
    "https://www.virustotal.com/gui/file/309740ee31eff70c8510340293cc45b135c4791a8a7c70e8a12ea6b4f1217ff5/detection",
    "https://www.virustotal.com/gui/file/30f9676fb31a2ee5c4d5ec9e3809422cad8efcc7f409d4e5ba96d3229e42ae61/detection",
    "https://www.virustotal.com/gui/file/31214e97722f99666dde6b09f386e71843895b0f3b4ebe373d7858f5dbec8ce2/detection",
    "https://www.virustotal.com/gui/file/34182232200718be91a1b683112f8e44c1ee75bf3b11e2c055de68d990e0dd92/detection",
    "https://www.virustotal.com/gui/file/359200a112936939f8b324bee7edc943e97cbf0677c8478bfa20b5b333a47663/detection",
    "https://www.virustotal.com/gui/file/35952afc1c9f5597348373cee4611bc37287076606ca1b912d6a73aeee26602a/detection",
    "https://www.virustotal.com/gui/file/389883cfa666855750974c540299de82f1ee8b51670b337e6cd86617f44817cc/detection",
    "https://www.virustotal.com/gui/file/3d529596440dfc64a7db106ddb77ec65fb88d48d6e30e7760e67b50905165ae7/detection",
    "https://www.virustotal.com/gui/file/408292710999abc4d37f23a6672ef407d70ffb4dc2e3e030a5ec705735c1f8bd/detection",
    "https://www.virustotal.com/gui/file/413d0aacddad41105f9f04de12cae9420919083796ed856df47ee2c7b3767fda/detection",
    "https://www.virustotal.com/gui/file/414d6ed63baaaa69a555068e91e1ee89dbcf38cac7ac4918f6e50fb82d039485/detection",
    "https://www.virustotal.com/gui/file/42ab740ff15988b4f919b31a6203fb40f9470d281791f0d7c96eb80586d6b2eb/detection",
    "https://www.virustotal.com/gui/file/43c8ada7cb7c046893dd96aef195856ec94f62823ca1a2987adf31899788c92d/detection",
    "https://www.virustotal.com/gui/file/445c801e857329e1740745b4949349a02971530c4f5d28a8e9e5489c3516933a/detection",
    "https://www.virustotal.com/gui/file/4664dc63b2faaa69ee7440980da0b9894a5267f06cfe3948b0f762196c0b50b7/detection",
    "https://www.virustotal.com/gui/file/471b384ca81a9d804992d4e4693ab3d42d419a2e2690ebb146671407fe0809d8/detection",
    "https://www.virustotal.com/gui/file/482e4f64e1aa9096bed00dbe0cc6451441c0f0d0bf5a9d33e3011057f4bed9c5/detection",
    "https://www.virustotal.com/gui/file/4885affbac1695037c5fbfc000ff54021406c5da58a14fca96dd34f6de499220/detection",
    "https://www.virustotal.com/gui/file/490eccbb2712e7752a0ba193f783de9d333f67ba1fde5bb130280c5abf77555a/detection",
    "https://www.virustotal.com/gui/file/499bf98bef84eeff781828932b16747a5aa03d3f70e15aabf4718cccd20a51a5/detection",
    "https://www.virustotal.com/gui/file/4baf42e448120bd26fd0198c1b3382296fa3cb47f6c882fd5a9f4693d88847e5/detection",
    "https://www.virustotal.com/gui/file/4c556d9e902c8cc0096bb56447075834f19ea456f5871e08a948da4bb3192db8/detection",
    "https://www.virustotal.com/gui/file/4ca4f673e4389a352854f5feb0793dac43519ade8049b5dd9356d0cbe0f06148/detection",
    "https://www.virustotal.com/gui/file/4dfe81aeb881c9e7cf0a469542d3908df9d7c5bc87c8fe1061254d77a53cb1d3/detection",
    "https://www.virustotal.com/gui/file/4e0824b6c9c4e53a7caeda78c8b60bf1dc20670e58955ad1e2e9f89fdf22029c/detection",
    "https://www.virustotal.com/gui/file/4e32e86f1feeaecc03f7f9d4734a41dffe98893fccd1ff2004029c708c160e20/detection",
    "https://www.virustotal.com/gui/file/4e3e4d476810c95c34b6f2aa9c735f8e57e85e3b7a97c709adc5d6ee4a5f6ccc/detection",
    "https://www.virustotal.com/gui/file/4f94e7bd1515e0025293fb5a041bc41c20a7dd15a6dd0bc7076145a69d5238c0/detection",
    "https://www.virustotal.com/gui/file/507aa944d77806b3f24a3337729b52168808e8d469e5253cbf889cdaabb5254e/detection",
    "https://www.virustotal.com/gui/file/510b3de50c8dfc20a3085166f373a5f12475c7915984de0afa3cc0bff0c2580d/detection",
    "https://www.virustotal.com/gui/file/52362a3bf05d0f65c49d527bfecec76472502ec0fbd9ebac96c832c8af362385/detection",
    "https://www.virustotal.com/gui/file/528c6bf7c0c32be26bc1e32df73fed73ca7312e1b6fdb2ca20d5f0c157b02256/detection",
    "https://www.virustotal.com/gui/file/52a4020392de0d527fe0aaf551fa557628c68419415b86afa36854d0bc987d9d/detection",
    "https://www.virustotal.com/gui/file/5374d2b9c9802d3b04735134960be84033c390b9279aea5b8ff7cbca8eaf9a4c/detection",
    "https://www.virustotal.com/gui/file/53e9d201163cd5fc1adf3974afb41c6a31496737bdbbefec3be7205d63a3780e/detection",
    "https://www.virustotal.com/gui/file/55901c2d5489d6ac5a0671971d29a31f4cdfa2e03d56e18c1585d78547a26396/detection",
    "https://www.virustotal.com/gui/file/561ace43f77de135d5b3286bd2ef270b185d0abdba15d442551211068f8bbf11/detection",
    "https://www.virustotal.com/gui/file/563fd6ff3f767d8120731803aeec9e5f5fc3a26a48567ac57d95493ca18133ee/detection",
    "https://www.virustotal.com/gui/file/575b783b3bd38271450a2c2cc8fb3ad0dc5ba69e044ad9aa0684851a3426cc06/detection",
    "https://www.virustotal.com/gui/file/5a98b05cff064c3884c689e4f4fb991533cf631de39299a924d69d8376661b0c/detection",
    "https://www.virustotal.com/gui/file/5b90d4c397e575965ed49082981fd34272b5e1da010057f6ebcdd4f53a409ad0/detection",
    "https://www.virustotal.com/gui/file/5bdbec839592af17a725c5705201d331848b12912a0889d2edad07fcc85f76b8/detection",
    "https://www.virustotal.com/gui/file/5de9131252e6bc5a336516b9de4d7e0e0e2e3cde38ace85dbda39a3a166eb1a5/detection",
    "https://www.virustotal.com/gui/file/624decbc0445e51873436e42699323bf48093e0c4ba5ea1d348e9e5a1822579b/detection",
    "https://www.virustotal.com/gui/file/62e42d3e778fd79b7989966b057c24c141531f871a7c73703b35858ab3d13f47/detection",
    "https://www.virustotal.com/gui/file/636c2a16f94b5e30e725527a1bd2215399f98f17cc08580bc7358751b9eb2944/detection",
    "https://www.virustotal.com/gui/file/64fd1e641731e48ea8c3df7b9caa5f8074dea15e99093b137af2acfe66754f73/detection",
    "https://www.virustotal.com/gui/file/65419a704f252f8c3574d90cf016b6bfdd70b63f65dbc5b57d44a3a6ef457f80/detection",
    "https://www.virustotal.com/gui/file/667e411ec65acc61eea0be0dbae8a4ffde8529e905c780cd35f71ef9ebc0a0bf/detection",
    "https://www.virustotal.com/gui/file/66a73b1b3b51a1c6a56db2d20cff9af3d1362b989989b5d9543d2e9b92ac9a3d/detection",
    "https://www.virustotal.com/gui/file/66eff3058760b478aa70b44b929ca59fec9c5b401e7a7d8f7af5b06f4c8aa398/detection",
    "https://www.virustotal.com/gui/file/6763fadbfbcf125a73cc6388aba075f51caa2883a071178e438c7046dd92a1a5/detection",
    "https://www.virustotal.com/gui/file/67c0ad5ab6be8efec70a53cc56a03b581c7712eee7310ec5a8afba583c2b75bb/detection",
    "https://www.virustotal.com/gui/file/6ac16df25b0faead1d019f73edd9b12bac9f356d8250b5637f3f6a0b94e73c75/detection",
    "https://www.virustotal.com/gui/file/6b475078aca28ef7c8b162065b562e61670aceea1602715f53d64d81e7023a2a/detection",
    "https://www.virustotal.com/gui/file/6cb0c0a2f89d1e82653d2b0dd1389007543616d11f0709ff194a4db2d36865f7/detection",
    "https://www.virustotal.com/gui/file/6cdc79edba95c6a9ec1d50457dc16f40f02c46a7d0b9665f099abe8155d1a25c/detection",
    "https://www.virustotal.com/gui/file/6d92924ff3a1de18fe715c2e7432ee3db912696135f78b7627440ace6f94ecfa/detection",
    "https://www.virustotal.com/gui/file/6f0bc10f8326b462e02cf97f4aac1ef87b8eee99ca364fada3948a21e585f359/detection",
    "https://www.virustotal.com/gui/file/6f5ce57dce03d9456657ad872766ee8f78b1b6c258a8b99c7658bc0590813d4d/detection",
    "https://www.virustotal.com/gui/file/6fd40f0aba5c6bd9dd784abd8f5c0ede41e81e7cc4c0a9c614bd2aa32f449f89/detection",
    "https://www.virustotal.com/gui/file/71fa6a00314701fef5c6f32c17e1438063d05616198ac9a12004aeab957e11ae/detection",
    "https://www.virustotal.com/gui/file/73f3a0d2d93c36276e1ecc7ebe64bede9c5adcfd01c5bebc89be75dc5b70111e/detection",
    "https://www.virustotal.com/gui/file/7525cecb3d45097db48ee08410ba2b2ae1f9db84f887098557b09e7f8fa79a81/detection",
    "https://www.virustotal.com/gui/file/7847a287472f7e2b688bd5d000f43584007337e11359cc14d4c42d1f8d84efdb/detection",
    "https://www.virustotal.com/gui/file/7b801221a024507ff948261bf5b635d93d1dc816d02f8255c495c6529a26cc4c/detection",
    "https://www.virustotal.com/gui/file/7ca837a4e410b57e0c54bb6fb3a7ef756b0913a77339e5d11c5e9371c3ee64b2/detection",
    "https://www.virustotal.com/gui/file/7ea0930a332788c2e88e5822e4908d77cdcaad57e0e97401ed8fe4b117fdfc95/detection",
    "https://www.virustotal.com/gui/file/813c67414723ea162e789b1fc4b269839351863050f27a2f906426dac3a86f39/detection",
    "https://www.virustotal.com/gui/file/81afc6d8e369ba8f08753541c78db4c424703e59a23d5d3bfbc46bc359c7336a/detection",
    "https://www.virustotal.com/gui/file/820ab2458839688369906cee2a4c08b4694e2bddcb187358ce575e5d2063515e/behavior",
    "https://www.virustotal.com/gui/file/833501101c1af641e9910389596e79f672dc721f57936e0f23898fa748f3b71b/detection",
    "https://www.virustotal.com/gui/file/836c8fb1ff998d3b94b4800aca7b17675893fe87a39b658000a776c5b3fe852c/detection",
    "https://www.virustotal.com/gui/file/83ca53918af3ea659d767e489a1e42ea97879e3e534f68c4edc7d0eb77f44204/detection",
    "https://www.virustotal.com/gui/file/83e64fc374eff67e66b476d32bfd3455840da66c618a0381822d23ef872fe5f2/detection",
    "https://www.virustotal.com/gui/file/84f2b3cde61895fbe28c3660d5f8d796f6eac6a969838eb340283a50a2c3de09/detection",
    "https://www.virustotal.com/gui/file/85a6ac13510983b3a29ccb2527679d91c86c1f91fdfee68913bc5d3d01eeda2b/detection",
    "https://www.virustotal.com/gui/file/85fae6eb3d173274e59293d31d48c119608682862390f70d58b9ad7465dcbc1e/detection",
    "https://www.virustotal.com/gui/file/86c4e9a4615836c6fc7c44f458a3fa784fe347f23b062b08ec22999cda15b2a9/detection",
    "https://www.virustotal.com/gui/file/8753006b62b74c6805e6cb22e149a487784ca31be6f15e94b1ada8a439f91290/detection",
    "https://www.virustotal.com/gui/file/876122fcc9e0d5ebd42df9e93d37ad23d9f521e6077e9cb8b05862ae157757e3/detection",
    "https://www.virustotal.com/gui/file/886c36f4625f98537e8f2df5975aab643ad355e13e35023842a10129c0c46865/detection",
    "https://www.virustotal.com/gui/file/891ffe498debc7accfbdf9146adb6de6f2cfd8c083bb374fe8db073a4b106581/detection",
    "https://www.virustotal.com/gui/file/8958b215f30f9d48010fb93363125dcaf265c18d3d8df04d299df8313fa6be5f/detection",
    "https://www.virustotal.com/gui/file/89e609cc48e0926b8121ed943bf9561d0ed0ac682d811618d56d0602ccca847c/detection",
    "https://www.virustotal.com/gui/file/8aeb7dd31c764b0cf08b38030a73ac1d22b29522fbcf512e0d24544b3d01d8b3/detection",
    "https://www.virustotal.com/gui/file/8af2d392181c359ce04e38ab113e22e526eae4c6f715d26462e439a3db1eb948/detection",
    "https://www.virustotal.com/gui/file/8b57d6b676afdd84786655eb5fc8769711ffefb9f4d2db7770a16c4ef9ae6592/detection",
    "https://www.virustotal.com/gui/file/8b79f6b2061e3231da4ef75799ad9754d64c336ce34fbc9a4538b0b3020fff8a/detection",
    "https://www.virustotal.com/gui/file/8b7f36b3af85639ea0fcdd35eda43e64ac59d034ebd43a884601ef6ae29bb71e/detection",
    "https://www.virustotal.com/gui/file/8bb36cb759cada50695ae3b5156b6f603c92081147400db544ac75ece8ce7129/detection",
    "https://www.virustotal.com/gui/file/8c4416b735826bd35707b9caad356292c82a574e5d85a5ce6e013754352d9098/detection",
    "https://www.virustotal.com/gui/file/8c95b0d740df0f91444d5ddb9107f3a41ac80c12c471c60c26e0a9513092464c/detection",
    "https://www.virustotal.com/gui/file/8cfc803459682619e97f172e9cca33458fdf38b0b9ca09f8ccbc7df16f09240f/detection",
    "https://www.virustotal.com/gui/file/8f03eb3fe7363bb7ab291c86680a71ad2820527ffbf067103f0c8909956c059e/detection",
    "https://www.virustotal.com/gui/file/8f5f92e4d901eccf63e76223cacce47a29cdd533fb513d08abc7f659a8869382/detection",
    "https://www.virustotal.com/gui/file/91ddbe011f1129c186849cd4c84cf7848f20f74bf512362b3283d1ad93be3e42/detection",
    "https://www.virustotal.com/gui/file/939f509a8edc6b9da103fbcebe85630671ed591dd9e40243da37559e10dcfd80/detection",
    "https://www.virustotal.com/gui/file/93a905048ca8cdf7162ade1720d50883495bf1bbc000c828a6844a88a73a05db/detection",
    "https://www.virustotal.com/gui/file/941011523ce613d6729e83febc1de7d3f907e116a29257f24610133e0a83d2a9/detection",
    "https://www.virustotal.com/gui/file/95990cac90d19e6fe48bff85a72148c35facbb2e61b1f326d85e82603240a741/detection",
    "https://www.virustotal.com/gui/file/96f74896774ad4877740378d216afde6cdc962729b2ff8b9a56393ad14ea7f58/detection",
    "https://www.virustotal.com/gui/file/974626cf14864f0a3185233bbce417d37bf5c8ad6e3c82774985db027b54acd2/detection",
    "https://www.virustotal.com/gui/file/974abd4dc03bd9dc1a5d7ae56d2882b5f69627c5af8f77a64fa880186b437007/detection",
    "https://www.virustotal.com/gui/file/9a8b201eb2bebe309d15c7b0ab5a6dcde460b84b035bb3575d4a0ec6af51a37e/detection",
    "https://www.virustotal.com/gui/file/9b21e4b32e3e125bad638df76f25ca364a53cd50e324ab961a571a06b755a658/detection",
    "https://www.virustotal.com/gui/file/9ca64c2672258e72d297dbf0d2d7a57d92d6011e75ac08ba4feb01e8a975cf09/detection",
    "https://www.virustotal.com/gui/file/9da7bb7065b91ec4634c080955d7ab086f7bc6f5391d1db10751812c38bcff19/detection",
    "https://www.virustotal.com/gui/file/9fb6f4c55e5198739123264f8007cf6e22b3821af97a00a471bd54b30991ecd0/detection",
    "https://www.virustotal.com/gui/file/9fca7eeb6a7c3591492ddb7693b9d7b2349acc3240cc46710f91fb79d8a8deb6/detection",
    "https://www.virustotal.com/gui/file/9fcae6572e9d474e131e64b639becf0bbaea7297edd451459f069fb20742b1f2/detection",
    "https://www.virustotal.com/gui/file/a0a18e76d8af39b9b198d9ea7c67dc372fa3cdb2286ac405fa8e76154af34fff/detection",
    "https://www.virustotal.com/gui/file/a152fa2e7368ed357a91214fdd91e1742541955f76c0d2bd936ec2d856bde38e/detection",
    "https://www.virustotal.com/gui/file/a169156b0d307ca978d722cafbd3bc1d04c94e55f71bc9d16ba6fabb8140be83/detection",
    "https://www.virustotal.com/gui/file/a1bb8ce0cf7290524326442be9b8ecce883d860f6437dcc4bc64b99f72004fdd/detection",
    "https://www.virustotal.com/gui/file/a2e3f464e1c39909f47f0b837b04e1256061f4a9698678e097b4dd09aa4de9c1/detection",
    "https://www.virustotal.com/gui/file/a447a890c7738c259ae0fc03958fbd6a96abd350a5acb9cc39fd8b3e7d450147/detection",
    "https://www.virustotal.com/gui/file/a4afaa41383f447d96d0ebb1e2e50721af080e951d40754a836215fb2c3f0660/detection",
    "https://www.virustotal.com/gui/file/a76f00ea65cf7fb9327e9b6d2d4acac61196feb30bd8fa164179ca81b9349c7e/detection",
    "https://www.virustotal.com/gui/file/a850a903b74c1d3d21c41e03761e8e64b43962269e7649940b10368a005bce20/detection",
    "https://www.virustotal.com/gui/file/a979c76afd0e9d2e135ca64a215e1af270222d059d806e7028022060e8cbe72c/detection",
    "https://www.virustotal.com/gui/file/ab26ffe31e0c6b247781b20eba4f405ade35ebe6d87d49e7780a65ea7bd870dc/detection",
    "https://www.virustotal.com/gui/file/acfb3223d5bcbcf96ee1265fdd510c124bfa3f1ae8670a7f7b48f46fc9895ee0/detection",
    "https://www.virustotal.com/gui/file/ae8d252986c616884c10ab5082088cc9e413ddf5f9a0e292a1f2c5c0764c74e7/detection",
    "https://www.virustotal.com/gui/file/aecfa3879cd68b3a2ab0771638c0d649b007cbb6f28dddb56af4fb740b8e25a5/detection",
    "https://www.virustotal.com/gui/file/afaaa7d065ad7267dfbd2b69cd0d0eee7af5e4416bdc27d5de3f7640695bc809/detection",
    "https://www.virustotal.com/gui/file/b1efa4e3abadfab14aba6e36ed9f4105dc859f86968126de2e0ec792745c87d5/detection",
    "https://www.virustotal.com/gui/file/b3b2d915f47aa631cc4900ec56f9b833e84d20e850d78f42f78ad80eb362b8fc/detection",
    "https://www.virustotal.com/gui/file/b514635f569791316e1c55057f63f596847e23c0fa1ca0f751c5a2135f72b8ff/detection",
    "https://www.virustotal.com/gui/file/b6bd48fa94fa15cdcbd6b24198472faeb0d79e7c41efb26da507be7c311b7bec/detection",
    "https://www.virustotal.com/gui/file/b7a9407b47baf7442e0baf94a3b4cc8b7420cb01364fc8e6a3c622b7ae39301f/detection",
    "https://www.virustotal.com/gui/file/ba2853547fe79f52461323295f9bc528f3689cfa1882ddc549dfac76fa9e2498/detection",
    "https://www.virustotal.com/gui/file/ba2e21641a1238a5b30e535bd0940fcd316a6e5242bfdd48a97aaa203d11642b/detection",
    "https://www.virustotal.com/gui/file/ba352569428df4618cd57f91bd3479b73a798399a6b861ed996d715bc51e916c/detection",
    "https://www.virustotal.com/gui/file/bb67a4de756336d45ebaa7657a7586b4ebff26c74aba458d62de85c2070f3d90/detection",
    "https://www.virustotal.com/gui/file/bbe94912c0dd4b812decf9d4e8a81d1f5ad215627334b50d949ff407d7062e5f/detection",
    "https://www.virustotal.com/gui/file/bc764b4af4edeaf94920c75c7956b8bb6f7315071c3781d61c029f235cb62d96/detection",
    "https://www.virustotal.com/gui/file/be6be16175f523214ce49f765245ea38b4c5ecb24b15d08180232df0eb728e23/detection",
    "https://www.virustotal.com/gui/file/c00570eb0b47614b7286cf945b212774dde69572aa4d9bf273438921fb1cb557/detection",
    "https://www.virustotal.com/gui/file/c0120c1f458497602ae3068e7e755d5056f7a0b2c28c9e6ba9a3bfe12b27ad56/detection",
    "https://www.virustotal.com/gui/file/c0d926b33ae2351a9a528ba4d7ca13be7d55ba3455d52c5a69c8b381ade28ed0/detection",
    "https://www.virustotal.com/gui/file/c151a8861d4f75c09803efa677322193d04c4ec4e5b9d8eadcc6cbea69069b57/detection",
    "https://www.virustotal.com/gui/file/c1f27bed733c5bcf76d2e37e1f905d6c4e7abaeb0ea8975fca2d300c19c5e84f/detection",
    "https://www.virustotal.com/gui/file/c2131a3906d97b5d7d697d16de15a8f704db1e6e4a8d3d7316c784d45716cffc/detection",
    "https://www.virustotal.com/gui/file/c24efc7c4dafd4f0b39e7ae7e84627fbd0fb766019b820cb11edbb8dda54de66/detection",
    "https://www.virustotal.com/gui/file/c2e492da957ef5c76b3cc8890007c4f419ec510b5f9f259c2a0161c032ebc987/detection",
    "https://www.virustotal.com/gui/file/c3fc4d145ce3cee06782753be269cad6632751fb9b824e1917b0de6e597ee2ee/detection",
    "https://www.virustotal.com/gui/file/c44d142a4cf541afcc4b5fc6612c7db8d49a147332e027c45c7b15aa32489421/detection",
    "https://www.virustotal.com/gui/file/c492bdf749b0a229cb256e1ee04e1c48b7472a351f04605415c11d40063cd14a/detection",
    "https://www.virustotal.com/gui/file/c77ae7c9533eddbb5f2b80889590436aac7df6166abefc51d5a65f775e6258dc/detection",
    "https://www.virustotal.com/gui/file/c8b93075675b6b90cc5a2f58bdd1c52088a511485efd2f9bb6de54c9736e98e5/detection",
    "https://www.virustotal.com/gui/file/c93e0f954cfcfafbb07cc248fab3167eee51f9986304ed4afe0bf92965c83587/detection",
    "https://www.virustotal.com/gui/file/c967e7d3c8227e209537257bfe21a69aa2943e4a7b21cf8f79d2904df29404f7/detection",
    "https://www.virustotal.com/gui/file/caf871247b7256945598816e9c5461d64b6bdb68a15ff9f8742ca31dc00865f8/detection",
    "https://www.virustotal.com/gui/file/cb4a280f54c56d250c98124a88e80c46ccd82cb77ff0951f150f01e02791ca30/detection",
    "https://www.virustotal.com/gui/file/cb7e6640ab5c1dad5083e5790d6009c317894406b970d42a34758e99a9ff7f94/detection",
    "https://www.virustotal.com/gui/file/cbfa2aa73ea8bdc126c6767efd61a822786f4b48479859a6d14246a25d8ebd1a/detection",
    "https://www.virustotal.com/gui/file/cc1c7e53ea567509a4bcfda2df95cb8f6ed7eed7cb2ae8786b736cd4d858173a/detection",
    "https://www.virustotal.com/gui/file/cd3effd25629ab9c440ed8bedb9bfb312c73a022cad5078684784ea07eff2c68/detection",
    "https://www.virustotal.com/gui/file/ced29451faed4f5dfa9ce80e35469e3573a89f848d5a7f5b087ee62a62f5f89a/detection",
    "https://www.virustotal.com/gui/file/cfd883237a56a1a59c2882b9c7e11272ab32b76b35bbf69358c1168e82aae278/detection",
    "https://www.virustotal.com/gui/file/d02fd3472adb0d7a502b08656c5001093a7a052905f406979873b464e9ca2378/detection",
    "https://www.virustotal.com/gui/file/d07b4487348de35df5e4cfa7c26c8cc6432230c1df220d2379fc702e25850909/detection",
    "https://www.virustotal.com/gui/file/d0ee008d3c480d5f9f75332851ae94373158c13541f3c88be63465b975334e0a/detection",
    "https://www.virustotal.com/gui/file/d28df7a8a275f628660e2f2744bfa36bc5b5c7ae1a8d3a63fbfefa79f04b805e/detection",
    "https://www.virustotal.com/gui/file/d597c488b73cde0938b464f93ed9eebf24e1ac4a885b1f41a8875aeb9272b664/detection",
    "https://www.virustotal.com/gui/file/d6a533102f801066ddd6069e20f3a51e802852b72c6e105b6e1b8a2c035d0722/detection",
    "https://www.virustotal.com/gui/file/d94ff0edb28f7b90b9e4ab9ee94e8dcc33389538f15f536fa154b9506830c31f/detection",
    "https://www.virustotal.com/gui/file/dbd72490ce2642721ba8919b27a5f4854d2a8199132e9c4bb08f54b48282febc/detection",
    "https://www.virustotal.com/gui/file/dcdae583da8a1b01a8ad0caef6a7f6f3b6f1eb6dd3298ac7d904200f52712446/detection",
    "https://www.virustotal.com/gui/file/dea912dce66c32598ec2d0a24b9e0b5f690b3ed714b978578048bc8b28b2ed02/detection",
