ActivityPub Viewer

A small tool to view real-world ActivityPub objects as JSON! Enter a URL or username from Mastodon or a similar service below, and we'll send a request with the right Accept header to the server to view the underlying object.

Open in browser →
{ "@context": [ "https://www.w3.org/ns/activitystreams", { "ostatus": "http://ostatus.org#", "atomUri": "ostatus:atomUri", "inReplyToAtomUri": "ostatus:inReplyToAtomUri", "conversation": "ostatus:conversation", "sensitive": "as:sensitive", "toot": "http://joinmastodon.org/ns#", "votersCount": "toot:votersCount", "litepub": "http://litepub.social/ns#", "directMessage": "litepub:directMessage", "Hashtag": "as:Hashtag" } ], "id": "https://infosec.exchange/users/InfobloxThreatIntel/statuses/114083807957414192", "type": "Note", "summary": null, "inReplyTo": null, "published": "2025-02-28T22:12:41Z", "url": "https://infosec.exchange/@InfobloxThreatIntel/114083807957414192", "attributedTo": "https://infosec.exchange/users/InfobloxThreatIntel", "to": [ "https://www.w3.org/ns/activitystreams#Public" ], "cc": [ "https://infosec.exchange/users/InfobloxThreatIntel/followers" ], "sensitive": false, "atomUri": "https://infosec.exchange/users/InfobloxThreatIntel/statuses/114083807957414192", "inReplyToAtomUri": null, "conversation": "tag:infosec.exchange,2025-02-28:objectId=246544045:objectType=Conversation", "content": "<p>While everyone is enjoying Carnival in Brazil, threat actors are still out there trying to lure people into their traps. We have found a cluster of lookalikes to the Brazilian DMV office (DETRAN in Portuguese). We observed at least two instances where they were impersonating the DMV office for the Brazilian states of Paraná and Maranhão.<br /> <br />The actor(s) create domains with the same label, but on several different TLDs (mostly highly abused). Here are some examples of what they look like.<br /> <br />consultes-seu-debitos2025.&lt;space|site|shop|cloud&gt;<br />debitos-sp-2025.&lt;club|com|lat|net|online|store|xyz&gt;<br />de3trasn2025.&lt;click|fun|life|online|xyz&gt;<br />departamentodetran2025.&lt;click|icu|lat&gt;<br />detran2025.&lt;click|icu|lat|sbs&gt;<br />l1cenciamento-detran2025.&lt;click|icu|lat|sbs&gt;<br /> <br /><a href=\"https://infosec.exchange/tags/lookalikes\" class=\"mention hashtag\" rel=\"tag\">#<span>lookalikes</span></a> <a href=\"https://infosec.exchange/tags/dns\" class=\"mention hashtag\" rel=\"tag\">#<span>dns</span></a> <a href=\"https://infosec.exchange/tags/threatintel\" class=\"mention hashtag\" rel=\"tag\">#<span>threatintel</span></a> <a href=\"https://infosec.exchange/tags/cybercrime\" class=\"mention hashtag\" rel=\"tag\">#<span>cybercrime</span></a> <a href=\"https://infosec.exchange/tags/threatintelligence\" class=\"mention hashtag\" rel=\"tag\">#<span>threatintelligence</span></a> <a href=\"https://infosec.exchange/tags/cybersecurity\" class=\"mention hashtag\" rel=\"tag\">#<span>cybersecurity</span></a> <a href=\"https://infosec.exchange/tags/infoblox\" class=\"mention hashtag\" rel=\"tag\">#<span>infoblox</span></a> <a href=\"https://infosec.exchange/tags/infobloxthreatintel\" class=\"mention hashtag\" rel=\"tag\">#<span>infobloxthreatintel</span></a><br /> <br /><a href=\"https://urlscan.io/result/802374b7-6c8b-433b-b6e0-32561f74b7d3/\" target=\"_blank\" rel=\"nofollow noopener\" translate=\"no\"><span class=\"invisible\">https://</span><span class=\"ellipsis\">urlscan.io/result/802374b7-6c8</span><span class=\"invisible\">b-433b-b6e0-32561f74b7d3/</span></a><br /><a href=\"https://urlscan.io/result/721b12bb-d5fe-4c7e-b2b5-724e07aa22e0/\" target=\"_blank\" rel=\"nofollow noopener\" translate=\"no\"><span class=\"invisible\">https://</span><span class=\"ellipsis\">urlscan.io/result/721b12bb-d5f</span><span class=\"invisible\">e-4c7e-b2b5-724e07aa22e0/</span></a></p>", "contentMap": { "en": "<p>While everyone is enjoying Carnival in Brazil, threat actors are still out there trying to lure people into their traps. We have found a cluster of lookalikes to the Brazilian DMV office (DETRAN in Portuguese). We observed at least two instances where they were impersonating the DMV office for the Brazilian states of Paraná and Maranhão.