{
    "1855000": [
        {
            "ioc_value": "rapidwavenet.verdalya.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 17:41:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854999": [
        {
            "ioc_value": "emwcx.kafekarachi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 17:36:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854998": [
        {
            "ioc_value": "hhqzk.stevestowingsatx.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 17:19:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854997": [
        {
            "ioc_value": "stevestowingsatx.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 17:18:37",
            "last_seen_utc": "2026-07-21 17:18:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854996": [
        {
            "ioc_value": "ivox.polarstartire.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 17:06:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854995": [
        {
            "ioc_value": "cbtlecmkc.nextbahis.one",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 17:05:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0xa770,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854994": [
        {
            "ioc_value": "151.243.137.78:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-07-21 17:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854993": [
        {
            "ioc_value": "106.52.255.211:8999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 17:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854991": [
        {
            "ioc_value": "8.152.201.69:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 17:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854992": [
        {
            "ioc_value": "8.152.201.69:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 17:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854989": [
        {
            "ioc_value": "t2yl06y1.letstalkrocks.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 16:36:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854988": [
        {
            "ioc_value": "letstalkrocks.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 16:35:40",
            "last_seen_utc": "2026-07-21 16:36:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854986": [
        {
            "ioc_value": "deltahostgate2.verdalya.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 16:26:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854985": [
        {
            "ioc_value": "jguzg.stashngrab.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 16:24:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854984": [
        {
            "ioc_value": "stashngrab.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 16:22:29",
            "last_seen_utc": "2026-07-21 16:22:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854983": [
        {
            "ioc_value": "twcw.playantwatch.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 16:06:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854982": [
        {
            "ioc_value": "103.142.147.19:5700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 16:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854981": [
        {
            "ioc_value": "8.152.201.69:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 16:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854977": [
        {
            "ioc_value": "hsdav.stable-virtual-camera.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 15:22:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854975": [
        {
            "ioc_value": "stable-virtual-camera.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 15:22:02",
            "last_seen_utc": "2026-07-21 15:22:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854974": [
        {
            "ioc_value": "ironlogicway5.florenth.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 15:11:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854973": [
        {
            "ioc_value": "nhos.pikachuplush.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 15:05:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854971": [
        {
            "ioc_value": "8.152.201.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 15:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854972": [
        {
            "ioc_value": "8.152.201.69:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 15:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854969": [
        {
            "ioc_value": "101.200.193.211:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 15:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854970": [
        {
            "ioc_value": "8.152.201.69:50001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 15:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854968": [
        {
            "ioc_value": "1.116.121.47:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 15:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854954": [
        {
            "ioc_value": "https://hur.luckyturbo88.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-21 14:40:05",
            "last_seen_utc": "2026-07-21 17:27:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854953": [
        {
            "ioc_value": "hur.luckyturbo88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-21 14:40:04",
            "last_seen_utc": "2026-07-21 17:27:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854952": [
        {
            "ioc_value": "r7e0hc30.legend-capital-group.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:37:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854947": [
        {
            "ioc_value": "77.42.90.175:9895",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-07-21 14:36:22",
            "last_seen_utc": "2026-07-21 15:09:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "758932669c2cccb72dce7588f8703839,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854948": [
        {
            "ioc_value": "62.171.177.27:2930",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-07-21 14:36:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0f81469cc7638ba7c82eaddbd6b3c20a,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854951": [
        {
            "ioc_value": "https://hur.aww88.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-21 14:35:05",
            "last_seen_utc": "2026-07-21 17:27:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854950": [
        {
            "ioc_value": "hur.aww88.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-21 14:35:04",
            "last_seen_utc": "2026-07-21 17:27:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854949": [
        {
            "ioc_value": "legend-capital-group.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:34:56",
            "last_seen_utc": "2026-07-21 14:35:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854946": [
        {
            "ioc_value": "ybsve.springhillcommons.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:26:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854945": [
        {
            "ioc_value": "springhillcommons.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:21:28",
            "last_seen_utc": "2026-07-21 14:21:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854944": [
        {
            "ioc_value": "udsik.springfieldsummerhoops.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:17:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854943": [
        {
            "ioc_value": "springfieldsummerhoops.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:16:27",
            "last_seen_utc": "2026-07-21 14:17:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854942": [
        {
            "ioc_value": "nrqbf.spencershorttexas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:13:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854941": [
        {
            "ioc_value": "spencershorttexas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:12:49",
            "last_seen_utc": "2026-07-21 14:12:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854940": [
        {
            "ioc_value": "cppeh.spacedecorideas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:09:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854939": [
        {
            "ioc_value": "spacedecorideas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:08:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854937": [
        {