    "https://www.virustotal.com/gui/file/deb241a46da181c8c1f68a43745fcbf8a6927e4344c2fc96ef4cf31c828576c8/detection",
    "https://www.virustotal.com/gui/file/ded0635c5ef9c3d63543abc36a69b1176875dba84ca005999986bd655da3a446/detection",
    "https://www.virustotal.com/gui/file/df5c0d787de9cc7dceeec3e34575220d831b5c8aeef2209bcd81f58c8b3c08ed/detection",
    "https://www.virustotal.com/gui/file/dfedb0033337aaa8570ef682a931196c36864931fb48605ac82cee94a2d51a4a/detection",
    "https://www.virustotal.com/gui/file/e07e8cbeeddc60697cc6fdb5314bd3abb748e3ac5347ff108fef9eab2f5c89b8/detection",
    "https://www.virustotal.com/gui/file/e1aff2618bad2418023730bab3e2e119fb9682dafac5078456800cc98f2178e0/detection",
    "https://www.virustotal.com/gui/file/e44d034ceb135990452fce74d358bdf7841316fdcb6db1172e6e5e3e07ffa4bd/detection",
    "https://www.virustotal.com/gui/file/e61e41d73682c166e7cf8c8a1db169f0f689fa2b70e19cfb0033e4c9211d9de6/detection",
    "https://www.virustotal.com/gui/file/e6b523e77c31b89f8eb3489007bf14b3b9d34bc3870a9d96ecf7b99efa506c76/detection",
    "https://www.virustotal.com/gui/file/e8149ba0e8ce1a48142df2009688d5aa657286d56638b36da1c5ea2376ba6f9f/detection",
    "https://www.virustotal.com/gui/file/ea73818d5c96294381ea56af0bdda98a987704ee478d8ab374e53e2bafec892b/detection",
    "https://www.virustotal.com/gui/file/eaa013b863bda3bd76c6f6073cc304002d1a9f317c8fba9c362534aff7dd1b0b/detection",
    "https://www.virustotal.com/gui/file/edb68223db3e583f9a4dd52fd91867fa3c1ce93a98b3c93df3832318fd0a3a56/detection",
    "https://www.virustotal.com/gui/file/ee088e6d8ac0f3dbfbd17f556a58d06cc882016fd8a4a8ba2ddcd0cab5322d23/detection",
    "https://www.virustotal.com/gui/file/efeaadaa53ec033d224b58be109c0f5fde12c8775fc5603f51efa8e23bcd6fb2/detection",
    "https://www.virustotal.com/gui/file/f2f783a72e955ecbcddc448764921a753bd1ac4dd14128200bb4866021287ae7/detection",
    "https://www.virustotal.com/gui/file/f45590dbb07e6a506c19f62b3f23b17a1aefbb6d8287f94a74c3ea707e6f4736/detection",
    "https://www.virustotal.com/gui/file/f598f3bd60a39ad5861f145e82b33acde146b6ed5c2ffd9c6862ca1ea635afbf/detection",
    "https://www.virustotal.com/gui/file/f5e066da37fc9da2ca68678aa1e001c4428e9476dde8a927cb76fa9389038b06/detection",
    "https://www.virustotal.com/gui/file/f692ba8fbe76ee5488fd81ad3ae6689744b7b8f9e35712cb6848bb7151f7bf1d/detection",
    "https://www.virustotal.com/gui/file/f6afa3080c4f69eaaeb4d43c723672031b4a5b7130b1db8361786180e6bba380/detection",
    "https://www.virustotal.com/gui/file/f7e25e5601fdf038aa0840be508cf1d5915cd5317a5513cd7e7c3ae76055839f/detection",
    "https://www.virustotal.com/gui/file/f7ed5eec6d1869498f2fca8f989125326b2d8cee8dcacf3bc9315ae7566963db/detection",
    "https://www.virustotal.com/gui/file/f95167754f162097b83495baa070d3a0036b335a22c6d584300dd94b45988780/detection",
    "https://www.virustotal.com/gui/file/fb91c7fd342803ae581ea52e78bc610ab876cb5eb900486cb4fa7009feee2233/detection",
    "https://www.virustotal.com/gui/file/fbab7758765265a6988e78779cae2e12d093813217d09230136185d72f726c3c/detection",
    "https://www.virustotal.com/gui/file/fc39ec35d767a2c0a178ca9874be8aaf87033f8b834ee8dcb57d3904516e4335/detection",
    "https://www.virustotal.com/gui/file/fc72bd3e21cddcb3c181d7bdf1cacd2886701cdf9cc12be63061c2eeeda47ce9/detection",
    "https://www.virustotal.com/gui/file/fc9f84bad598c057b595efbca7ae0ae9a1678de7f2185275953424b3ec47a00e/detection",
    "https://www.virustotal.com/gui/file/fd2f4f23bb4d42a0d758d56ccb04a133301b21320a7cc346367db04965aea0c7/detection",
    "https://www.virustotal.com/gui/file/fdc7cff892b890cb46c3c6d9fd3e8a62bb3059caaf034d63ba7d615342f17f70/detection",
    "https://www.virustotal.com/gui/file/fec00455734451b722f3037e0a668c280c5ddbec1d905c647bf1a7f153856860/detection",
    "https://www.virustotal.com/gui/file/ffea43ead04d4bda567b1fd32ec68c8903ac7dbf9d63e001f804dbd0f717bbdf/detection",
    "https://www.virustotal.com/gui/file/ffee624870767c528c9d7578833483a496279508e665c5d24f6b9445490cda27/detection",
    "https://www.virustotal.com/gui/ip-address/103.57.251.154/relations",
    "https://www.virustotal.com/gui/ip-address/104.200.73.57/relations",
    "https://www.virustotal.com/gui/ip-address/135.125.242.211/relations",
    "https://www.virustotal.com/gui/ip-address/146.70.118.226/relations",
    "https://www.virustotal.com/gui/ip-address/172.86.68.175/relations",
    "https://www.virustotal.com/gui/ip-address/172.93.201.143/relations",
    "https://www.virustotal.com/gui/ip-address/185.244.151.84/relations",
    "https://www.virustotal.com/gui/ip-address/192.71.249.194/relations",
    "https://www.virustotal.com/gui/ip-address/63.250.38.240/relations",
    "https://www.virustotal.com/gui/ip-address/69.61.36.170/relations",
    "https://www.virustotal.com/gui/ip-address/69.61.36.186/relations",
    "https://www.virustotal.com/gui/ip-address/74.119.239.234/relations",
    "https://www.virustotal.com/gui/ip-address/78.110.166.82/relations",
    "https://www.virustotal.com/gui/ip-address/82.221.129.39/relations",
    "https://www.virustotal.com/gui/ip-address/91.236.230.44/relations",
    "https://www.virustotal.com/gui/ip-address/93.123.73.160/relations",
    "https://x.com/AndreGironda/status/1955692280825962846",
    "https://x.com/BaoshengbinCumt/status/1946009959831126054",
    "https://x.com/RedDrip7/status/1794979757559599555",
    "https://x.com/RedDrip7/status/1852178923695804654",
    "https://x.com/RedDrip7/status/1952922656220823798",
    "https://x.com/RedDrip7/status/1962415190051573781",
    "https://x.com/RedDrip7/status/1964874030869332252",
    "https://x.com/RedDrip7/status/1976923481377063382",
    "https://x.com/RedDrip7/status/1976924908736405560",
    "https://x.com/RedDrip7/status/1978366720432562372",
    "https://x.com/RedDrip7/status/1993874904710828150",
    "https://x.com/RedDrip7/status/1998638735358128307",
    "https://x.com/RedDrip7/status/2001489642072482032",
    "https://x.com/RedDrip7/status/2004026276294938903",
    "https://x.com/RedDrip7/status/2009443295127326763",
    "https://x.com/RedDrip7/status/2011023732341686629",
    "https://x.com/RedDrip7/status/2014542257488306575",
    "https://x.com/RedDrip7/status/2016415763633242298",
    "https://x.com/RedDrip7/status/2019243120131805198",
    "https://x.com/RedDrip7/status/2027209484784017629",
    "https://x.com/RedDrip7/status/2031616083569029525",
    "https://x.com/RedDrip7/status/2037368638605570409",
    "https://x.com/RedDrip7/status/2037368885876564464",
    "https://x.com/RedDrip7/status/2038827595018727498",
    "https://x.com/RedDrip7/status/2047579562184413587",
    "https://x.com/RedDrip7/status/2049775100237676647",
    "https://x.com/RexorVc0/status/2049740014875967766",
    "https://x.com/SethKingHi/status/1876845124488941942",
    "https://x.com/ShadowChasing1/status/1824630406823678214",
    "https://x.com/ShanHolo/status/1971249000985788673",
    "https://x.com/StrikeReadyLabs/status/1808457407632224733",
    "https://x.com/StrikeReadyLabs/status/1811034367856161254",
    "https://x.com/StrikeReadyLabs/status/1820787452174368831",
    "https://x.com/StrikeReadyLabs/status/1822458511940264187",
    "https://x.com/StrikeReadyLabs/status/1824790667765190793",
    "https://x.com/StrikeReadyLabs/status/1831506911839080873",
    "https://x.com/StrikeReadyLabs/status/1834599289391108556",
    "https://x.com/StrikeReadyLabs/status/1834609928285110285",
    "https://x.com/StrikeReadyLabs/status/1835445587149562137",
    "https://x.com/StrikeReadyLabs/status/1837317218943525321",
    "https://x.com/StrikeReadyLabs/status/1839037780644471181",
    "https://x.com/StrikeReadyLabs/status/1846000315566375184",
    "https://x.com/StrikeReadyLabs/status/1851227466259443931",
    "https://x.com/StrikeReadyLabs/status/1856371787145130399/history",
    "https://x.com/StrikeReadyLabs/status/1861383328521207980",
    "https://x.com/StrikeReadyLabs/status/1864408026658041888",
    "https://x.com/StrikeReadyLabs/status/1865140931953070382",
    "https://x.com/ThreatrayLabs/status/1986432637762732515",
    "https://x.com/WhichbufferArda/status/1921506670343061548",
    "https://x.com/__0XYC__/status/1930552371530129610",
    "https://x.com/__0XYC__/status/1930552424353202399",
    "https://x.com/alex_lanstein/status/1792638726931161109",
    "https://x.com/banthisguy9349/status/1867179104899854616",
    "https://x.com/banthisguy9349/status/1867458625532506452",
    "https://x.com/blackorbird/status/1845000997665755151",
    "https://x.com/blackorbird/status/1846487125249970293",
    "https://x.com/blackorbird/status/1850060334079610936",
    "https://x.com/blackorbird/status/1854529596156182765",
    "https://x.com/blackorbird/status/1856340219328639441",
    "https://x.com/blackorbird/status/1858873110625243398",
    "https://x.com/blackorbird/status/1859161598469836806",
    "https://x.com/blackorbird/status/1862131045883408582",
    "https://x.com/blackorbird/status/1958836180587307479",
    "https://x.com/blackorbird/status/1981958007958524023",
    "https://x.com/blackorbird/status/1986747686050287997",
    "https://x.com/blackorbird/status/2051892318203175106",
    "https://x.com/blackorbird/status/2064727597435752846",
    "https://x.com/frdfzi/status/1930495401456533564",
    "https://x.com/ginkgo_g/status/1850821079260094731",
    "https://x.com/ginkgo_g/status/1897192606196703668",
    "https://x.com/ginkgo_g/status/1933364194998694198",
    "https://x.com/k3yp0d/status/1823652687029698699",
    "https://x.com/k3yp0d/status/1836001049976422810",
    "https://x.com/karol_paciorek/status/1818204812564938798",
    "https://x.com/liqingjia1989/status/1795058403540173275",
    "https://x.com/liqingjia1989/status/1795276257627877723",
    "https://x.com/liqingjia1989/status/1798160822134546655",
    "https://x.com/liqingjia1989/status/1811658282366271537",
    "https://x.com/liqingjia1989/status/1831906877841797172",
    "https://x.com/liqingjia1989/status/1833410135005483214",
    "https://x.com/liqingjia1989/status/1834427464837464131",
    "https://x.com/liqingjia1989/status/1930584300224676024",
    "https://x.com/mal_analysis136/status/1793123437680210067",
    "https://x.com/mal_analysis136/status/1826491897910886675",
    "https://x.com/mal_analysis136/status/1831562638104703371",
    "https://x.com/mal_analysis136/status/1846049340328198352",
    "https://x.com/mal_analysis136/status/1863537157119299620",
    "https://x.com/mal_analysis136/status/1864285903058809266",
    "https://x.com/mal_analysis136/status/1865323680344969262",
    "https://x.com/malwrhunterteam/status/1923660512920744438",
    "https://x.com/malwrhunterteam/status/1925086462120165852",
    "https://x.com/malwrhunterteam/status/1929906003258048816",
    "https://x.com/malwrhunterteam/status/1994001214795862270",
    "https://x.com/malwrhunterteam/status/2002470001924813279",
    "https://x.com/nextronresearch/status/2070473326372291037",
    "https://x.com/silentpush_labs/status/1839077173141094605",
    "https://x.com/skocherhan/status/2024194564605579358",
    "https://x.com/smica83/status/1983935993209069584",
    "https://x.com/smica83/status/2044417422606655769",
    "https://x.com/suyog41/status/1808379399953146053",
    "https://x.com/suyog41/status/1813453691019571279",
    "https://x.com/suyog41/status/1820766059814953246",
    "https://x.com/suyog41/status/1831196846615633926",
    "https://x.com/suyog41/status/1837073539121434966",
    "https://x.com/suyog41/status/1864199979369447473",
    "https://x.com/suyog41/status/1922608403454583215",
    "https://x.com/suyog41/status/1924329354504634767",
    "https://x.com/suyog41/status/1929855753206083762",
    "https://x.com/suyog41/status/1952709606297227414",
    "https://x.com/suyog41/status/1952990924210094369",
    "https://x.com/suyog41/status/1963171056044109898",
    "https://x.com/volrant136/status/1923686317252075887",
    "https://x.com/volrant136/status/1924126261514833963",
    "https://x.com/volrant136/status/1930659807440039970",
    "https://x.com/volrant136/status/1941557096933359638",
    "https://x.com/volrant136/status/1956393083949502767",
    "https://x.com/volrant136/status/2041159217374244990",
    "https://x.com/wa1Ile/status/1795747139601195042",
    "https://x.com/wa1Ile/status/1814284608269353136",
    "https://x.com/wa1Ile/status/1823643124562022487",
    "https://x.com/wa1Ile/status/1858421539286168058",
    "https://x.com/wa1Ile/status/1925447893743542391"
  ],
  "related": [
    {
      "evidence": [
        {
          "detail": "2 shared indicators",
          "kind": "infrastructure",
          "weight": 2.0
        },
        {
          "detail": "1 report cite both",
          "kind": "reporting",
          "weight": 1.0
        }
      ],
      "slug": "G0040"
    },
    {
      "evidence": [
        {
          "detail": "1 shared indicator",
          "kind": "infrastructure",
          "weight": 1.0
        }
      ],
      "slug": "G0112"
    },
    {
      "evidence": [
        {
          "detail": "8 reports cite both",
          "kind": "reporting",
          "weight": 8.0
        }
      ],
      "slug": "G0121"
    },
    {
      "evidence": [
        {
          "detail": "1 report cite both",
          "kind": "reporting",
          "weight": 1.0
        }
      ],
      "slug": "UNCLASSIFIED"
    },
    {
      "evidence": [
        {
          "detail": "1 report cite both",
          "kind": "reporting",
          "weight": 1.0
        }
      ],
      "slug": "G0050"
    },
    {
      "evidence": [
        {
          "detail": "1 report cite both",
          "kind": "reporting",
          "weight": 1.0
        }
      ],
      "slug": "G0097"
    },
    {
      "evidence": [
        {
          "detail": "1 report cite both",
          "kind": "reporting",
          "weight": 1.0
        }
      ],
      "slug": "VENOMSPIDER"
    },
    {
      "evidence": [
        {
          "detail": "1 report cite both",
          "kind": "reporting",
          "weight": 1.0
        }
      ],
      "slug": "G0032"
    }
  ],
  "slug": "G1002",
  "timeline": [
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-06-26",
      "indicators": {
        "domain": [
          "ultraflavors.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/nextronresearch/status/2070473326372291037",
        "https://www.virustotal.com/gui/file/d0ee008d3c480d5f9f75332851ae94373158c13541f3c88be63465b975334e0a/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2026-06-11",
      "indicators": {
        "domain": [
          "downloadclouddata.com"
        ],
        "ipv4": [
          "163.245.220.108:8442"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/2064727597435752846",
        "https://mp.weixin.qq.com/s/jH60_sYtZjJZWtVc5d277g"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2026-05-06",
      "indicators": {
        "domain": [
          "fswhardtools.com",
          "vpn146318720.softether.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/2051892318203175106"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 3,
        "ipv4": 2,
        "url": 1
      },
      "first_seen": "2026-04-30",
      "indicators": {
        "domain": [
          "domainnamevalidator.com",
          "domainregistationcheck.com",
          "getserviceupdates.com"
        ],
        "ipv4": [
          "151.236.4.164:5010",
          "89.46.236.152:443"
        ],
        "url": [
          "http://46.30.191.221"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RexorVc0/status/2049740014875967766",
        "https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508516&idx=1&sn=a869f67294b5777615ad597c3730105e&chksm=f9c1912dceb6183b4f7f359de87814c613d58b671245307a99857eb03847a0860743516e7fae&scene=178&cur_album_id=1955835290309230595&search_click_id"
      ],
      "total": 6
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-04-30",
      "indicators": {
        "domain": [
          "bravojacksonmentor.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2049775100237676647",
        "https://www.virustotal.com/gui/file/359200a112936939f8b324bee7edc943e97cbf0677c8478bfa20b5b333a47663/detection",
        "https://www.virustotal.com/gui/file/c151a8861d4f75c09803efa677322193d04c4ec4e5b9d8eadcc6cbea69069b57/detection",
        "https://www.virustotal.com/gui/file/84f2b3cde61895fbe28c3660d5f8d796f6eac6a969838eb340283a50a2c3de09/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2026-04-24",
      "indicators": {
        "domain": [
          "grandinaspectrum.com"
        ],
        "url_path": [
          "/hgdtfjgtyf.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2047579562184413587",
        "https://www.virustotal.com/gui/file/563fd6ff3f767d8120731803aeec9e5f5fc3a26a48567ac57d95493ca18133ee/detection",
        "https://www.virustotal.com/gui/file/85fae6eb3d173274e59293d31d48c119608682862390f70d58b9ad7465dcbc1e/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-04-15",
      "indicators": {
        "domain": [
          "invstampvest.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/smica83/status/2044417422606655769",
        "https://www.virustotal.com/gui/file/6fd40f0aba5c6bd9dd784abd8f5c0ede41e81e7cc4c0a9c614bd2aa32f449f89/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-04-06",
      "indicators": {
        "domain": [
          "commonlifesupport.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/volrant136/status/2041159217374244990",
        "https://www.virustotal.com/gui/file/0b6d4f7a545e6fc1bfc907f76e9291a75f1fbb679dcb87c5a72cf2dcadf4aa6f/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2026-03-31",
      "indicators": {
        "ipv4": [
          "188.214.33.170:443"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2038827595018727498",
        "https://www.virustotal.com/gui/file/7ea0930a332788c2e88e5822e4908d77cdcaad57e0e97401ed8fe4b117fdfc95/detection",
        "https://www.virustotal.com/gui/file/9fb6f4c55e5198739123264f8007cf6e22b3821af97a00a471bd54b30991ecd0/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2026-03-27",
      "indicators": {
        "domain": [
          "haburyohoteam.com"
        ],
        "url_path": [
          "/jvdmhawme.okjhvthfv"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2037368885876564464",
        "https://www.virustotal.com/gui/file/bbe94912c0dd4b812decf9d4e8a81d1f5ad215627334b50d949ff407d7062e5f/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-03-27",
      "indicators": {
        "domain": [
          "caravelcruiser.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2037368638605570409",
        "https://www.virustotal.com/gui/file/c967e7d3c8227e209537257bfe21a69aa2943e4a7b21cf8f79d2904df29404f7/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2026-03-11",
      "indicators": {
        "domain": [
          "99media.com.pk",
          "zoemagicbook.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2031616083569029525",
        "https://www.virustotal.com/gui/file/fb91c7fd342803ae581ea52e78bc610ab876cb5eb900486cb4fa7009feee2233/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2026-02-27",
      "indicators": {
        "domain": [
          "ashersoftlib.com"
        ],
        "ipv4": [
          "107.172.39.100:44908"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2027209484784017629",
        "https://www.virustotal.com/gui/file/e6b523e77c31b89f8eb3489007bf14b3b9d34bc3870a9d96ecf7b99efa506c76/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-02-19",
      "indicators": {
        "domain": [
          "officesignature.info"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/skocherhan/status/2024194564605579358",
        "https://www.virustotal.com/gui/file/4885affbac1695037c5fbfc000ff54021406c5da58a14fca96dd34f6de499220/detection",
        "https://www.virustotal.com/gui/file/5a98b05cff064c3884c689e4f4fb991533cf631de39299a924d69d8376661b0c/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-02-19",
      "indicators": {
        "domain": [
          "nelavohomet.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://strikeready.com/blog/open-sesame/",
        "https://www.virustotal.com/gui/ip-address/172.86.68.175/relations",