<br /> <br />The actor(s) create domains with the same label, but on several different TLDs (mostly highly abused). Here are some examples of what they look like.<br /> <br />consultes-seu-debitos2025.&lt;space|site|shop|cloud&gt;<br />debitos-sp-2025.&lt;club|com|lat|net|online|store|xyz&gt;<br />de3trasn2025.&lt;click|fun|life|online|xyz&gt;<br />departamentodetran2025.&lt;click|icu|lat&gt;<br />detran2025.&lt;click|icu|lat|sbs&gt;<br />l1cenciamento-detran2025.&lt;click|icu|lat|sbs&gt;<br /> <br /><a href=\"https://infosec.exchange/tags/lookalikes\" class=\"mention hashtag\" rel=\"tag\">#<span>lookalikes</span></a> <a href=\"https://infosec.exchange/tags/dns\" class=\"mention hashtag\" rel=\"tag\">#<span>dns</span></a> <a href=\"https://infosec.exchange/tags/threatintel\" class=\"mention hashtag\" rel=\"tag\">#<span>threatintel</span></a> <a href=\"https://infosec.exchange/tags/cybercrime\" class=\"mention hashtag\" rel=\"tag\">#<span>cybercrime</span></a> <a href=\"https://infosec.exchange/tags/threatintelligence\" class=\"mention hashtag\" rel=\"tag\">#<span>threatintelligence</span></a> <a href=\"https://infosec.exchange/tags/cybersecurity\" class=\"mention hashtag\" rel=\"tag\">#<span>cybersecurity</span></a> <a href=\"https://infosec.exchange/tags/infoblox\" class=\"mention hashtag\" rel=\"tag\">#<span>infoblox</span></a> <a href=\"https://infosec.exchange/tags/infobloxthreatintel\" class=\"mention hashtag\" rel=\"tag\">#<span>infobloxthreatintel</span></a><br /> <br /><a href=\"https://urlscan.io/result/802374b7-6c8b-433b-b6e0-32561f74b7d3/\" target=\"_blank\" rel=\"nofollow noopener\" translate=\"no\"><span class=\"invisible\">https://</span><span class=\"ellipsis\">urlscan.io/result/802374b7-6c8</span><span class=\"invisible\">b-433b-b6e0-32561f74b7d3/</span></a><br /><a href=\"https://urlscan.io/result/721b12bb-d5fe-4c7e-b2b5-724e07aa22e0/\" target=\"_blank\" rel=\"nofollow noopener\" translate=\"no\"><span class=\"invisible\">https://</span><span class=\"ellipsis\">urlscan.io/result/721b12bb-d5f</span><span class=\"invisible\">e-4c7e-b2b5-724e07aa22e0/</span></a></p>" }, "attachment": [], "tag": [ { "type": "Hashtag", "href": "https://infosec.exchange/tags/lookalikes", "name": "#lookalikes" }, { "type": "Hashtag", "href": "https://infosec.exchange/tags/dns", "name": "#dns" }, { "type": "Hashtag", "href": "https://infosec.exchange/tags/threatintel", "name": "#threatintel" }, { "type": "Hashtag", "href": "https://infosec.exchange/tags/cybercrime", "name": "#cybercrime" }, { "type": "Hashtag", "href": "https://infosec.exchange/tags/threatintelligence", "name": "#threatintelligence" }, { "type": "Hashtag", "href": "https://infosec.exchange/tags/cybersecurity", "name": "#cybersecurity" }, { "type": "Hashtag", "href": "https://infosec.exchange/tags/infoblox", "name": "#infoblox" }, { "type": "Hashtag", "href": "https://infosec.exchange/tags/infobloxthreatintel", "name": "#infobloxthreatintel" } ], "replies": { "id": "https://infosec.exchange/users/InfobloxThreatIntel/statuses/114083807957414192/replies", "type": "Collection", "first": { "type": "CollectionPage", "next": "https://infosec.exchange/users/InfobloxThreatIntel/statuses/114083807957414192/replies?only_other_accounts=true&page=true", "partOf": "https://infosec.exchange/users/InfobloxThreatIntel/statuses/114083807957414192/replies", "items": [] } }, "likes": { "id": "https://infosec.exchange/users/InfobloxThreatIntel/statuses/114083807957414192/likes", "type": "Collection", "totalItems": 3 }, "shares": { "id": "https://infosec.exchange/users/InfobloxThreatIntel/statuses/114083807957414192/shares", "type": "Collection", "totalItems": 4 } }