            "ioc_value": "47.99.102.231:8020",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 14:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854938": [
        {
            "ioc_value": "47.99.102.231:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 14:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854935": [
        {
            "ioc_value": "47.99.102.231:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 14:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854936": [
        {
            "ioc_value": "47.99.102.231:7010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 14:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854934": [
        {
            "ioc_value": "47.99.102.231:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854933": [
        {
            "ioc_value": "mvjx.phtaxiservices.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 14:04:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854913": [
        {
            "ioc_value": "api.googlevv.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 13:54:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "GovCERT_CH"
        }
    ],
    "1854914": [
        {
            "ioc_value": "analyzer01.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 13:54:47",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "GovCERT_CH"
        }
    ],
    "1854917": [
        {
            "ioc_value": "https://pub-7ac99e69d5af40ffa345a3f731c1b833.r2.dev/tz.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 13:54:47",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "GovCERT_CH"
        }
    ],
    "1854925": [
        {
            "ioc_value": "moorlandatlas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 13:54:46",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/domain/moorlandatlas.com",
            "tags": "clickfix,curl,hetzner,loader,mshta",
            "anonymous": 0,
            "reporter": "Lenny3BO"
        }
    ],
    "1854926": [
        {
            "ioc_value": "5.161.192.203:443",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 13:54:45",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/domain/moorlandatlas.com",
            "tags": "clickfix,curl,hetzner,loader,mshta",
            "anonymous": 0,
            "reporter": "Lenny3BO"
        }
    ],
    "1854932": [
        {
            "ioc_value": "http://fimmora.surf:6504",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-07-21 13:40:51",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f3156f37607b62971c65a95cd5bd186d2d85194cb74119d558526f97424ff238/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854931": [
        {
            "ioc_value": "w3jxkd42.jardins-do-mar.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:38:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854930": [
        {
            "ioc_value": "pmzvrv9c.ezgarageautorepairtx.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:36:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854929": [
        {
            "ioc_value": "ezgarageautorepairtx.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:33:49",
            "last_seen_utc": "2026-07-21 13:33:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854928": [
        {
            "ioc_value": "kori1903.anondns.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:30:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClearFake,ScreenConnect",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854927": [
        {
            "ioc_value": "213.232.235.51:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:29:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClearFake,ScreenConnect",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854924": [
        {
            "ioc_value": "jqtzbyimn.hrmotorsspringville.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:14:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0xa770,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854923": [
        {
            "ioc_value": "https://omnia360.de/reCAPTCHA.hta",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:13:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854922": [
        {
            "ioc_value": "https://www.diction.ch/wp-content/uploads/2026/07/ScreenConnect.ClientSetup.msi",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:13:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854921": [
        {
            "ioc_value": "hrmotorsspringville.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:13:22",
            "last_seen_utc": "2026-07-21 13:13:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854920": [
        {
            "ioc_value": "kdlff.riggsjacksboro.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:13:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854919": [
        {
            "ioc_value": "riggsjacksboro.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:08:01",
            "last_seen_utc": "2026-07-21 13:09:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854918": [
        {
            "ioc_value": "izhx.phimmoichilla.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 13:07:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854915": [
        {
            "ioc_value": "47.99.102.231:8010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854916": [
        {
            "ioc_value": "47.99.102.231:7000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854912": [
        {
            "ioc_value": "6t7fjqk7.laurelcrownpartners.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 12:36:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854911": [
        {
            "ioc_value": "laurelcrownpartners.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 12:34:26",
            "last_seen_utc": "2026-07-21 12:34:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854910": [
        {
            "ioc_value": "https://datarecoverycenterbd.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-21 12:15:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854909": [
        {
            "ioc_value": "eumlu.ridgerenovation.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 12:08:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854908": [
        {
            "ioc_value": "ridgerenovation.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 12:07:45",
            "last_seen_utc": "2026-07-21 12:07:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854907": [
        {
            "ioc_value": "wwmf.patxisdublin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 12:05:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854905": [
        {
            "ioc_value": "43.155.169.245:110",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 12:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854906": [
        {
            "ioc_value": "47.99.102.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 12:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854903": [
        {
            "ioc_value": "152.136.253.101:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 12:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854904": [
        {
            "ioc_value": "152.136.253.101:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 12:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854902": [
        {
            "ioc_value": "152.136.253.101:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 12:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854899": [
        {
            "ioc_value": "45.76.182.55:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 12:00:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854900": [
        {
            "ioc_value": "207.148.66.2:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 12:00:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854901": [
        {
            "ioc_value": "ordereltacofeliz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 12:00:36",
            "last_seen_utc": "2026-07-21 12:01:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854898": [
        {
            "ioc_value": "embermeshnode.florenth.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 11:26:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854897": [
        {
            "ioc_value": "qrilb.rickybobbystowing.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 11:07:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854896": [
        {
            "ioc_value": "rickybobbystowing.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 11:07:12",