        "https://www.virustotal.com/gui/file/15337ad45a65f8f9eae57f76d6cff314968417665750f336c6154a2c05991582/detection",
        "https://www.virustotal.com/gui/file/ba352569428df4618cd57f91bd3479b73a798399a6b861ed996d715bc51e916c/detection",
        "https://www.virustotal.com/gui/file/ee088e6d8ac0f3dbfbd17f556a58d06cc882016fd8a4a8ba2ddcd0cab5322d23/detection",
        "https://www.virustotal.com/gui/file/52a4020392de0d527fe0aaf551fa557628c68419415b86afa36854d0bc987d9d/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2,
        "url_path": 2
      },
      "first_seen": "2026-02-05",
      "indicators": {
        "domain": [
          "pinkrosesandmore.com",
          "prolukemarion.com"
        ],
        "url_path": [
          "/ceszvd.php",
          "/vbdfsbad.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2019243120131805198",
        "https://www.virustotal.com/gui/file/941011523ce613d6729e83febc1de7d3f907e116a29257f24610133e0a83d2a9/detection",
        "https://www.virustotal.com/gui/file/28b586cf4f84eeb6ced3e5b40451e0075b6b0250ab7936a1147f6858b217fae1/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2026-01-28",
      "indicators": {
        "ipv4": [
          "134.255.210.127:443"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2016415763633242298",
        "https://www.virustotal.com/gui/file/836c8fb1ff998d3b94b4800aca7b17675893fe87a39b658000a776c5b3fe852c/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-23",
      "indicators": {
        "domain": [
          "crudestopics.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2014542257488306575",
        "https://www.virustotal.com/gui/file/6d92924ff3a1de18fe715c2e7432ee3db912696135f78b7627440ace6f94ecfa/detection",
        "https://www.virustotal.com/gui/file/d597c488b73cde0938b464f93ed9eebf24e1ac4a885b1f41a8875aeb9272b664/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2026-01-13",
      "indicators": {
        "domain": [
          "broadsforthestate.com"
        ],
        "url_path": [
          "/jdfgwe.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2011023732341686629",
        "https://www.virustotal.com/gui/file/8753006b62b74c6805e6cb22e149a487784ca31be6f15e94b1ada8a439f91290/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "ipv4": 2
      },
      "first_seen": "2026-01-09",
      "indicators": {
        "ipv4": [
          "185.193.50.233:443",
          "83.243.121.87:443"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/2009443295127326763",
        "https://www.virustotal.com/gui/file/deb241a46da181c8c1f68a43745fcbf8a6927e4344c2fc96ef4cf31c828576c8/detection",
        "https://www.virustotal.com/gui/file/dfedb0033337aaa8570ef682a931196c36864931fb48605ac82cee94a2d51a4a/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 10,
        "ipv4": 2
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "jmxdnqr8.mediumblog.online",
          "manage.mediumblog.online",
          "mediumblog.online",
          "qdey4uvj.mediumblog.online",
          "rgevzuir.mediumblog.online",
          "services.windowmediaplayer.media",
          "unr0wddj.mediumblog.online",
          "vzgmbwva.mediumblog.online",
          "windowmediaplayer.media",
          "yorkstar.mediumblog.online"
        ],
        "ipv4": [
          "103.57.251.154:4443",
          "192.71.213.128:4431"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/ThreatrayLabs/status/1986432637762732515",
        "https://www.virustotal.com/gui/ip-address/103.57.251.154/relations",
        "https://www.virustotal.com/gui/file/090b1691a623cc6e8d956ed41ab3efdae98ab9db1bb95cbcbea3162f7a54abf9/detection",
        "https://www.virustotal.com/gui/file/0ca1ce61d917771ed344f8345a81610e4c03eb9d186353e2f339e38345e3296d/detection"
      ],
      "total": 12
    },
    {
      "counts": {
        "domain": 11
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "alvesbarcelona.com",
          "app.chabaka.com",
          "balkanclan.com",
          "chabaka.com",
          "com-ae.net",
          "drogbachelsea.com",
          "mail.alvesbarcelona.com",
          "mail.com-ae.net",
          "mail.drogbachelsea.com",
          "mail.youtubepremiumapp.com",
          "opfor.balkanclan.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/volrant136/status/1923686317252075887"
      ],
      "total": 11
    },
    {
      "counts": {
        "domain": 6,
        "url_path": 4
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "365cloudz.esanojinjasvc.com",
          "eliteteam.esanojinjasvc.com",
          "esanojinjasvc.com",
          "msoffice.365cloudz.esanojinjasvc.com",
          "supportteaminterface.esanojinjasvc.com",
          "teamlogin.esanojinjasvc.com"
        ],
        "url_path": [
          "/cloudzx/msweb/drdxcsv34.php",
          "/cloudzx/msweb/drxbds23.php",
          "/cloudzx/msweb/drxcvg45.php",
          "/teamesano/drivers/teamzid.php"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/RedDrip7/status/1976924908736405560",
        "https://x.com/RedDrip7/status/1976923481377063382",
        "https://www.virustotal.com/gui/ip-address/78.110.166.82/relations",
        "https://www.virustotal.com/gui/file/bb67a4de756336d45ebaa7657a7586b4ebff26c74aba458d62de85c2070f3d90/detection",
        "https://www.virustotal.com/gui/file/f7e25e5601fdf038aa0840be508cf1d5915cd5317a5513cd7e7c3ae76055839f/detection"
      ],
      "total": 10
    },
    {
      "counts": {
        "domain": 4,
        "ipv4": 3
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "ecoglide.site",
          "marine-research.space",
          "pentree.online",
          "skyfare.site"
        ],
        "ipv4": [
          "162.0.216.229:21443",
          "162.0.216.229:8888",
          "209.74.80.194:7699"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/malwrhunterteam/status/1929906003258048816",
        "https://x.com/BaoshengbinCumt/status/1946009959831126054",
        "https://www.seqrite.com/blog/ung0002-espionage-campaigns-south-asia/",
        "https://www.virustotal.com/gui/file/4ca4f673e4389a352854f5feb0793dac43519ade8049b5dd9356d0cbe0f06148/detection"
      ],
      "total": 7
    },
    {
      "counts": {
        "domain": 6,
        "url": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "blucollinsoutien.com",
          "headntale.com",
          "trkswqsservice.com",
          "utizviewstation.com",
          "warsanservices.com",
          "woodstocktutors.com"
        ],
        "url": [
          "http://46.229.55.63"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/frdfzi/status/1930495401456533564",
        "https://www.proofpoint.com/us/blog/threat-insight/bitter-end-unraveling-eight-years-espionage-antics-part-one (# ta397)",
        "https://www.threatray.com/blog/the-bitter-end-unraveling-eight-years-of-espionage-antics-part-two (# ta397)"
      ],
      "total": 7
    },
    {
      "counts": {
        "domain": 4,
        "url_path": 2
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "fogomyart.com",
          "greenadelhouse.com",
          "maximasigns.greenadelhouse.com",
          "tradesmarkets.greenadelhouse.com"
        ],
        "url_path": [
          "/crvtyfgvwicidnex.php",
          "/excerorderslistoncbook.php"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/WhichbufferArda/status/1921506670343061548",
        "https://tria.ge/250511-kptycahm6s/behavioral1",
        "https://www.virustotal.com/gui/file/15db9daa175d506c3e1eaee339eecde8771599ed81adfac48fa99aa5c2322436/detection",
        "https://www.virustotal.com/gui/file/edb68223db3e583f9a4dd52fd91867fa3c1ce93a98b3c93df3832318fd0a3a56/detection"
      ],
      "total": 6
    },
    {
      "counts": {
        "domain": 3,
        "ipv4": 2
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "bootcampquest.com",
          "mail.bootcampquest.com",
          "tools.bootcampquest.com"
        ],
        "ipv4": [
          "194.110.246.254:443",
          "83.172.134.186:443"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/RedDrip7/status/1978366720432562372",
        "https://www.virustotal.com/gui/file/9b21e4b32e3e125bad638df76f25ca364a53cd50e324ab961a571a06b755a658/detection",
        "https://www.virustotal.com/gui/file/d6a533102f801066ddd6069e20f3a51e802852b72c6e105b6e1b8a2c035d0722/detection"
      ],
      "total": 5
    },
    {
      "counts": {
        "domain": 4
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "carlminiclub.com",
          "keeferbeautytrends.com",
          "microsoft365.sangellobrighthouse.com",
          "sangellobrighthouse.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/RedDrip7/status/1962415190051573781",
        "https://x.com/blackorbird/status/1981958007958524023",
        "https://www.virustotal.com/gui/file/1e7ce7c530a1cf4d74a356592f99bde2ca359ed4b4144f32cc69ab705f52e4e2/detection",
        "https://www.virustotal.com/gui/file/66eff3058760b478aa70b44b929ca59fec9c5b401e7a7d8f7af5b06f4c8aa398/detection",
        "https://www.virustotal.com/gui/file/b6bd48fa94fa15cdcbd6b24198472faeb0d79e7c41efb26da507be7c311b7bec/detection",
        "https://www.virustotal.com/gui/file/7b801221a024507ff948261bf5b635d93d1dc816d02f8255c495c6529a26cc4c/detection",
        "https://www.virustotal.com/gui/file/08674b806c13a1dab09645483021708e9eef6dd6d5fa7ece2955a096d68e9477/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 2
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "nsipsvc.com"
        ],
        "url_path": [
          "/edgevrisinze.php",
          "/imacnags/edgevrisinze.php"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/volrant136/status/1956393083949502767",
        "https://www.virustotal.com/gui/file/6f0bc10f8326b462e02cf97f4aac1ef87b8eee99ca364fada3948a21e585f359/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 2
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "inspurcloudservice.com"
        ],
        "ipv4": [
          "89.46.234.221:443",
          "89.46.234.221:9672"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/liqingjia1989/status/1930584300224676024",
        "https://www.virustotal.com/gui/file/a76f00ea65cf7fb9327e9b6d2d4acac61196feb30bd8fa164179ca81b9349c7e/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 3
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "florabrocuisine.com",
          "joelgardens.com",
          "oscarskatingcoach.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/RedDrip7/status/2004026276294938903",
        "https://www.virustotal.com/gui/file/974abd4dc03bd9dc1a5d7ae56d2882b5f69627c5af8f77a64fa880186b437007/detection",
        "https://www.virustotal.com/gui/file/8c95b0d740df0f91444d5ddb9107f3a41ac80c12c471c60c26e0a9513092464c/detection",
        "https://www.virustotal.com/gui/file/c93e0f954cfcfafbb07cc248fab3167eee51f9986304ed4afe0bf92965c83587/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "jgmfducservice.net"
        ],
        "url_path": [
          "/jmv/jmd.php?st="
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/suyog41/status/1924329354504634767",
        "https://www.virustotal.com/gui/file/d02fd3472adb0d7a502b08656c5001093a7a052905f406979873b464e9ca2378/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "large-file-download-in-progress-page-loading-iuwt6sk34bs6543df.tartaakademi.com",
          "tartaakademi.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/smica83/status/1983935993209069584",
        "https://tria.ge/251030-t3ev1s1khn/behavioral1",
        "https://www.virustotal.com/gui/ip-address/146.70.118.226/relations",
        "https://www.virustotal.com/gui/file/8b57d6b676afdd84786655eb5fc8769711ffefb9f4d2db7770a16c4ef9ae6592/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "url": 1,
        "url_path": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "url": [
          "http://196.251.84.150"
        ],
        "url_path": [
          "/v10.066/egrf.php"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/malwrhunterteam/status/1925086462120165852",
        "https://www.virustotal.com/gui/file/ea73818d5c96294381ea56af0bdda98a987704ee478d8ab374e53e2bafec892b/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "url": 1,
        "url_path": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "url": [
          "http://149.154.153.184"
        ],
        "url_path": [
          "/loccs.php?cn="
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/ginkgo_g/status/1897192606196703668",
        "https://www.virustotal.com/gui/file/8958b215f30f9d48010fb93363125dcaf265c18d3d8df04d299df8313fa6be5f/detection",
        "https://www.virustotal.com/gui/file/7847a287472f7e2b688bd5d000f43584007337e11359cc14d4c42d1f8d84efdb/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "pololiberty.com"
        ],
        "ipv4": [
          "185.237.166.24:56218"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/blackorbird/status/1958836180587307479",
        "https://mp.weixin.qq.com/s/ItcbKuoH0KjJjzSTG7YSrA",
        "https://www.virustotal.com/gui/file/a850a903b74c1d3d21c41e03761e8e64b43962269e7649940b10368a005bce20/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "diginurworld.com"
        ],
        "ipv4": [
          "151.236.21.48:8080"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/__0XYC__/status/1930552371530129610",
        "https://x.com/__0XYC__/status/1930552424353202399",
        "https://www.virustotal.com/gui/file/5bdbec839592af17a725c5705201d331848b12912a0889d2edad07fcc85f76b8/detection",
        "https://www.virustotal.com/gui/file/fbab7758765265a6988e78779cae2e12d093813217d09230136185d72f726c3c/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "url_path": 2
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "url_path": [
          "/cndrll.php",
          "/cndrll.php?er="
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1846000315566375184",
        "https://x.com/ginkgo_g/status/1933364194998694198",
        "https://www.virustotal.com/gui/file/ae8d252986c616884c10ab5082088cc9e413ddf5f9a0e292a1f2c5c0764c74e7/detection",
        "https://www.virustotal.com/gui/file/939f509a8edc6b9da103fbcebe85630671ed591dd9e40243da37559e10dcfd80/detection",
        "https://www.virustotal.com/gui/file/8af2d392181c359ce04e38ab113e22e526eae4c6f715d26462e439a3db1eb948/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "andrewswebstorage.com",
          "sanolegazy.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/RedDrip7/status/1998638735358128307",
        "https://www.virustotal.com/gui/file/1f262d5838e29f56eb190100f0753f2ae9c6a2b56954b0fef0f5481a2014fe00/detection",
        "https://www.virustotal.com/gui/file/1854e0e0a59a82e4d9629dd54a506eb442a4d71e0b8c9984b444cb9407a89f42/detection",
        "https://www.virustotal.com/gui/file/ffea43ead04d4bda567b1fd32ec68c8903ac7dbf9d63e001f804dbd0f717bbdf/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "hannahsgpsapp.com"
        ],
        "ipv4": [
          "185.117.72.87:10923"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/RedDrip7/status/1993874904710828150",
        "https://www.virustotal.com/gui/file/258918e48a7aaf393af89858f95af666d260c4035b63195f29c8ecfb3291ccb5/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "ipv4": 2
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "ipv4": [
          "151.236.14.173:443",
          "185.76.79.30:443"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/RedDrip7/status/1964874030869332252"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "ebeninstallsvc.com"
        ],
        "url_path": [
          "/uplh4ppy.php"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/AndreGironda/status/1955692280825962846",
        "https://blog.pulsedive.com/unpacking-kiwistealer-diving-into-bitter-apts-malware-for-file-exfiltration/",
        "https://app.any.run/tasks/a755b624-d146-4a49-acd5-c25e6b07aa3f"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "inizdesignstudio.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/wa1Ile/status/1925447893743542391",
        "https://www.virustotal.com/gui/file/64fd1e641731e48ea8c3df7b9caa5f8074dea15e99093b137af2acfe66754f73/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "oakcreekbakers.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/volrant136/status/1941557096933359638"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "goldenaturalinc.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/volrant136/status/1930659807440039970",
        "https://www.virustotal.com/gui/ip-address/69.61.36.186/relations"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "parcaredrive.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/volrant136/status/1924126261514833963"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "seragoonupdates.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/suyog41/status/1963171056044109898",
        "https://www.virustotal.com/gui/file/624decbc0445e51873436e42699323bf48093e0c4ba5ea1d348e9e5a1822579b/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "koliwooclients.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/suyog41/status/1952990924210094369",
        "https://www.virustotal.com/gui/file/121c3917e7b2e00d7c6e15f09370d21e2531e3dff27b177e69a10aa234a1bf37/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "ccltdcn.org"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/suyog41/status/1952709606297227414",
        "https://www.virustotal.com/gui/file/891ffe498debc7accfbdf9146adb6de6f2cfd8c083bb374fe8db073a4b106581/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "plymouthvibes.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/suyog41/status/1929855753206083762",
        "https://www.virustotal.com/gui/file/6763fadbfbcf125a73cc6388aba075f51caa2883a071178e438c7046dd92a1a5/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "princecleanit.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/suyog41/status/1922608403454583215",
        "https://www.virustotal.com/gui/file/31214e97722f99666dde6b09f386e71843895b0f3b4ebe373d7858f5dbec8ce2/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "stellacustomscreens.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/malwrhunterteam/status/2002470001924813279",
        "https://www.virustotal.com/gui/file/f692ba8fbe76ee5488fd81ad3ae6689744b7b8f9e35712cb6848bb7151f7bf1d/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "pawsandtailcare.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/malwrhunterteam/status/1994001214795862270",
        "https://www.virustotal.com/gui/file/09647fabb086acf09fdc72f3e8703c77c65e27fa52de14c9976389ef1bf4a843/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "ntplugnplay.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/malwrhunterteam/status/1923660512920744438",
        "https://www.virustotal.com/gui/file/243e4d1e53a805f61d2c4e8cabdd02e99a51fba37101b3e0535f219383871091/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "tapeqcqoptions.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/blackorbird/status/1986747686050287997",
        "https://mp.weixin.qq.com/s/CI1g4iaYxHhO925V15LvIQ",
        "https://www.virustotal.com/gui/file/93a905048ca8cdf7162ade1720d50883495bf1bbc000c828a6844a88a73a05db/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "ipv4": [
          "46.30.191.221:443"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/RedDrip7/status/2001489642072482032",
        "https://www.virustotal.com/gui/file/1fd8ba64a687247466fa6e8b7d194154439ef527746fdb8c18b3c3d65b6d2390/detection",
        "https://www.virustotal.com/gui/file/71fa6a00314701fef5c6f32c17e1438063d05616198ac9a12004aeab957e11ae/detection",
        "https://www.virustotal.com/gui/file/974626cf14864f0a3185233bbce417d37bf5c8ad6e3c82774985db027b54acd2/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "domain": [
          "glamormusicwave.com"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://x.com/RedDrip7/status/1952922656220823798",
        "https://www.virustotal.com/gui/file/389883cfa666855750974c540299de82f1ee8b51670b337e6cd86617f44817cc/detection",
        "https://www.virustotal.com/gui/file/886c36f4625f98537e8f2df5975aab643ad355e13e35023842a10129c0c46865/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "url_path": 1
      },
      "first_seen": "2026-01-02",
      "indicators": {
        "url_path": [
          "/cmpn/xing.php"
        ]
      },
      "precision": "at-or-before",
      "references": [
        "https://twitter.com/binlmmhc/status/1610969202722242561",
        "https://x.com/ShanHolo/status/1971249000985788673"
      ],
      "total": 1
    },
    {
      "counts": {
        "ipv4": 4,
        "url_path": 2
      },
      "first_seen": "2025-01-08",
      "indicators": {
        "ipv4": [
          "158.255.215.45:8899",
          "185.193.48.135:8676",
          "194.71.227.222:8855",
          "91.103.66.202:46882"
        ],
        "url_path": [
          "/anotherLife?credPart=",
          "/nina/anotherLife?credPart="
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/SethKingHi/status/1876845124488941942",
        "https://www.virustotal.com/gui/file/d94ff0edb28f7b90b9e4ab9ee94e8dcc33389538f15f536fa154b9506830c31f/detection",
        "https://www.virustotal.com/gui/file/b1efa4e3abadfab14aba6e36ed9f4105dc859f86968126de2e0ec792745c87d5/detection",
        "https://www.virustotal.com/gui/file/1126916c98b7801175375827fb5e8b8cee23e4bd920691ff7acd9a648ec13b67/detection"
      ],
      "total": 6
    },
    {
      "counts": {
        "url": 1
      },
      "first_seen": "2024-12-13",
      "indicators": {
        "url": [
          "http://72.18.215.1"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/banthisguy9349/status/1867179104899854616",
        "https://x.com/banthisguy9349/status/1867458625532506452",
        "https://www.virustotal.com/gui/file/acfb3223d5bcbcf96ee1265fdd510c124bfa3f1ae8670a7f7b48f46fc9895ee0/detection",
        "https://www.virustotal.com/gui/file/a152fa2e7368ed357a91214fdd91e1742541955f76c0d2bd936ec2d856bde38e/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "url": 1,
        "url_path": 2
      },
      "first_seen": "2024-12-07",
      "indicators": {
        "url": [
          "http://37.1.214.196"
        ],
        "url_path": [
          "/zserr.php",
          "/zserr.php?li="
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1865140931953070382",
        "https://x.com/mal_analysis136/status/1865323680344969262",
        "https://www.virustotal.com/gui/file/14ce282ffeaa5cc3d214acae33785795ae63021158305a7d6d305296539936d9/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-12-05",
      "indicators": {
        "domain": [
          "grounpackcluepik.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1864408026658041888",
        "https://www.virustotal.com/gui/file/65419a704f252f8c3574d90cf016b6bfdd70b63f65dbc5b57d44a3a6ef457f80/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2024-12-04",
      "indicators": {
        "domain": [
          "jacknwoods.com",
          "premierinvestmentfund.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/suyog41/status/1864199979369447473",
        "https://x.com/mal_analysis136/status/1864285903058809266",
        "https://www.virustotal.com/gui/ip-address/185.244.151.84/relations",
        "https://www.virustotal.com/gui/file/cb4a280f54c56d250c98124a88e80c46ccd82cb77ff0951f150f01e02791ca30/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "url": 2
      },
      "first_seen": "2024-11-28",
      "indicators": {
        "url": [
          "http://159.100.30.103",
          "http://173.254.204.72"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/1862131045883408582",
        "https://www.virustotal.com/gui/file/e44d034ceb135990452fce74d358bdf7841316fdcb6db1172e6e5e3e07ffa4bd/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2024-11-26",
      "indicators": {
        "domain": [
          "siasat.top"
        ],
        "url_path": [
          "/xyzxyzhanoiwhb3237gb2wahabjiki/"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1861383328521207980",
        "https://x.com/mal_analysis136/status/1863537157119299620",
        "https://www.virustotal.com/gui/file/b3b2d915f47aa631cc4900ec56f9b833e84d20e850d78f42f78ad80eb362b8fc/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-11-20",
      "indicators": {
        "domain": [
          "updateschedulers.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/1859161598469836806",
        "https://blogs.blackberry.com/en/2024/11/suspected-nation-state-adversary-targets-pakistan-navy-in-cyber-espionage-campaign",
        "https://www.virustotal.com/gui/collection/f6f862c588961ae94c5c23d92331b85e5023ed7064c00d1299f73d47aadf699d/iocs",
        "https://www.virustotal.com/gui/file/fc39ec35d767a2c0a178ca9874be8aaf87033f8b834ee8dcb57d3904516e4335/detection",
        "https://www.virustotal.com/gui/file/a0a18e76d8af39b9b198d9ea7c67dc372fa3cdb2286ac405fa8e76154af34fff/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 4
      },
      "first_seen": "2024-11-19",
      "indicators": {
        "domain": [
          "dappscryp.com",
          "ghayoorfilmstudio.com",
          "haileemecacademy.com",
          "zensparkagent.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/1858873110625243398"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-11-18",
      "indicators": {
        "domain": [
          "abelewebconnect.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/wa1Ile/status/1858421539286168058",
        "https://www.virustotal.com/gui/file/c00570eb0b47614b7286cf945b212774dde69572aa4d9bf273438921fb1cb557/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 2
      },
      "first_seen": "2024-11-12",
      "indicators": {
        "domain": [
          "federalrevenueboard.com"
        ],
        "ipv4": [
          "162.252.175.131:6969",
          "91.132.92.231:9314"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1856371787145130399/history",
        "https://medium.com/@knownsec404team/unveiling-the-past-and-present-of-apt-k-47-weapon-asyncshell-5a98f75c2d68",
        "https://www.virustotal.com/gui/file/52362a3bf05d0f65c49d527bfecec76472502ec0fbd9ebac96c832c8af362385/detection",
        "https://www.virustotal.com/gui/file/4e32e86f1feeaecc03f7f9d4734a41dffe98893fccd1ff2004029c708c160e20/detection",
        "https://www.virustotal.com/gui/file/cb7e6640ab5c1dad5083e5790d6009c317894406b970d42a34758e99a9ff7f94/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2024-11-12",
      "indicators": {
        "domain": [
          "laboratoreventsvc.com",
          "procarcaresvc.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/1856340219328639441",
        "https://www.virustotal.com/gui/file/08d12b65525d05e6c4e2d308a1e1edc1329ac29d39cf71b1ce883b03ace7d406/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "ipv4": 1,
        "url": 1
      },
      "first_seen": "2024-11-07",
      "indicators": {
        "ipv4": [
          "95.169.180.122:443"
        ],
        "url": [
          "http://95.169.180.122"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/1854529596156182765",
        "https://www.virustotal.com/gui/file/fd2f4f23bb4d42a0d758d56ccb04a133301b21320a7cc346367db04965aea0c7/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2024-11-01",
      "indicators": {
        "domain": [
          "wusvcpsvc.com"
        ],
        "ipv4": [
          "45.56.165.121:46346"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/1852178923695804654",
        "https://www.virustotal.com/gui/file/2544d79e47c01c9714264550b9e31151f66a9384d6aca33ee83cdfa8649dbb46/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2024-10-29",
      "indicators": {
        "domain": [
          "iboxencentrum.com"
        ],
        "url_path": [
          "/lux.php?cv="
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1851227466259443931",
        "https://www.virustotal.com/gui/file/2b0f8c6261b4e9e97732efadad14fcb66872474f092f8c7fd69b941cd4796912/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2024-10-28",
      "indicators": {
        "ipv4": [
          "192.71.249.194:443"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/ginkgo_g/status/1850821079260094731",
        "https://www.virustotal.com/gui/file/d28df7a8a275f628660e2f2744bfa36bc5b5c7ae1a8d3a63fbfefa79f04b805e/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2,
        "url": 1
      },
      "first_seen": "2024-10-26",
      "indicators": {
        "domain": [
          "fizzillacottages.com",
          "ottawadesignlab.com"
        ],
        "url": [
          "http://47.245.111.83"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/1850060334079610936",
        "https://mp.weixin.qq.com/s/kkl0jh14M9DtDGtSGQ4gag"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 5
      },
      "first_seen": "2024-10-16",
      "indicators": {
        "domain": [
          "ns2.easyiplookup.com"
        ],
        "ipv4": [
          "151.236.9.75:6396",
          "162.252.172.67:443",
          "162.252.175.131:8246",
          "46.183.187.42:443",
          "91.132.92.231:5959"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/1846487125249970293",
        "https://mp.weixin.qq.com/s/tkOMIHY36TujPKjWKVa6kA",
        "https://www.virustotal.com/gui/ip-address/192.71.249.194/relations"
      ],
      "total": 6
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2024-10-16",
      "indicators": {
        "ipv4": [
          "46.183.186.208:6060"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/1846487125249970293",
        "https://mp.weixin.qq.com/s/tkOMIHY36TujPKjWKVa6kA",
        "https://www.virustotal.com/gui/ip-address/192.71.249.194/relations",
        "https://x.com/StrikeReadyLabs/status/1856371787145130399/history",
        "https://medium.com/@knownsec404team/unveiling-the-past-and-present-of-apt-k-47-weapon-asyncshell-5a98f75c2d68",
        "https://www.virustotal.com/gui/file/52362a3bf05d0f65c49d527bfecec76472502ec0fbd9ebac96c832c8af362385/detection",
        "https://www.virustotal.com/gui/file/4e32e86f1feeaecc03f7f9d4734a41dffe98893fccd1ff2004029c708c160e20/detection",
        "https://www.virustotal.com/gui/file/cb7e6640ab5c1dad5083e5790d6009c317894406b970d42a34758e99a9ff7f94/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 2
      },
      "first_seen": "2024-10-15",
      "indicators": {
        "domain": [
          "inhostnetservice.com"
        ],
        "url_path": [
          "/mscu/lokc.php",
          "/mscu/lokc.php?wl="
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1846000315566375184",
        "https://x.com/ginkgo_g/status/1933364194998694198",
        "https://www.virustotal.com/gui/file/ae8d252986c616884c10ab5082088cc9e413ddf5f9a0e292a1f2c5c0764c74e7/detection",
        "https://www.virustotal.com/gui/file/939f509a8edc6b9da103fbcebe85630671ed591dd9e40243da37559e10dcfd80/detection",
        "https://www.virustotal.com/gui/file/8af2d392181c359ce04e38ab113e22e526eae4c6f715d26462e439a3db1eb948/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2024-10-15",
      "indicators": {
        "domain": [
          "miyamassagenklinik.com",
          "narinesonlinelibrary.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/mal_analysis136/status/1846049340328198352"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 6,
        "ipv4": 2
      },
      "first_seen": "2024-10-12",
      "indicators": {
        "domain": [
          "locklearhealthapp.com",
          "mail.wmiapcservice.com",
          "maxnursesolutions.com",
          "nurekleindesign.com",
          "samsnewlooker.com",
          "wmiapcservice.com"
        ],
        "ipv4": [
          "185.106.123.198:40269",
          "96.9.215.155:56172"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/blackorbird/status/1845000997665755151",
        "https://mp.weixin.qq.com/s/eseliIVHqiWI-Q1CoCA81g",
        "https://www.virustotal.com/gui/file/8b7f36b3af85639ea0fcdd35eda43e64ac59d034ebd43a884601ef6ae29bb71e/detection",
        "https://www.virustotal.com/gui/file/df5c0d787de9cc7dceeec3e34575220d831b5c8aeef2209bcd81f58c8b3c08ed/detection"
      ],
      "total": 8
    },
    {
      "counts": {
        "domain": 3,
        "ipv4": 1
      },
      "first_seen": "2024-10-12",
      "indicators": {
        "domain": [
          "lsamapkitlaunch.com",
          "nashmediawave.com",
          "ns1.nashmediawave.com"
        ],
        "ipv4": [
          "5.135.43.181:35598"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/ba2853547fe79f52461323295f9bc528f3689cfa1882ddc549dfac76fa9e2498/detection",
        "https://www.virustotal.com/gui/file/afaaa7d065ad7267dfbd2b69cd0d0eee7af5e4416bdc27d5de3f7640695bc809/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-10-12",
      "indicators": {
        "domain": [
          "microworldus.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/c44d142a4cf541afcc4b5fc6612c7db8d49a147332e027c45c7b15aa32489421/detection",
        "https://www.virustotal.com/gui/file/3d529596440dfc64a7db106ddb77ec65fb88d48d6e30e7760e67b50905165ae7/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2,
        "ipv4": 2,
        "url": 1
      },
      "first_seen": "2024-09-26",
      "indicators": {
        "domain": [
          "easyiplookup.com",
          "gewistaplaner.gewista.at"
        ],
        "ipv4": [
          "151.236.9.75:5080",
          "91.132.92.231:6060"
        ],
        "url": [
          "http://151.236.9.75"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1839037780644471181",
        "https://x.com/silentpush_labs/status/1839077173141094605",
        "https://www.virustotal.com/gui/file/294323c2611edeb7bae0ff3993ac48eed50c16abe04ff6afbf735b16cf8bcd10/detection",
        "https://www.virustotal.com/gui/file/303bc4bce9555b02d9b1c0b96eb5736561d70fca3b994b353db2cc1b2eca66ca/detection"
      ],
      "total": 5
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2024-09-25",
      "indicators": {
        "domain": [
          "apifilestore.net",
          "winfreecloud.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1839037780644471181",
        "https://x.com/silentpush_labs/status/1839077173141094605",
        "https://www.virustotal.com/gui/file/294323c2611edeb7bae0ff3993ac48eed50c16abe04ff6afbf735b16cf8bcd10/detection",
        "https://www.virustotal.com/gui/file/303bc4bce9555b02d9b1c0b96eb5736561d70fca3b994b353db2cc1b2eca66ca/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-09-21",
      "indicators": {
        "domain": [
          "elevateecom.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/suyog41/status/1837073539121434966",
        "https://x.com/StrikeReadyLabs/status/1837317218943525321",
        "https://www.virustotal.com/gui/file/507aa944d77806b3f24a3337729b52168808e8d469e5253cbf889cdaabb5254e/detection",
        "https://www.virustotal.com/gui/file/c1f27bed733c5bcf76d2e37e1f905d6c4e7abaeb0ea8975fca2d300c19c5e84f/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-09-20",
      "indicators": {
        "domain": [
          "vanessalove.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/suyog41/status/1837073539121434966",
        "https://x.com/StrikeReadyLabs/status/1837317218943525321",
        "https://www.virustotal.com/gui/file/507aa944d77806b3f24a3337729b52168808e8d469e5253cbf889cdaabb5254e/detection",
        "https://www.virustotal.com/gui/file/c1f27bed733c5bcf76d2e37e1f905d6c4e7abaeb0ea8975fca2d300c19c5e84f/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-09-17",
      "indicators": {
        "domain": [
          "healthtipsart.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/k3yp0d/status/1836001049976422810",
        "https://www.virustotal.com/gui/ip-address/104.200.73.57/relations"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2,
        "ipv4": 1
      },
      "first_seen": "2024-09-16",
      "indicators": {
        "domain": [
          "jetmains.com",
          "sharesmydrive.com"
        ],
        "ipv4": [
          "65.20.105.88:8082"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1835445587149562137",
        "https://www.virustotal.com/gui/file/81afc6d8e369ba8f08753541c78db4c424703e59a23d5d3bfbc46bc359c7336a/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2024-09-16",
      "indicators": {
        "ipv4": [
          "95.156.206.105:443"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1834599289391108556",
        "https://www.virustotal.com/gui/file/67c0ad5ab6be8efec70a53cc56a03b581c7712eee7310ec5a8afba583c2b75bb/detection",
        "https://www.virustotal.com/gui/file/5de9131252e6bc5a336516b9de4d7e0e0e2e3cde38ace85dbda39a3a166eb1a5/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 8
      },
      "first_seen": "2024-09-13",
      "indicators": {
        "domain": [
          "affinitycapitalgp.com",
          "affinitycapitalgr.com",
          "gdatesystems.com",
          "idbcxnetmac.com",
          "jmsatozplanning.com",
          "mcxntoolsservice.com",
          "sporcketngearforu.com",
          "surininfiniumclub.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1834609928285110285",
        "https://www.virustotal.com/gui/ip-address/69.61.36.170/relations"
      ],
      "total": 8
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2024-09-13",
      "indicators": {
        "domain": [
          "benclickstudio.com"
        ],
        "url_path": [
          "/shrd.php?vo="
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/liqingjia1989/status/1834427464837464131",
        "https://www.virustotal.com/gui/file/575b783b3bd38271450a2c2cc8fb3ad0dc5ba69e044ad9aa0684851a3426cc06/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-09-10",
      "indicators": {
        "domain": [
          "andbouncersclub.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/liqingjia1989/status/1833410135005483214",
        "https://www.virustotal.com/gui/file/0db680ad035e30a4d17716538ab56af73492c722480da1ff683b550dbacf45bd/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-09-06",
      "indicators": {
        "domain": [
          "aadresourcing.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/liqingjia1989/status/1831906877841797172",
        "https://www.virustotal.com/gui/file/dea912dce66c32598ec2d0a24b9e0b5f690b3ed714b978578048bc8b28b2ed02/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-09-05",
      "indicators": {
        "domain": [
          "mnemautoregsvc.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/mal_analysis136/status/1831562638104703371"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-09-05",
      "indicators": {
        "domain": [
          "glamorcliniques.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1831506911839080873",
        "https://www.virustotal.com/gui/file/8f5f92e4d901eccf63e76223cacce47a29cdd533fb513d08abc7f659a8869382/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-09-04",
      "indicators": {
        "domain": [
          "onlinewebdebugsvc.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/suyog41/status/1831196846615633926",
        "https://www.virustotal.com/gui/file/83e64fc374eff67e66b476d32bfd3455840da66c618a0381822d23ef872fe5f2/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-08-22",
      "indicators": {
        "domain": [
          "devflowservice.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/mal_analysis136/status/1826491897910886675"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 2
      },
      "first_seen": "2024-08-17",
      "indicators": {
        "domain": [
          "mcdavezonepanel.com"
        ],
        "url_path": [
          "/mloknj.php",
          "/mloknj.php?cv="
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1824790667765190793",
        "https://www.virustotal.com/gui/file/2c5a14edacc03a57458d82607067207911b0b92003641e0b973d90630483d4ce/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-08-17",
      "indicators": {
        "domain": [
          "mxuconlinegame.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/ShadowChasing1/status/1824630406823678214",
        "https://www.virustotal.com/gui/file/11dff82741190cdb7934fd996796ad8b9e564ebc7e903036824acba99fb7d6af/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2024-08-15",
      "indicators": {
        "domain": [
          "kimfilippovision.com",
          "windowphotoviewer.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://strikeready.com/blog/open-sesame/",
        "https://www.virustotal.com/gui/ip-address/172.86.68.175/relations",
        "https://www.virustotal.com/gui/file/15337ad45a65f8f9eae57f76d6cff314968417665750f336c6154a2c05991582/detection",
        "https://www.virustotal.com/gui/file/ba352569428df4618cd57f91bd3479b73a798399a6b861ed996d715bc51e916c/detection",
        "https://www.virustotal.com/gui/file/ee088e6d8ac0f3dbfbd17f556a58d06cc882016fd8a4a8ba2ddcd0cab5322d23/detection",
        "https://www.virustotal.com/gui/file/52a4020392de0d527fe0aaf551fa557628c68419415b86afa36854d0bc987d9d/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-08-14",
      "indicators": {
        "domain": [
          "vizylstatpro.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/wa1Ile/status/1823643124562022487",
        "https://www.virustotal.com/gui/file/4c556d9e902c8cc0096bb56447075834f19ea456f5871e08a948da4bb3192db8/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "url": 1
      },
      "first_seen": "2024-08-14",
      "indicators": {
        "url": [
          "http://94.156.175.95"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/k3yp0d/status/1823652687029698699",
        "https://www.virustotal.com/gui/file/42ab740ff15988b4f919b31a6203fb40f9470d281791f0d7c96eb80586d6b2eb/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-08-11",
      "indicators": {
        "domain": [
          "gocartwillium.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1822458511940264187",
        "https://www.virustotal.com/gui/file/e1aff2618bad2418023730bab3e2e119fb9682dafac5078456800cc98f2178e0/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2024-08-06",
      "indicators": {
        "domain": [
          "bickrickneoservice.com",
          "pdcunaco.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/suyog41/status/1820766059814953246",
        "https://x.com/StrikeReadyLabs/status/1820787452174368831",
        "https://www.virustotal.com/gui/file/a1bb8ce0cf7290524326442be9b8ecce883d860f6437dcc4bc64b99f72004fdd/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 2,
        "ipv4": 1,
        "url": 1
      },
      "first_seen": "2024-07-30",
      "indicators": {
        "domain": [
          "cloudaff.net",
          "turkeyapi.bio"
        ],
        "ipv4": [
          "65.20.103.184:8080"
        ],
        "url": [
          "http://45.61.139.69"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/karol_paciorek/status/1818204812564938798",
        "https://www.virustotal.com/gui/file/28cb51c171d591b2bb35bc9a4379010fd37f66cfcd317a67cb73b24262dc17c6/detection",
        "https://www.virustotal.com/gui/file/833501101c1af641e9910389596e79f672dc721f57936e0f23898fa748f3b71b/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2024-07-22",
      "indicators": {
        "domain": [
          "mindgamecenter.com"
        ],
        "ipv4": [
          "193.29.58.210:15192"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/wa1Ile/status/1814284608269353136",
        "https://www.virustotal.com/gui/file/96f74896774ad4877740378d216afde6cdc962729b2ff8b9a56393ad14ea7f58/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-07-22",
      "indicators": {
        "domain": [
          "lezziezgrillcorner.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/wa1Ile/status/1795747139601195042",
        "https://www.virustotal.com/gui/file/ffee624870767c528c9d7578833483a496279508e665c5d24f6b9445490cda27/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-07-17",
      "indicators": {
        "domain": [
          "littlehipsononline.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/suyog41/status/1813453691019571279",
        "https://www.virustotal.com/gui/file/8f03eb3fe7363bb7ab291c86680a71ad2820527ffbf067103f0c8909956c059e/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2024-07-12",
      "indicators": {
        "domain": [
          "gorgxwebset.com"
        ],
        "ipv4": [
          "46.30.190.137:51620"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/liqingjia1989/status/1811658282366271537",
        "https://www.virustotal.com/gui/file/c2e492da957ef5c76b3cc8890007c4f419ec510b5f9f259c2a0161c032ebc987/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-07-10",
      "indicators": {
        "domain": [
          "mxmediasolutions.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1811034367856161254",
        "https://www.virustotal.com/gui/file/1dd50966db005e30f7a69b6d16dfe8b9810dba3cdbe43bebb136f8786d027ed1/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-07-03",
      "indicators": {
        "domain": [
          "shioyuilubiz.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/suyog41/status/1808379399953146053",
        "https://www.virustotal.com/gui/file/8c4416b735826bd35707b9caad356292c82a574e5d85a5ce6e013754352d9098/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-07-03",
      "indicators": {
        "domain": [
          "bakuackermannfashions.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/StrikeReadyLabs/status/1808457407632224733",
        "https://www.virustotal.com/gui/file/86c4e9a4615836c6fc7c44f458a3fa784fe347f23b062b08ec22999cda15b2a9/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-07-03",
      "indicators": {
        "domain": [
          "fusionjunction.link"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/309740ee31eff70c8510340293cc45b135c4791a8a7c70e8a12ea6b4f1217ff5/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-06-05",
      "indicators": {
        "domain": [
          "viyoappmapper.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/liqingjia1989/status/1798160822134546655",
        "https://www.virustotal.com/gui/file/7ca837a4e410b57e0c54bb6fb3a7ef756b0913a77339e5d11c5e9371c3ee64b2/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-05-28",
      "indicators": {
        "domain": [
          "giov.officeweb.live"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/liqingjia1989/status/1795276257627877723",
        "https://www.virustotal.com/gui/file/c8b93075675b6b90cc5a2f58bdd1c52088a511485efd2f9bb6de54c9736e98e5/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2024-05-27",
      "indicators": {
        "domain": [
          "manderikgamezilla.com"
        ],
        "ipv4": [
          "46.183.25.24:52546"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/liqingjia1989/status/1795058403540173275",
        "https://www.virustotal.com/gui/file/bc764b4af4edeaf94920c75c7956b8bb6f7315071c3781d61c029f235cb62d96/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-05-27",
      "indicators": {
        "domain": [
          "mariasunistyle.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/RedDrip7/status/1794979757559599555",
        "https://www.virustotal.com/gui/file/0b230b83c0b4af6e13ad837c35121d0827f5a243855a5d8a80e299b9c91ad5ae/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 13
      },
      "first_seen": "2024-05-22",
      "indicators": {
        "domain": [
          "55five.lol",
          "888toto.com",
          "8toto.co",
          "918slot.top",
          "99togel.org",
          "99toto.shop",
          "aduhoki88.com",
          "bulltrader.vip",
          "efgchartered.co.uk",
          "kertasiusaus.com",
          "maxcavelli.com",
          "plugins-support.com",
          "test.bulltrader.vip"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/mal_analysis136/status/1793123437680210067",
        "https://app.validin.com/detail?type=dom&find=aduhoki88.com#tab=host_pairs_v2"
      ],
      "total": 13
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-05-20",
      "indicators": {
        "domain": [
          "goalvaidclub.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/alex_lanstein/status/1792638726931161109",
        "https://www.virustotal.com/gui/file/482e4f64e1aa9096bed00dbe0cc6451441c0f0d0bf5a9d33e3011057f4bed9c5/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-05-08",
      "indicators": {
        "domain": [
          "yalinasculetips.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1788123283931717847",
        "https://www.virustotal.com/gui/file/f95167754f162097b83495baa070d3a0036b335a22c6d584300dd94b45988780/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2024-05-07",
      "indicators": {
        "domain": [
          "smartclouddirect.com"
        ],
        "ipv4": [
          "167.88.15.93:61920"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1787752297461846466",
        "https://www.virustotal.com/gui/file/667e411ec65acc61eea0be0dbae8a4ffde8529e905c780cd35f71ef9ebc0a0bf/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2024-05-02",
      "indicators": {
        "ipv4": [
          "47.94.19.69:8080"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1785925227337375766",
        "https://www.virustotal.com/gui/file/30f9676fb31a2ee5c4d5ec9e3809422cad8efcc7f409d4e5ba96d3229e42ae61/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-04-29",
      "indicators": {
        "domain": [
          "johnfashionaccess.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1784846105416708314",
        "https://www.virustotal.com/gui/file/53e9d201163cd5fc1adf3974afb41c6a31496737bdbbefec3be7205d63a3780e/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-04-29",
      "indicators": {
        "domain": [
          "colorsofnether.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/alex_lanstein/status/1785026144246325630",
        "https://www.virustotal.com/gui/ip-address/93.123.73.160/relations"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 4
      },
      "first_seen": "2024-04-28",
      "indicators": {
        "domain": [
          "libraofficeonline.com",
          "officeweb.live",
          "outlook-web.ddns.net",
          "outlook.officeweb.live"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ginkgo_g/status/1784505204391739493",
        "https://www.virustotal.com/gui/file/ba2e21641a1238a5b30e535bd0940fcd316a6e5242bfdd48a97aaa203d11642b/detection",
        "https://www.virustotal.com/gui/file/6cdc79edba95c6a9ec1d50457dc16f40f02c46a7d0b9665f099abe8155d1a25c/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2024-04-28",
      "indicators": {
        "domain": [
          "microsoft.officeweb.live"
        ],
        "ipv4": [
          "141.94.68.169:443"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/85a6ac13510983b3a29ccb2527679d91c86c1f91fdfee68913bc5d3d01eeda2b/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-04-25",
      "indicators": {
        "domain": [
          "oraclewebonline.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ginkgo_g/status/1783386949765718155",
        "https://www.virustotal.com/gui/file/dcdae583da8a1b01a8ad0caef6a7f6f3b6f1eb6dd3298ac7d904200f52712446/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-04-09",
      "indicators": {
        "domain": [
          "evtessentials.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1777622247936491681",
        "https://www.virustotal.com/gui/file/9fcae6572e9d474e131e64b639becf0bbaea7297edd451459f069fb20742b1f2/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-04-07",
      "indicators": {
        "domain": [
          "bsdqcaptureman.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1776779248524755435",
        "https://www.virustotal.com/gui/file/4dfe81aeb881c9e7cf0a469542d3908df9d7c5bc87c8fe1061254d77a53cb1d3/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-03-21",
      "indicators": {
        "domain": [
          "libraofficeweb.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/__0XYC__/status/1770689612031164671",
        "https://www.virustotal.com/gui/file/7525cecb3d45097db48ee08410ba2b2ae1f9db84f887098557b09e7f8fa79a81/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-03-07",
      "indicators": {
        "domain": [
          "bartelemarks.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/JVPv5sIM3eFmGyi/status/1765651279093612644"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-03-06",
      "indicators": {
        "domain": [
          "whitelilyshop.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1765296640028774450",
        "https://www.virustotal.com/gui/file/8b79f6b2061e3231da4ef75799ad9754d64c336ce34fbc9a4538b0b3020fff8a/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-03-05",
      "indicators": {
        "domain": [
          "clairsvanieclub.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/h2jazi/status/1765117935469658451",
        "https://www.virustotal.com/gui/file/c0120c1f458497602ae3068e7e755d5056f7a0b2c28c9e6ba9a3bfe12b27ad56/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-03-05",
      "indicators": {
        "domain": [
          "demolaservices.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/alex_lanstein/status/1765088371108639175",
        "https://www.virustotal.com/gui/file/414d6ed63baaaa69a555068e91e1ee89dbcf38cac7ac4918f6e50fb82d039485/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "url_path": 1
      },
      "first_seen": "2024-03-05",
      "indicators": {
        "url_path": [
          "/wmis/wave.php?xas="
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/RedDrip7/status/1613474917038837764",
        "https://www.virustotal.com/gui/file/5b90d4c397e575965ed49082981fd34272b5e1da010057f6ebcdd4f53a409ad0/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2024-02-21",
      "indicators": {
        "domain": [
          "kaatmusiclab.com"
        ],
        "ipv4": [
          "91.192.81.102:22981"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1760112384071606393",
        "https://www.virustotal.com/gui/file/c0d926b33ae2351a9a528ba4d7ca13be7d55ba3455d52c5a69c8b381ade28ed0/detection",
        "https://www.virustotal.com/gui/file/f2f783a72e955ecbcddc448764921a753bd1ac4dd14128200bb4866021287ae7/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2024-02-02",
      "indicators": {
        "domain": [
          "northgenstudios.com"
        ],
        "url_path": [
          "/ML/vbn.php?pi="
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ginkgo_g/status/1753259443675156855",
        "https://www.virustotal.com/gui/file/876122fcc9e0d5ebd42df9e93d37ad23d9f521e6077e9cb8b05862ae157757e3/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2024-01-15",
      "indicators": {
        "domain": [
          "upulllogistics.com"
        ],
        "url_path": [
          "/wipe/ret.php?eer="
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ginkgo_g/status/1746827915306909954"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2024-01-12",
      "indicators": {
        "domain": [
          "hallanskylarks.com"
        ],
        "ipv4": [
          "135.125.242.211:52112"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1745729324349825131",
        "https://www.virustotal.com/gui/ip-address/135.125.242.211/relations",
        "https://www.virustotal.com/gui/file/c492bdf749b0a229cb256e1ee04e1c48b7472a351f04605415c11d40063cd14a/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2024-01-08",
      "indicators": {
        "domain": [
          "alfiehealtcareservice.com",
          "nesiallservice.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/RexorVc0/status/1744276666782716098",
        "https://mp.weixin.qq.com/s/0iiCwpxNnd8akoT8RjU84A?ref=www.ctfiot.com"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2024-01-05",
      "indicators": {
        "domain": [
          "gotiktikweb.com"
        ],
        "ipv4": [
          "185.117.73.209:49725"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1743080624196661436",
        "https://www.virustotal.com/gui/file/89e609cc48e0926b8121ed943bf9561d0ed0ac682d811618d56d0602ccca847c/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 2
      },
      "first_seen": "2024-01-04",
      "indicators": {
        "domain": [
          "adamsresearchshare.com"
        ],
        "url_path": [
          "/textcmd/cmd1.php",
          "/textcmd/text.php?id1="
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/malwrhunterteam/status/1742941632922624097",
        "https://www.virustotal.com/gui/file/15161231be575991c70252cc33cdd2c41b5c3b255d6510790bef32be9b6ff5a2/detection",
        "https://www.virustotal.com/gui/file/408292710999abc4d37f23a6672ef407d70ffb4dc2e3e030a5ec705735c1f8bd/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2024-01-02",
      "indicators": {
        "domain": [
          "lcpcstudiover.com"
        ],
        "ipv4": [
          "46.249.38.18:52993"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1742010387481121156",
        "https://www.virustotal.com/gui/file/f6afa3080c4f69eaaeb4d43c723672031b4a5b7130b1db8361786180e6bba380/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2023-12-20",
      "indicators": {
        "domain": [
          "mikeyourevents.com"
        ],
        "url_path": [
          "/CP/tre.php?pi="
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1737375533250511276",
        "https://www.virustotal.com/gui/file/c77ae7c9533eddbb5f2b80889590436aac7df6166abefc51d5a65f775e6258dc/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 2
      },
      "first_seen": "2023-12-14",
      "indicators": {
        "domain": [
          "jjwappconsole.com"
        ],
        "ipv4": [
          "23.254.128.22:22812",
          "51.178.206.76:22812"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1656105672365477888",
        "https://www.virustotal.com/gui/file/c24efc7c4dafd4f0b39e7ae7e84627fbd0fb766019b820cb11edbb8dda54de66/detection",
        "https://www.virustotal.com/gui/file/66a73b1b3b51a1c6a56db2d20cff9af3d1362b989989b5d9543d2e9b92ac9a3d/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2023-12-14",
      "indicators": {
        "domain": [
          "dtzappaccount.com"
        ],
        "ipv4": [
          "45.66.248.66:59142"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1724011550825136526",
        "https://www.virustotal.com/gui/file/fc9f84bad598c057b595efbca7ae0ae9a1678de7f2185275953424b3ec47a00e/detection",
        "https://www.virustotal.com/gui/file/813c67414723ea162e789b1fc4b269839351863050f27a2f906426dac3a86f39/detection",
        "https://www.virustotal.com/gui/file/14e43110cc3c40bf56d95df0079cc744055b1568dbceac05b50a2c0159bef872/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2023-12-14",
      "indicators": {
        "domain": [
          "umsmssvc.com"
        ],
        "ipv4": [
          "95.174.71.139:39006"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1706835231536525805",
        "https://www.virustotal.com/gui/file/20bf58300532c55c46c19ff9c634bd8f3d48c577b1d8414cb6d4d2fbb1716087/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2023-12-14",
      "indicators": {
        "ipv4": [
          "91.236.230.54:46056"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1694531703505813618",
        "https://www.virustotal.com/gui/file/4664dc63b2faaa69ee7440980da0b9894a5267f06cfe3948b0f762196c0b50b7/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-12-14",
      "indicators": {
        "domain": [
          "alfiehealthcareservice.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1672787159424835585",
        "https://twitter.com/liqingjia1989/status/1672792060007714816"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2023-12-12",
      "indicators": {
        "domain": [
          "loganwcshost.com"
        ],
        "ipv4": [
          "46.249.38.18:41426"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/liqingjia1989/status/1734459198245867732",
        "https://www.virustotal.com/gui/file/ab26ffe31e0c6b247781b20eba4f405ade35ebe6d87d49e7780a65ea7bd870dc/detection",
        "https://www.virustotal.com/gui/file/be6be16175f523214ce49f765245ea38b4c5ecb24b15d08180232df0eb728e23/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2023-12-07",
      "indicators": {
        "domain": [
          "lroliviapanel.com"
        ],
        "url_path": [
          "/frst.php?ys="
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1732637340299104556",
        "https://www.virustotal.com/gui/file/22dd82c94cadf5cf31b3e9519e8149d4a68fe13bac13eaef91bf283a4beb8101/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-12-04",
      "indicators": {
        "domain": [
          "paulalesiastyles.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1731632299618525471",
        "https://www.virustotal.com/gui/file/62e42d3e778fd79b7989966b057c24c141531f871a7c73703b35858ab3d13f47/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2023-11-30",
      "indicators": {
        "domain": [
          "newlbfashions.com"
        ],
        "url_path": [
          "/kna.php?ka="
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1730172467094983083",
        "https://www.virustotal.com/gui/file/83ca53918af3ea659d767e489a1e42ea97879e3e534f68c4edc7d0eb77f44204/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2023-11-30",
      "indicators": {
        "domain": [
          "maxdimservice.com"
        ],
        "ipv4": [
          "89.40.206.85:52529"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ginkgo_g/status/1729698368987787591",
        "https://www.virustotal.com/gui/file/132098213b5923463611e6fc77bfce0cfad3d727566ce0e87e9723456c698ae6/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-11-29",
      "indicators": {
        "domain": [
          "newsaxfluteclub.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/JVPv5sIM3eFmGyi/status/1729760374960927051",
        "https://twitter.com/doc_guard/status/1729861690613989781",
        "https://app.docguard.io/fc72bd3e21cddcb3c181d7bdf1cacd2886701cdf9cc12be63061c2eeeda47ce9/results/dashboard",
        "https://www.virustotal.com/gui/file/fc72bd3e21cddcb3c181d7bdf1cacd2886701cdf9cc12be63061c2eeeda47ce9/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 4,
        "ipv4": 1
      },
      "first_seen": "2023-11-22",
      "indicators": {
        "domain": [
          "cjcjegb9k5vg46vkns5g.sportsaccessstore.com",
          "gspcfdqtloe.sportsaccessstore.com",
          "olivershikerhelp.com",
          "sportsaccessstore.com"
        ],
        "ipv4": [
          "91.236.230.44:59310"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/RexorVc0/status/1727230322855833657",
        "https://mp.weixin.qq.com/s/HVhXyIB4sKuG6dDwwe4Pcw",
        "https://www.virustotal.com/gui/ip-address/91.236.230.44/relations",
        "https://www.virustotal.com/gui/file/2b25469b0e23fc024f5ca147948292cd4175a18625cb8a5b67ab04300082866f/detection"
      ],
      "total": 5
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 2
      },
      "first_seen": "2023-11-10",
      "indicators": {
        "domain": [
          "farlookclinic.com"
        ],
        "url_path": [
          "/DMMA/hfo.php",
          "/DMMA/hfo.php?pi="
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/StopMalvertisin/status/1722944218015179147",
        "https://www.virustotal.com/gui/file/445c801e857329e1740745b4949349a02971530c4f5d28a8e9e5489c3516933a/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 2
      },
      "first_seen": "2023-10-25",
      "indicators": {
        "domain": [
          "webandersondesign.com"
        ],
        "url_path": [
          "/dozq/jkl.php",
          "/dozq/jkl.php?pi="
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1717061493068640648",
        "https://www.virustotal.com/gui/file/8bb36cb759cada50695ae3b5156b6f603c92081147400db544ac75ece8ce7129/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 2,
        "url_path": 2
      },
      "first_seen": "2023-09-27",
      "indicators": {
        "domain": [
          "mxsiclienteventlog.com",
          "neozelappconsole.com"
        ],
        "url_path": [
          "/ROAM/gret.php",
          "/WORK/info.php?cve="
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/lightC07379408/status/1706965936098390431",
        "https://www.virustotal.com/gui/file/e61e41d73682c166e7cf8c8a1db169f0f689fa2b70e19cfb0033e4c9211d9de6/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-09-12",
      "indicators": {
        "domain": [
          "xiuxonlinehost.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ThreatBookLabs/status/1677666593982271488"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2023-09-04",
      "indicators": {
        "domain": [
          "dashonlineclub.com"
        ],
        "url_path": [
          "/CVBN/mzx.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1698568505535414578",
        "https://www.virustotal.com/gui/ip-address/82.221.129.39/relations",
        "https://www.virustotal.com/gui/file/413d0aacddad41105f9f04de12cae9420919083796ed856df47ee2c7b3767fda/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-08-29",
      "indicators": {
        "domain": [
          "shzjwxsns.qqcloud.coauthcn.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ginkgo_g/status/1696470343979012600",
        "https://www.virustotal.com/gui/file/cc1c7e53ea567509a4bcfda2df95cb8f6ed7eed7cb2ae8786b736cd4d858173a/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-08-08",
      "indicators": {
        "domain": [
          "emmacloudsystem.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ThreatBookLabs/status/1688902207566196736"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2,
        "url_path": 1
      },
      "first_seen": "2023-08-02",
      "indicators": {
        "domain": [
          "kaatsonlinesupport.com",
          "thenewmusictunes.com"
        ],
        "url_path": [
          "/WVKA/qbv.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/binlmmhc/status/1686659755622924288",
        "https://twitter.com/binlmmhc/status/1686661719261958144"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-08-01",
      "indicators": {
        "domain": [
          "mercifulnearyou.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1686298387455283200",
        "https://www.virustotal.com/gui/file/c3fc4d145ce3cee06782753be269cad6632751fb9b824e1917b0de6e597ee2ee/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-07-28",
      "indicators": {
        "domain": [
          "farleysmxpph.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1684892151316955136",
        "https://www.virustotal.com/gui/file/1ea9e9ecd0e5b0ac4aedc1b5515484a372dd8aefb1dbeb00f243a0a3ce40fab9/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-07-19",
      "indicators": {
        "domain": [
          "webcarewellclinic.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ThreatBookLabs/status/1681656384071376897",
        "https://www.virustotal.com/gui/file/e8149ba0e8ce1a48142df2009688d5aa657286d56638b36da1c5ea2376ba6f9f/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-07-07",
      "indicators": {
        "domain": [
          "netmansrvdns.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ThreatBookLabs/status/1676953190913433607"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-06-22",
      "indicators": {
        "domain": [
          "daveonenewtestpanel.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1671452383879081984",
        "https://www.virustotal.com/gui/file/a2e3f464e1c39909f47f0b837b04e1256061f4a9698678e097b4dd09aa4de9c1/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-06-11",
      "indicators": {
        "domain": [
          "greenspowerpanel.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ThreatBookLabs/status/1662266116247552001"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-06-10",
      "indicators": {
        "domain": [
          "novasapothecary.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/StopMalvertisin/status/1666834231983767558",
        "https://www.virustotal.com/gui/file/490eccbb2712e7752a0ba193f783de9d333f67ba1fde5bb130280c5abf77555a/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-05-31",
      "indicators": {
        "domain": [
          "folkmusicstreams.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1663857230616186881",
        "https://www.virustotal.com/gui/file/4f94e7bd1515e0025293fb5a041bc41c20a7dd15a6dd0bc7076145a69d5238c0/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2023-05-05",
      "indicators": {
        "domain": [
          "uxmesysconsole.com"
        ],
        "ipv4": [
          "46.30.190.160:60099"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/JVPv5sIM3eFmGyi/status/1654318267002163202",
        "https://www.virustotal.com/gui/file/4e3e4d476810c95c34b6f2aa9c735f8e57e85e3b7a97c709adc5d6ee4a5f6ccc/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-03-27",
      "indicators": {
        "domain": [
          "erswuniconsharing.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/suyog41/status/1640346154205343747",
        "https://www.virustotal.com/gui/file/6ac16df25b0faead1d019f73edd9b12bac9f356d8250b5637f3f6a0b94e73c75/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-03-25",
      "indicators": {
        "domain": [
          "msdata.ddns.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/fmc_nan/status/1639175633019478017",
        "https://twitter.com/StopMalvertisin/status/1639339836225253377",
        "https://twitter.com/StopMalvertisin/status/1639340323200733184",
        "https://www.virustotal.com/gui/file/43c8ada7cb7c046893dd96aef195856ec94f62823ca1a2987adf31899788c92d/detection",
        "https://www.virustotal.com/gui/file/cd3effd25629ab9c440ed8bedb9bfb312c73a022cad5078684784ea07eff2c68/detection",
        "https://www.virustotal.com/gui/file/8aeb7dd31c764b0cf08b38030a73ac1d22b29522fbcf512e0d24544b3d01d8b3/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2023-03-24",
      "indicators": {
        "domain": [
          "bluelotus.mail-gdrive.com",
          "mail-gdrive.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/fmc_nan/status/1639175633019478017",
        "https://twitter.com/StopMalvertisin/status/1639339836225253377",
        "https://twitter.com/StopMalvertisin/status/1639340323200733184",
        "https://www.virustotal.com/gui/file/43c8ada7cb7c046893dd96aef195856ec94f62823ca1a2987adf31899788c92d/detection",
        "https://www.virustotal.com/gui/file/cd3effd25629ab9c440ed8bedb9bfb312c73a022cad5078684784ea07eff2c68/detection",
        "https://www.virustotal.com/gui/file/8aeb7dd31c764b0cf08b38030a73ac1d22b29522fbcf512e0d24544b3d01d8b3/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2023-03-24",
      "indicators": {
        "ipv4": [
          "46.30.188.43:51683"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/fmc_nan/status/1638874363335409667",
        "https://www.virustotal.com/gui/file/117ae7b2d08c8f11be7e4c4f27e54fa1d3a816073502241f1bb6277c89c67d85/detection",
        "https://www.virustotal.com/gui/file/f5e066da37fc9da2ca68678aa1e001c4428e9476dde8a927cb76fa9389038b06/detection",
        "https://www.virustotal.com/gui/file/2eca2f7a1fb4654dd73bf4a999ce155b2303e47340b26a49623f5b32948060c3/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-03-08",
      "indicators": {
        "domain": [
          "lbhandlesystem.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/StopMalvertisin/status/1633398160843485185",
        "https://www.virustotal.com/gui/file/9da7bb7065b91ec4634c080955d7ab086f7bc6f5391d1db10751812c38bcff19/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-02-23",
      "indicators": {
        "domain": [
          "coauthcn.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/StopMalvertisin/status/1628694986140311552",
        "https://www.virustotal.com/gui/file/ded0635c5ef9c3d63543abc36a69b1176875dba84ca005999986bd655da3a446/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-02-08",
      "indicators": {
        "domain": [
          "rxnovelapps.info"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/StopMalvertisin/status/1623199776476131328",
        "https://www.virustotal.com/gui/file/35952afc1c9f5597348373cee4611bc37287076606ca1b912d6a73aeee26602a/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-02-08",
      "indicators": {
        "domain": [
          "jlmusiklearn.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/StopMalvertisin/status/1623199772810301447",
        "https://www.virustotal.com/gui/file/636c2a16f94b5e30e725527a1bd2215399f98f17cc08580bc7358751b9eb2944/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-02-07",
      "indicators": {
        "domain": [
          "zingstockpicks.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ThreatBookLabs/status/1622884433945829376",
        "https://www.virustotal.com/gui/file/a447a890c7738c259ae0fc03958fbd6a96abd350a5acb9cc39fd8b3e7d450147/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-02-07",
      "indicators": {
        "domain": [
          "dracjohnsupport.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/StopMalvertisin/status/1622200643787309056",
        "https://www.virustotal.com/gui/file/f598f3bd60a39ad5861f145e82b33acde146b6ed5c2ffd9c6862ca1ea635afbf/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-01-26",
      "indicators": {
        "domain": [
          "wbfashionshow.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/StopMalvertisin/status/1618434887220105216",
        "https://www.virustotal.com/gui/file/561ace43f77de135d5b3286bd2ef270b185d0abdba15d442551211068f8bbf11/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-01-15",
      "indicators": {
        "domain": [
          "bensnewfashionstyles.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/StopMalvertisin/status/1614460800680472579",
        "https://www.virustotal.com/gui/file/95990cac90d19e6fe48bff85a72148c35facbb2e61b1f326d85e82603240a741/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-01-13",
      "indicators": {
        "domain": [
          "onlinehealthmatters.info"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/StopMalvertisin/status/1613833615984721922",
        "https://www.virustotal.com/gui/file/2fe49d93b5dcf19a2b60e91756246b051adc89303151c9e0b875c3f21c698be9/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-01-12",
      "indicators": {
        "domain": [
          "wcnsappword.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/RedDrip7/status/1613474917038837764",
        "https://www.virustotal.com/gui/file/5b90d4c397e575965ed49082981fd34272b5e1da010057f6ebcdd4f53a409ad0/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2023-01-09",
      "indicators": {
        "domain": [
          "ellearningstore.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/06dd9a7aebe0995b23526f04eabc85db3d2d98def9be58c1012a1280f5aa63f1/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 4
      },
      "first_seen": "2023-01-06",
      "indicators": {
        "domain": [
          "deriksystemspartens.com",
          "guppu.pk",
          "herbsbrunabuiz.net",
          "mirzadihatti.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/binlmmhc/status/1610969202722242561",
        "https://x.com/ShanHolo/status/1971249000985788673"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2023-01-06",
      "indicators": {
        "domain": [
          "kryoblockbind.net"
        ],
        "ipv4": [
          "23.106.122.149:31174"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ThreatBookLabs/status/1611260753151164417",
        "https://www.virustotal.com/gui/file/b7a9407b47baf7442e0baf94a3b4cc8b7420cb01364fc8e6a3c622b7ae39301f/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2023-01-06",
      "indicators": {
        "ipv4": [
          "147.124.223.140:41320"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/binlmmhc/status/1555002494593679361",
        "https://www.virustotal.com/gui/file/5374d2b9c9802d3b04735134960be84033c390b9279aea5b8ff7cbca8eaf9a4c/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-12-29",
      "indicators": {
        "domain": [
          "mabizstockholm.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/Des00464472/status/1608357353589735425"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-12-28",
      "indicators": {
        "domain": [
          "devqrytoprar.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/Des00464472/status/1607962294222454784",
        "https://www.virustotal.com/gui/file/caf871247b7256945598816e9c5461d64b6bdb68a15ff9f8742ca31dc00865f8/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-12-16",
      "indicators": {
        "domain": [
          "supunitysharehost.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ThreatBookLabs/status/1603675610504499200"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-12-13",
      "indicators": {
        "domain": [
          "rusjamystarapp.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ThreatBookLabs/status/1602611437326991360"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2022-12-01",
      "indicators": {
        "domain": [
          "mobisharestock.com",
          "updnangelgroup.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ginkgo_g/status/1598138502017085440",
        "https://www.virustotal.com/gui/file/8cfc803459682619e97f172e9cca33458fdf38b0b9ca09f8ccbc7df16f09240f/detection",
        "https://www.virustotal.com/gui/file/b514635f569791316e1c55057f63f596847e23c0fa1ca0f751c5a2135f72b8ff/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-11-21",
      "indicators": {
        "domain": [
          "vividworld.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/h2jazi/status/1594688392314474502",
        "https://www.virustotal.com/gui/file/4baf42e448120bd26fd0198c1b3382296fa3cb47f6c882fd5a9f4693d88847e5/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2022-11-06",
      "indicators": {
        "ipv4": [
          "110.42.64.137:9527"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/HONKONE_K/status/1533694370805063680",
        "https://www.virustotal.com/gui/file/d07b4487348de35df5e4cfa7c26c8cc6432230c1df220d2379fc702e25850909/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-10-21",
      "indicators": {
        "domain": [
          "qwavemediaservice.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/SethKingHi/status/1583039595524259841",
        "https://www.virustotal.com/gui/file/07504fcef717e6b74ed381e94eab5a9140171572b5572cda87b275e3873c8a88/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-10-14",
      "indicators": {
        "domain": [
          "dnldsalecraze.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/510b3de50c8dfc20a3085166f373a5f12475c7915984de0afa3cc0bff0c2580d/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-10-05",
      "indicators": {
        "domain": [
          "currweather.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/malwrhunterteam/status/1577401341768568854",
        "https://twitter.com/LukasStefanko/status/1577553669700083714",
        "https://www.virustotal.com/gui/ip-address/74.119.239.234/relations",
        "https://www.virustotal.com/gui/file/cbfa2aa73ea8bdc126c6767efd61a822786f4b48479859a6d14246a25d8ebd1a/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-10-04",
      "indicators": {
        "domain": [
          "weather-latest.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/malwrhunterteam/status/1577401341768568854",
        "https://twitter.com/LukasStefanko/status/1577553669700083714",
        "https://www.virustotal.com/gui/ip-address/74.119.239.234/relations",
        "https://www.virustotal.com/gui/file/cbfa2aa73ea8bdc126c6767efd61a822786f4b48479859a6d14246a25d8ebd1a/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 17
      },
      "first_seen": "2022-08-14",
      "indicators": {
        "domain": [
          "1drivestorage.com",
          "appsupdate.net",
          "archiverst.com",
          "createasocialcard.top",
          "hatvax.com",
          "play.google.com.whatsapp.playapps.ga",
          "playapps.ga",
          "shareflx.com",
          "shareflx.createasocialcard.top",
          "shareflx.social-card-share.top",
          "shareflx.socialpreviews.top",
          "social-card-share.top",
          "socialpreviews.top",
          "storeupdates.net",
          "theambix.org",
          "whatsapp.playapps.ga",
          "yoursdrive.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://about.fb.com/wp-content/uploads/2022/08/Quarterly-Adversarial-Threat-Report-Q2-2022.pdf",
        "https://otx.alienvault.com/pulse/62f2344533e6cfe5e975f573"
      ],
      "total": 17
    },
    {
      "counts": {
        "domain": 18
      },
      "first_seen": "2022-08-12",
      "indicators": {
        "domain": [
          "app2.appvlc.com",
          "appbriar.com",
          "appprotonvpn.com",
          "briarapppro.org",
          "converse-app.org",
          "gallery.play-protect.com",
          "gosignal.org",
          "islam-360-plus.com",
          "linphone-app.com",
          "pflix.camdvr.org",
          "play-protect.com",
          "signal-premium.org",
          "signalpro.org",
          "sikhsiyasatapp.net",
          "telegram-app.tech",
          "telegram-pro.org",
          "telegramapppro.org",
          "weather.play-protect.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://github.com/blackorbird/APT_REPORT/tree/master/bitter/2022"
      ],
      "total": 18
    },
    {
      "counts": {
        "domain": 3,
        "ipv4": 1
      },
      "first_seen": "2022-08-10",
      "indicators": {
        "domain": [
          "signal-premium-app.org",
          "signalpremium.com",
          "youtubepremiumapp.com"
        ],
        "ipv4": [
          "94.140.114.22:41322"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/Richard_S81/status/1557419346078666752",
        "https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware/",
        "https://www.bleepingcomputer.com/news/security/hackers-install-dracarys-android-malware-using-modified-signal-app/",
        "https://www.virustotal.com/gui/file/220fcfa47a11e7e3f179a96258a5bb69914c17e8ca7d0fdce44d13f1f3229548/detection (# Dracarys)"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-07-31",
      "indicators": {
        "domain": [
          "box.livevideosonlinepk.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/blackorbird/status/1295265067173163010",
        "https://twitter.com/ShadowChasing1/status/1303628547366350848",
        "https://twitter.com/ShadowChasing1/status/1306422911972958210",
        "https://twitter.com/Des00464472/status/1348964050076540928",
        "https://www.virustotal.com/gui/file/f45590dbb07e6a506c19f62b3f23b17a1aefbb6d8287f94a74c3ea707e6f4736/detection",
        "https://www.virustotal.com/gui/file/2ba30469c3cbe13aa02073ae6c48114d2902450c3745857946b30d811eff6e6d/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-07-26",
      "indicators": {
        "domain": [
          "novaoutletclub.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/h2jazi/status/1551980359990104064",
        "https://www.virustotal.com/gui/file/fec00455734451b722f3037e0a668c280c5ddbec1d905c647bf1a7f153856860/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 3,
        "url_path": 1
      },
      "first_seen": "2022-07-12",
      "indicators": {
        "domain": [
          "login.mynewellowstore.com",
          "mynewellowstore.com",
          "star.mynewellowstore.com"
        ],
        "url_path": [
          "/OibytDsERt.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/binlmmhc/status/1539094292064784384",
        "https://www.virustotal.com/gui/file/cfd883237a56a1a59c2882b9c7e11272ab32b76b35bbf69358c1168e82aae278/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2022-07-12",
      "indicators": {
        "domain": [
          "plprasvchost.net"
        ],
        "ipv4": [
          "185.117.73.195:59600"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/binlmmhc/status/1485545135882784768",
        "https://www.virustotal.com/gui/file/9ca64c2672258e72d297dbf0d2d7a57d92d6011e75ac08ba4feb01e8a975cf09/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2022-07-12",
      "indicators": {
        "ipv4": [
          "51.255.3.62:48152"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/binlmmhc/status/1529782539199868928",
        "https://www.virustotal.com/gui/file/3037f41f422033a11ed86871ea7f6dbba8b910dbee3212eb33165e488eecde14/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-07-12",
      "indicators": {
        "domain": [
          "fdcx32hostlaunchsvc.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/binlmmhc/status/1437704326789488642",
        "https://www.virustotal.com/gui/file/73f3a0d2d93c36276e1ecc7ebe64bede9c5adcfd01c5bebc89be75dc5b70111e/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-07-12",
      "indicators": {
        "domain": [
          "vercplsupport.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/binlmmhc/status/1377080167881924608",
        "https://www.virustotal.com/gui/file/fdc7cff892b890cb46c3c6d9fd3e8a62bb3059caaf034d63ba7d615342f17f70/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2022-06-15",
      "indicators": {
        "domain": [
          "wizbizkidshow.biz"
        ],
        "ipv4": [
          "64.44.131.109:33638"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/RedDrip7/status/1536987661939773440",
        "https://twitter.com/RedDrip7/status/1536989979229835265",
        "https://www.virustotal.com/gui/file/6f5ce57dce03d9456657ad872766ee8f78b1b6c258a8b99c7658bc0590813d4d/detection",
        "https://www.virustotal.com/gui/file/55901c2d5489d6ac5a0671971d29a31f4cdfa2e03d56e18c1585d78547a26396/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 5
      },
      "first_seen": "2022-06-08",
      "indicators": {
        "domain": [
          "botanoolifeapp.net",
          "deliverymailserver.com",
          "maildataserver.com",
          "pnptrafcroutsvc.net",
          "rurushophoogtypnl.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/__0XYC__/status/1501847173864083458",
        "https://twitter.com/__0XYC__/status/1501852899491852288",
        "https://twitter.com/blackorbird/status/1534373342446202881",
        "https://mp.weixin.qq.com/s/8j_rHA7gdMxY1_X8alj8Zg (Chinese)"
      ],
      "total": 5
    },
    {
      "counts": {
        "domain": 5
      },
      "first_seen": "2022-05-20",
      "indicators": {
        "domain": [
          "emshedulersvc.com",
          "han.huandocimama.com",
          "huandocimama.com",
          "log.huandocimama.com",
          "m.huandocimama.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/k3yp0d/status/1527656133837594624",
        "https://www.virustotal.com/gui/file/91ddbe011f1129c186849cd4c84cf7848f20f74bf512362b3283d1ad93be3e42/detection"
      ],
      "total": 5
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-05-14",
      "indicators": {
        "domain": [
          "nymedsvcsystems.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/k3yp0d/status/1525508775980957698",
        "https://www.virustotal.com/gui/file/dbd72490ce2642721ba8919b27a5f4854d2a8199132e9c4bb08f54b48282febc/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1,
        "url_path": 1
      },
      "first_seen": "2022-05-11",
      "indicators": {
        "domain": [
          "urocakpmpanel.com"
        ],
        "ipv4": [
          "185.141.25.244:33324"
        ],
        "url_path": [
          "/updateReqServ10893x.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-05-09",
      "indicators": {
        "domain": [
          "levarisnetqlsvc.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/SethKingHi/status/1523592393249136640",
        "https://www.virustotal.com/gui/file/471b384ca81a9d804992d4e4693ab3d42d419a2e2690ebb146671407fe0809d8/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-05-07",
      "indicators": {
        "domain": [
          "wmbwowxsvc.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/SethKingHi/status/1522867750481408001",
        "https://www.virustotal.com/gui/file/14986da600df26fdb4e435cf01b6be4e5fffcc001059609070a2de701496bdde/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2022-05-03",
      "indicators": {
        "ipv4": [
          "193.142.58.38:34905"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1521401317360513025",
        "https://www.virustotal.com/gui/file/a979c76afd0e9d2e135ca64a215e1af270222d059d806e7028022060e8cbe72c/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-05-01",
      "indicators": {
        "domain": [
          "zhaodaolajiankang.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/blackorbird/status/1520688352286052352"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-04-07",
      "indicators": {
        "domain": [
          "lltdifslogsvc.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/GGGGh0st/status/1512002541370097664",
        "https://www.virustotal.com/gui/file/195682cc8a6318d3eb2af83faaff76dc925e3e382b13729b9e03cf6d8f5435b0/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-04-04",
      "indicators": {
        "domain": [
          "windowtemplates.info"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/RedDrip7/status/1468420250245136390",
        "https://twitter.com/kyleehmke/status/1510958302800318467",
        "https://www.virustotal.com/gui/ip-address/172.93.201.143/relations",
        "https://www.virustotal.com/gui/file/25aeec4c58f740c62664c757987902981c9676d0f58f9337f852fa9dd8a874d9"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-03-31",
      "indicators": {
        "domain": [
          "coerciondigital.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/h2jazi/status/1509636768504717313",
        "https://www.virustotal.com/gui/file/9fca7eeb6a7c3591492ddb7693b9d7b2349acc3240cc46710f91fb79d8a8deb6/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "url": 1
      },
      "first_seen": "2022-03-18",
      "indicators": {
        "url": [
          "http://45.11.19.170"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/34182232200718be91a1b683112f8e44c1ee75bf3b11e2c055de68d990e0dd92/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-03-10",
      "indicators": {
        "domain": [
          "ekoconect.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/__0XYC__/status/1501847173864083458",
        "https://twitter.com/__0XYC__/status/1501852899491852288",
        "https://twitter.com/blackorbird/status/1534373342446202881",
        "https://mp.weixin.qq.com/s/8j_rHA7gdMxY1_X8alj8Zg (Chinese)"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-03-04",
      "indicators": {
        "domain": [
          "diyefosterfeeds.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/h2jazi/status/1499501002743062539",
        "https://www.virustotal.com/gui/file/eaa013b863bda3bd76c6f6073cc304002d1a9f317c8fba9c362534aff7dd1b0b/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2022-02-16",
      "indicators": {
        "domain": [
          "snapsvcvirtual.net"
        ],
        "ipv4": [
          "45.86.163.212:49920"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/RedDrip7/status/1493905786354892801",
        "https://www.virustotal.com/gui/file/a4afaa41383f447d96d0ebb1e2e50721af080e951d40754a836215fb2c3f0660/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "url_path": 2
      },
      "first_seen": "2022-02-08",
      "indicators": {
        "url_path": [
          "/dFFrt3856ByutTs/",
          "/dFFrt3856ByutTs/xnb/data1.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/k3yp0d/status/1490994886338027527",
        "https://www.virustotal.com/gui/file/15a58d7223761f8386c902ae2d55a1313b4744e543f8f228851d0376dce721fe/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2022-01-19",
      "indicators": {
        "domain": [
          "comnmsgwrapsvc.net"
        ],
        "url_path": [
          "/jsprc.php?h="
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/1b60ef6900dc790f2565e4fd27b14742ed6bec53252e3b142f0af6a246d94837/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-01-11",
      "indicators": {
        "domain": [
          "gpcpsvclog.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1480853604609126403",
        "https://www.virustotal.com/gui/file/4e0824b6c9c4e53a7caeda78c8b60bf1dc20670e58955ad1e2e9f89fdf22029c/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 6
      },
      "first_seen": "2022-01-10",
      "indicators": {
        "domain": [
          "cpcalendars.tomcruefrshsvc.com",
          "cpcontacts.tomcruefrshsvc.com",
          "mail.tomcruefrshsvc.com",
          "viewz.tomcruefrshsvc.com",
          "webdisk.tomcruefrshsvc.com",
          "webmail.tomcruefrshsvc.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1478259210110775297",
        "https://www.virustotal.com/gui/file/9a8b201eb2bebe309d15c7b0ab5a6dcde460b84b035bb3575d4a0ec6af51a37e/detection"
      ],
      "total": 6
    },
    {
      "counts": {
        "domain": 7
      },
      "first_seen": "2022-01-09",
      "indicators": {
        "domain": [
          "autodefragapp.com",
          "care.autodefragapp.com",
          "evert.autodefragapp.com",
          "helpdesk.autodefragapp.com",
          "mail.autodefragapp.com",
          "newdesk.autodefragapp.com",
          "support.autodefragapp.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1480193191299084288"
      ],
      "total": 7
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2022-01-08",
      "indicators": {
        "domain": [
          "slrpnlcontrlintrface.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1479641732169932801",
        "https://www.virustotal.com/gui/file/f7ed5eec6d1869498f2fca8f989125326b2d8cee8dcacf3bc9315ae7566963db/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 3,
        "url_path": 4
      },
      "first_seen": "2022-01-04",
      "indicators": {
        "domain": [
          "sbss.com.pk",
          "subscribe.tomcruefrshsvc.com",
          "tomcruefrshsvc.com"
        ],
        "url_path": [
          "/SzWvcxuer/",
          "/VcvNbtgRrPopqSD/",
          "/VcvNbtgRrPopqSD/SzWvcxuer/",
          "/VcvNbtgRrPopqSD/SzWvcxuer/userlog.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1478259210110775297",
        "https://www.virustotal.com/gui/file/9a8b201eb2bebe309d15c7b0ab5a6dcde460b84b035bb3575d4a0ec6af51a37e/detection"
      ],
      "total": 7
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2021-12-29",
      "indicators": {
        "domain": [
          "epapbuizhost.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1474005551818313729",
        "https://www.virustotal.com/gui/file/6b475078aca28ef7c8b162065b562e61670aceea1602715f53d64d81e7023a2a/detection",
        "https://twitter.com/__0XYC__/status/1501847173864083458",
        "https://twitter.com/__0XYC__/status/1501852899491852288",
        "https://twitter.com/blackorbird/status/1534373342446202881",
        "https://mp.weixin.qq.com/s/8j_rHA7gdMxY1_X8alj8Zg (Chinese)"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2021-12-08",
      "indicators": {
        "domain": [
          "msofficeupdates.ddns.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/RedDrip7/status/1468420250245136390",
        "https://twitter.com/kyleehmke/status/1510958302800318467",
        "https://www.virustotal.com/gui/ip-address/172.93.201.143/relations",
        "https://www.virustotal.com/gui/file/25aeec4c58f740c62664c757987902981c9676d0f58f9337f852fa9dd8a874d9"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2021-11-26",
      "indicators": {
        "domain": [
          "snsrsvchost.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/HONKONE_K/status/1464090084349669382",
        "https://www.virustotal.com/gui/file/528c6bf7c0c32be26bc1e32df73fed73ca7312e1b6fdb2ca20d5f0c157b02256/detection",
        "https://www.virustotal.com/gui/file/499bf98bef84eeff781828932b16747a5aa03d3f70e15aabf4718cccd20a51a5/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2021-09-17",
      "indicators": {
        "domain": [
          "olmajhnservice.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1438706652522303489",
        "https://www.virustotal.com/gui/file/a169156b0d307ca978d722cafbd3bc1d04c94e55f71bc9d16ba6fabb8140be83/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 8,
        "ipv4": 1,
        "url": 1,
        "url_path": 5
      },
      "first_seen": "2021-08-06",
      "indicators": {
        "domain": [
          "bheragreens.com",
          "msisspsvc.net",
          "myprivatehostsvc.com",
          "w32timeslicesvc.net",
          "wdisvcnotifyhost.com",
          "webmailcgwip.com",
          "windiagnosticsvc.net",
          "youxiangxiezhu.com"
        ],
        "ipv4": [
          "45.11.19.170:34318"
        ],
        "url": [
          "http://193.142.58.186"
        ],
        "url_path": [
          "/45Ugty845nv7rt.php",
          "/UihbywscTZ/",
          "/UihbywscTZ/45Ugty845nv7rt.php",
          "/n9brCs21/",
          "/n9brCs21/apprun"
        ]
      },
      "precision": "exact",
      "references": [
        "https://ti.qianxin.com/blog/articles/%22operation-magichm%22:CHM-file-release-and-subsequent-operation-of-BITTER-organization/ (Chenese)"
      ],
      "total": 15
    },
    {
      "counts": {
        "domain": 2,
        "url_path": 7
      },
      "first_seen": "2021-08-06",
      "indicators": {
        "domain": [
          "gxwxtvonline.com",
          "otx.gxwxtvonline.com"
        ],
        "url_path": [
          "/OtPefhePbvw/",
          "/OtPefhePbvw/datarcvoninfile.php",
          "/OtPefhePbvw/nnodata3inf.php",
          "/OtPefhePbvw/onlinedata1inf.php",
          "/datarcvoninfile.php",
          "/nnodata3inf.php",
          "/onlinedata1inf.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://cloud.tencent.com/developer/article/1826900",
        "https://twitter.com/AnonySecAgency/status/1423510463212523521",
        "https://www.virustotal.com/gui/file/1ac7f4cee8b614359cb0997c1934e8b2e4cab0bbfddfa84bedb6d1b2f55e26f3/detection"
      ],
      "total": 9
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2021-08-06",
      "indicators": {
        "domain": [
          "svc2mcxwave.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://ti.qianxin.com/blog/articles/%22operation-magichm%22:CHM-file-release-and-subsequent-operation-of-BITTER-organization/ (Chenese)",
        "https://twitter.com/__0XYC__/status/1501847173864083458",
        "https://twitter.com/__0XYC__/status/1501852899491852288",
        "https://twitter.com/blackorbird/status/1534373342446202881",
        "https://mp.weixin.qq.com/s/8j_rHA7gdMxY1_X8alj8Zg (Chinese)"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2021-06-26",
      "indicators": {
        "domain": [
          "yuruhjforonjoigrvnbnrgoigoigoisannvmvnfnmkfd7.000webhostapp.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1408579947417927687"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2021-06-26",
      "indicators": {
        "domain": [
          "mail-mfa-gov-cn-login.netlify.app"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1408579870230126592",
        "https://twitter.com/malwrhunterteam/status/1408491293207154696"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2021-03-26",
      "indicators": {
        "domain": [
          "snsrsvchost.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1375227175226368006",
        "https://www.virustotal.com/gui/file/e07e8cbeeddc60697cc6fdb5314bd3abb748e3ac5347ff108fef9eab2f5c89b8/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "url_path": 1
      },
      "first_seen": "2021-02-02",
      "indicators": {
        "url_path": [
          "/taskshandlers/DBhandle/secondary.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1356412596430233603",
        "https://twitter.com/_re_fox/status/1301887287765225477",
        "https://app.any.run/tasks/383a15aa-63b0-48ee-9a90-2cb64da9134f/",
        "https://www.virustotal.com/gui/file/c2131a3906d97b5d7d697d16de15a8f704db1e6e4a8d3d7316c784d45716cffc/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1,
        "url": 2
      },
      "first_seen": "2020-12-14",
      "indicators": {
        "domain": [
          "pichostfrm.net"
        ],
        "ipv4": [
          "107.173.63.218:58370"
        ],
        "url": [
          "http://72.11.134.216",
          "http://82.221.136.27"
        ]
      },
      "precision": "exact",
      "references": [
        "https://ti.qianxin.com/blog/articles/Blocking-APT:-Qianxin's-QOWL-Engine-Defeats-Bitter's-Targeted-Attack-on-Domestic-Government-and-Enterprises/",
        "https://otx.alienvault.com/pulse/5fd7a716e178ff014c630ecb",
        "https://www.virustotal.com/gui/file/6cb0c0a2f89d1e82653d2b0dd1389007543616d11f0709ff194a4db2d36865f7/detection",
        "https://www.virustotal.com/gui/file/820ab2458839688369906cee2a4c08b4694e2bddcb187358ce575e5d2063515e/behavior",
        "https://www.virustotal.com/gui/file/efeaadaa53ec033d224b58be109c0f5fde12c8775fc5603f51efa8e23bcd6fb2/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 5
      },
      "first_seen": "2020-09-27",
      "indicators": {
        "domain": [
          "churchill91.com",
          "muzicwonder.com",
          "nsiagenthoster.net",
          "tulipnetworks.net",
          "wirelesssolutions.mobi"
        ]
      },
      "precision": "exact",
      "references": [
        "https://github.com/pan-unit42/iocs/blob/master/bitter/iocs.csv"
      ],
      "total": 5
    },
    {
      "counts": {
        "url_path": 4
      },
      "first_seen": "2020-09-27",
      "indicators": {
        "url_path": [
          "/F1l3estPhPInf1.php",
          "/F1l3estPhPInf2.php",
          "/PsehestyvuPw/",
          "/PsehestyvuPw/F1l3estPhPInf1.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1306858164277526528"
      ],
      "total": 4
    },
    {
      "counts": {
        "url_path": 3
      },
      "first_seen": "2020-09-17",
      "indicators": {
        "url_path": [
          "/tstRsdvgiMincSnyYutspph/",
          "/tstRsdvgiMincSnyYutspph/tstPerHyPfilbmiw1.php",
          "/tstRsdvgiMincSnyYutspph/tstPerHyPfilbmiwts2t.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/blackorbird/status/1295265067173163010",
        "https://twitter.com/ShadowChasing1/status/1303628547366350848",
        "https://twitter.com/ShadowChasing1/status/1306422911972958210",
        "https://twitter.com/Des00464472/status/1348964050076540928",
        "https://www.virustotal.com/gui/file/f45590dbb07e6a506c19f62b3f23b17a1aefbb6d8287f94a74c3ea707e6f4736/detection",
        "https://www.virustotal.com/gui/file/2ba30469c3cbe13aa02073ae6c48114d2902450c3745857946b30d811eff6e6d/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "url": 1
      },
      "first_seen": "2020-09-15",
      "indicators": {
        "url": [
          "http://162.0.229.203"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1256036038331387904",
        "https://twitter.com/ShadowChasing1/status/1305879886473474048",
        "https://twitter.com/_re_fox/status/1305925337004601345",
        "https://ti.qianxin.com/blog/articles/Blocking-APT:-Qianxin's-QOWL-Engine-Defeats-Bitter's-Targeted-Attack-on-Domestic-Government-and-Enterprises/",
        "https://otx.alienvault.com/pulse/5fd7a716e178ff014c630ecb",
        "https://www.virustotal.com/gui/file/6cb0c0a2f89d1e82653d2b0dd1389007543616d11f0709ff194a4db2d36865f7/detection",
        "https://www.virustotal.com/gui/file/820ab2458839688369906cee2a4c08b4694e2bddcb187358ce575e5d2063515e/behavior",
        "https://www.virustotal.com/gui/file/efeaadaa53ec033d224b58be109c0f5fde12c8775fc5603f51efa8e23bcd6fb2/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "url": 1
      },
      "first_seen": "2020-09-10",
      "indicators": {
        "url": [
          "jgcest.com/css/"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/_re_fox/status/1301887287765225477",
        "https://twitter.com/ShadowChasing1/status/1304017919655858177",
        "https://app.any.run/tasks/383a15aa-63b0-48ee-9a90-2cb64da9134f/"
      ],
      "total": 1
    },
    {
      "counts": {
        "url_path": 5
      },
      "first_seen": "2020-09-09",
      "indicators": {
        "url_path": [
          "/tstPerHyPfilbmiw1.php",
          "/tstPerHyPfilbmiwts2t.php",
          "/tstRsdvgiMincSnyYutsphp/",
          "/tstRsdvgiMincSnyYutsphp/tstPerHyPfilbmiw1.php",
          "/tstRsdvgiMincSnyYutsphp/tstPerHyPfilbmiwts2t.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/blackorbird/status/1295265067173163010",
        "https://twitter.com/ShadowChasing1/status/1303628547366350848",
        "https://twitter.com/ShadowChasing1/status/1306422911972958210",
        "https://twitter.com/Des00464472/status/1348964050076540928",
        "https://www.virustotal.com/gui/file/f45590dbb07e6a506c19f62b3f23b17a1aefbb6d8287f94a74c3ea707e6f4736/detection",
        "https://www.virustotal.com/gui/file/2ba30469c3cbe13aa02073ae6c48114d2902450c3745857946b30d811eff6e6d/detection"
      ],
      "total": 5
    },
    {
      "counts": {
        "url_path": 1
      },
      "first_seen": "2020-09-04",
      "indicators": {
        "url_path": [
          "/taskshandlers/DBhandle/primary_main.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1356412596430233603",
        "https://twitter.com/_re_fox/status/1301887287765225477",
        "https://app.any.run/tasks/383a15aa-63b0-48ee-9a90-2cb64da9134f/",
        "https://www.virustotal.com/gui/file/c2131a3906d97b5d7d697d16de15a8f704db1e6e4a8d3d7316c784d45716cffc/detection",
        "https://twitter.com/binlmmhc/status/1377080167881924608",
        "https://www.virustotal.com/gui/file/fdc7cff892b890cb46c3c6d9fd3e8a62bb3059caaf034d63ba7d615342f17f70/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2020-09-04",
      "indicators": {
        "domain": [
          "vdsappauthservice.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1356412596430233603",
        "https://twitter.com/_re_fox/status/1301887287765225477",
        "https://app.any.run/tasks/383a15aa-63b0-48ee-9a90-2cb64da9134f/",
        "https://www.virustotal.com/gui/file/c2131a3906d97b5d7d697d16de15a8f704db1e6e4a8d3d7316c784d45716cffc/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "url": 2
      },
      "first_seen": "2020-08-24",
      "indicators": {
        "url": [
          "oppak.com/one/eths",
          "oppak.com/one/opa"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/HONKONE_K/status/1297829657568407554",
        "https://www.virustotal.com/gui/file/0ce047bb77073990a8810f8d6f178dc0d4fc5257603790f80d3d84b0b2405a6c/detection",
        "https://www.virustotal.com/gui/file/ced29451faed4f5dfa9ce80e35469e3573a89f848d5a7f5b087ee62a62f5f89a/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 5
      },
      "first_seen": "2020-08-17",
      "indicators": {
        "domain": [
          "livevideosonlinepk.com"
        ],
        "url_path": [
          "/PerHyPfilbmiw1.php",
          "/PerHyPfilbmiw2.php",
          "/RsdvgiMincSnyYu/",
          "/RsdvgiMincSnyYu/PerHyPfilbmiw1.php",
          "/RsdvgiMincSnyYu/PerHyPfilbmiw2.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/blackorbird/status/1295265067173163010",
        "https://twitter.com/ShadowChasing1/status/1303628547366350848",
        "https://twitter.com/ShadowChasing1/status/1306422911972958210",
        "https://twitter.com/Des00464472/status/1348964050076540928",
        "https://www.virustotal.com/gui/file/f45590dbb07e6a506c19f62b3f23b17a1aefbb6d8287f94a74c3ea707e6f4736/detection",
        "https://www.virustotal.com/gui/file/2ba30469c3cbe13aa02073ae6c48114d2902450c3745857946b30d811eff6e6d/detection"
      ],
      "total": 6
    },
    {
      "counts": {
        "url_path": 4
      },
      "first_seen": "2020-08-17",
      "indicators": {
        "url_path": [
          "/ergdfbd/",
          "/healthne/",
          "/ourtyaz/",
          "/ourtyaz/qwf.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/aecfa3879cd68b3a2ab0771638c0d649b007cbb6f28dddb56af4fb740b8e25a5/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "url_path": 1
      },
      "first_seen": "2020-08-17",
      "indicators": {
        "url_path": [
          "/RguhsT/"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/aecfa3879cd68b3a2ab0771638c0d649b007cbb6f28dddb56af4fb740b8e25a5/detection",
        "https://twitter.com/ShadowChasing1/status/1256036038331387904",
        "https://twitter.com/ShadowChasing1/status/1305879886473474048",
        "https://twitter.com/_re_fox/status/1305925337004601345"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "url": 2
      },
      "first_seen": "2020-07-07",
      "indicators": {
        "domain": [
          "mia.alkhaleejpk.info"
        ],
        "url": [
          "tusdec.org.pk/ee",
          "uniengrisb.com/img/rt.msi"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/Timele9527/status/1277843761318354944"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2020-07-07",
      "indicators": {
        "domain": [
          "liveways.pk"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/Timele9527/status/1280315854094123008"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2020-06-29",
      "indicators": {
        "domain": [
          "alkhaleejpk.info"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1306858164277526528"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2020-06-18",
      "indicators": {
        "domain": [
          "usmservice.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ccxsaber/status/1273442309816770560"
      ],
      "total": 1
    },
    {
      "counts": {
        "url": 1
      },
      "first_seen": "2020-05-08",
      "indicators": {
        "url": [
          "http://63.250.38.240"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/MeltX0R/status/1258870289066319872",
        "https://www.virustotal.com/gui/ip-address/63.250.38.240/relations"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2020-05-01",
      "indicators": {
        "domain": [
          "camncryptsvc.net"
        ],
        "url_path": [
          "/RguhsT/accept.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ShadowChasing1/status/1256036038331387904",
        "https://twitter.com/ShadowChasing1/status/1305879886473474048",
        "https://twitter.com/_re_fox/status/1305925337004601345"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 4
      },
      "first_seen": "2020-04-21",
      "indicators": {
        "domain": [
          "activemobistore.ddns.net",
          "cbyxhuxo663.ddns.net",
          "flashnewsservice.org",
          "wdibitmapservice.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.blackberry.com/content/dam/blackberry-com/asset/enterprise/pdf/direct/mobile-malware-report.pdf"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2020-02-03",
      "indicators": {
        "domain": [
          "wbclientservice.ddns.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/Rmy_Reserve/status/1224289465872502789"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2019-12-02",
      "indicators": {
        "domain": [
          "noitfication-office-client.890m.com",
          "office360-pub.16mb.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/Timele9527/status/1201477767352553472",
        "https://twitter.com/Timele9527/status/1201477848852090881",
        "https://twitter.com/Timele9527/status/1201477876236701696"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2019-11-28",
      "indicators": {
        "domain": [
          "kerbosim.com",
          "quartzu.hol.es"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/Timele9527/status/1201477767352553472",
        "https://twitter.com/Timele9527/status/1201477848852090881",
        "https://twitter.com/Timele9527/status/1201477876236701696"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-11-21",
      "indicators": {
        "domain": [
          "cloud-storage-service.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/Timele9527/status/1201477767352553472",
        "https://twitter.com/Timele9527/status/1201477848852090881",
        "https://twitter.com/Timele9527/status/1201477876236701696"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-11-07",
      "indicators": {
        "domain": [
          "tvnservereventlog.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/ccxsaber/status/1192326844529422337"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-11-04",
      "indicators": {
        "domain": [
          "netnsiservice.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/James_inthe_box/status/1166128688175300608",
        "https://twitter.com/MeltX0R/status/1170183286712340482",
        "https://meltx0r.github.io/tech/2019/09/06/bitter-apt-not-so-sweet.html",
        "https://twitter.com/Timele9527/status/1169785910881218560"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2019-10-25",
      "indicators": {
        "domain": [
          "nethostsupport.ddns.net",
          "sysintservice.ddns.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/blackorbird/status/1187662590224191489"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-10-15",
      "indicators": {
        "domain": [
          "lmhostsvc.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/James_inthe_box/status/1183927764778274816"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-09-10",
      "indicators": {
        "domain": [
          "w32infinitisupports.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/RedDrip7/status/1170988245561294850",
        "https://twitter.com/MeltX0R/status/1171245112082481153"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-09-09",
      "indicators": {
        "domain": [
          "blth32serv.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/RedDrip7/status/1170988245561294850",
        "https://twitter.com/MeltX0R/status/1171245112082481153"
      ],
      "total": 1
    },
    {
      "counts": {
        "url_path": 3
      },
      "first_seen": "2019-09-08",
      "indicators": {
        "url_path": [
          "/Mcx2svc.php",
          "/lax05u.php",
          "/ms2u1p.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/James_inthe_box/status/1166128688175300608",
        "https://twitter.com/MeltX0R/status/1170183286712340482",
        "https://meltx0r.github.io/tech/2019/09/06/bitter-apt-not-so-sweet.html",
        "https://twitter.com/Timele9527/status/1169785910881218560"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 4
      },
      "first_seen": "2019-09-07",
      "indicators": {
        "domain": [
          "biocons.pk",
          "gandharaart.org",
          "maq.com.pk",
          "zhongwenchuantongqiye.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/James_inthe_box/status/1166128688175300608",
        "https://twitter.com/MeltX0R/status/1170183286712340482",
        "https://meltx0r.github.io/tech/2019/09/06/bitter-apt-not-so-sweet.html",
        "https://twitter.com/Timele9527/status/1169785910881218560"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-09-07",
      "indicators": {
        "domain": [
          "sartetextile.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/James_inthe_box/status/1166128688175300608",
        "https://twitter.com/MeltX0R/status/1170183286712340482",
        "https://meltx0r.github.io/tech/2019/09/06/bitter-apt-not-so-sweet.html",
        "https://twitter.com/Timele9527/status/1169785910881218560",
        "https://ti.qianxin.com/blog/articles/%22operation-magichm%22:CHM-file-release-and-subsequent-operation-of-BITTER-organization/ (Chenese)"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-09-05",
      "indicators": {
        "domain": [
          "gongzuosousuo.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/Timele9527/status/1169430987832344576"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "url_path": 1
      },
      "first_seen": "2019-08-27",
      "indicators": {
        "domain": [
          "onlinejohnline99.org"
        ],
        "url_path": [
          "/kvs06v.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/James_inthe_box/status/1166128688175300608",
        "https://twitter.com/MeltX0R/status/1170183286712340482",
        "https://meltx0r.github.io/tech/2019/09/06/bitter-apt-not-so-sweet.html",
        "https://twitter.com/Timele9527/status/1169785910881218560"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 6
      },
      "first_seen": "2019-08-09",
      "indicators": {
        "domain": [
          "btappclientsvc.net",
          "cdaxpropsvc.net",
          "v3solutions4all.com",
          "v3solutions4all.org",
          "winmanagerservice.net",
          "winmanagerservice.org"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.anomali.com/blog/suspected-bitter-apt-continues-targeting-government-of-china-and-chinese-organizations",
        "https://cert.360.cn/report/detail?id=137867e159331b7a968aa45050502d13",
        "https://otx.alienvault.com/pulse/5d4d82f21a9bb34d2b0e65f7"
      ],
      "total": 6
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-08-09",
      "indicators": {
        "domain": [
          "wangluojiumingjingli.org"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.anomali.com/blog/suspected-bitter-apt-continues-targeting-government-of-china-and-chinese-organizations",
        "https://cert.360.cn/report/detail?id=137867e159331b7a968aa45050502d13",
        "https://otx.alienvault.com/pulse/5d4d82f21a9bb34d2b0e65f7",
        "https://twitter.com/blackorbird/status/1182479754965876737"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-07-08",
      "indicators": {
        "domain": [
          "healthdevicetracker.co"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/h4ckak/status/1147710998817542145"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 3
      },
      "first_seen": "2019-04-20",
      "indicators": {
        "domain": [
          "khurram.com.pk",
          "traxbin.com",
          "wcnchost.ddns.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://ti.360.net/blog/articles/analysis-of-targeted-attack-against-pakistan-by-exploiting-inpage-vulnerability-and-related-apt-groups/ (Chinese)"
      ],
      "total": 3
    },
    {
      "counts": {
        "url_path": 5
      },
      "first_seen": "2019-03-05",
      "indicators": {
        "url_path": [
          "/ergdfbd/wscspl",
          "/healthne/accept.php",
          "/healthne/regdl",
          "/ourtyaz/dwnack.php",
          "/ourtyaz/qwe.php"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.virustotal.com/gui/file/aecfa3879cd68b3a2ab0771638c0d649b007cbb6f28dddb56af4fb740b8e25a5/detection"
      ],
      "total": 5
    },
    {
      "counts": {
        "domain": 30
      },
      "first_seen": "2019-02-27",
      "indicators": {
        "domain": [
          "a.churchill91.com",
          "aday.primeservices.mobi",
          "chinatel90.com",
          "confirm97.com",
          "destiny91.com",
          "font.jiangsuhost.com",
          "healthnewsone.com",
          "hewle.kielsoservice.net",
          "johnywalter.webatu.com",
          "mappservworldvide.16mb.com",
          "marvel89.com",
          "marvellighter.com",
          "medzone71.com",
          "mob.wirelesssolutions.mobi",
          "nethosttalk.com",
          "red5big.com",
          "sound.muzicwonder.com",
          "spring.tulipnetworks.net",
          "sterling66.com",
          "stingray91.com",
          "styl.crrerc.com",
          "styl.hairparker.com",
          "thematrix.esy.es",
          "thepandaservices.nsiagenthoster.net",
          "victory1983.ddns.net",
          "wills.hairparker.com",
          "wingames2015.com",
          "woodwind71.com",
          "xiovo416.net",
          "zmwardrobe.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://github.com/pan-unit42/iocs/blob/master/bitter/iocs.csv"
      ],
      "total": 30
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-02-27",
      "indicators": {
        "domain": [
          "aroundtheworld123.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://github.com/pan-unit42/iocs/blob/master/bitter/iocs.csv",
        "https://twitter.com/blackorbird/status/1169925232255090689"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2019-02-05",
      "indicators": {
        "domain": [
          "frameworksupport.net"
        ]
      },
      "precision": "exact",
      "references": [
        "https://github.com/pan-unit42/iocs/blob/master/bitter/iocs.csv"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2018-09-29",
      "indicators": {
        "domain": [
          "newmysticvision.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://github.com/pan-unit42/iocs/blob/master/bitter/iocs.csv"
      ],
      "total": 1
    }
  ]
}