            "last_seen_utc": "2026-07-21 11:07:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854895": [
        {
            "ioc_value": "152.136.253.101:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 11:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854893": [
        {
            "ioc_value": "120.76.143.184:23333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 11:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854894": [
        {
            "ioc_value": "152.136.253.101:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 11:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854892": [
        {
            "ioc_value": "120.26.208.96:61001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 11:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854891": [
        {
            "ioc_value": "82.156.155.15:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-07-21 11:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854890": [
        {
            "ioc_value": "5.101.84.75:4242",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.purelogs",
            "malware_alias": null,
            "malware_printable": "PureLogs Stealer",
            "first_seen_utc": "2026-07-21 11:04:09",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/af0afca585caa54140a6673622f2d2093dd5e76eb7b71d428e3893c130cf1f8b/",
            "tags": "PureLogsStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854889": [
        {
            "ioc_value": "uxwc.orangefarmersmarket.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 11:00:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854888": [
        {
            "ioc_value": "orangefarmersmarket.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 10:59:52",
            "last_seen_utc": "2026-07-21 11:00:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854869": [
        {
            "ioc_value": "https://markdl.pro/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 10:52:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/markdl.pro",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1854872": [
        {
            "ioc_value": "149.28.128.253:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 10:52:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854873": [
        {
            "ioc_value": "45.76.146.2:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 10:52:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854885": [
        {
            "ioc_value": "4.144.235.121:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-21 10:52:01",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854887": [
        {
            "ioc_value": "contabili.balanteo.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-21 10:40:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/3565a7a2bb632357c35f6ca9e98eb083e1505526f0ab0e4d88df216299540069/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854886": [
        {
            "ioc_value": "oyawba10.site-asli-bedon-filter-1xbet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 10:36:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854884": [
        {
            "ioc_value": "lufry.mabelsnursery.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 10:17:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854883": [
        {
            "ioc_value": "mabelsnursery.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 10:15:49",
            "last_seen_utc": "2026-07-21 10:15:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854882": [
        {
            "ioc_value": "https://cldaa.org/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-21 10:15:02",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854880": [
        {
            "ioc_value": "120.26.208.96:33060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 10:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854881": [
        {
            "ioc_value": "120.26.208.96:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 10:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854879": [
        {
            "ioc_value": "120.26.208.96:61004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 10:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854878": [
        {
            "ioc_value": "117.72.39.83:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 10:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854877": [
        {
            "ioc_value": "ayhd.opulentbeautybarllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 10:00:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854876": [
        {
            "ioc_value": "opulentbeautybarllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 09:59:22",
            "last_seen_utc": "2026-07-21 09:59:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854875": [
        {
            "ioc_value": "hbsgb.lunabybodyshaping.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 09:58:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854874": [
        {
            "ioc_value": "lunabybodyshaping.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 09:58:10",
            "last_seen_utc": "2026-07-21 09:58:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854871": [
        {
            "ioc_value": "185.33.86.141:29292",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-21 09:44:16",
            "last_seen_utc": "2026-07-21 17:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854870": [
        {
            "ioc_value": "alkociferblat.cc",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 09:37:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854867": [
        {
            "ioc_value": "124.220.77.21:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 09:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854868": [
        {
            "ioc_value": "47.236.204.56:19999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-07-21 09:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854866": [
        {
            "ioc_value": "47.108.140.10:20885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 09:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854865": [
        {
            "ioc_value": "43.165.188.19:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 09:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854864": [
        {
            "ioc_value": "43.155.169.245:5353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 09:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854863": [
        {
            "ioc_value": "twhhp.lucymflowers.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 09:02:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854862": [
        {
            "ioc_value": "cyyf.nurtured-in-nature.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 09:01:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854861": [
        {
            "ioc_value": "nurtured-in-nature.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:58:49",
            "last_seen_utc": "2026-07-21 08:58:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854860": [
        {
            "ioc_value": "lucymflowers.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:57:34",
            "last_seen_utc": "2026-07-21 08:57:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854854": [
        {
            "ioc_value": "156.234.7.21:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-21 08:38:49",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854859": [
        {
            "ioc_value": "87jcg6w8.everestpointnorthglenn.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:36:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854858": [
        {
            "ioc_value": "zbklcsro.jadoou.lat",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:35:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854857": [
        {
            "ioc_value": "v23ewcsy.calculadoracomisiones.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:35:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854856": [
        {
            "ioc_value": "drrobertoiturralde.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:34:02",
            "last_seen_utc": "2026-07-21 08:35:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854855": [
        {
            "ioc_value": "everestpointnorthglenn.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:33:52",
            "last_seen_utc": "2026-07-21 08:33:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854853": [
        {
            "ioc_value": "cjdl.nspowdercoatingnj.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:28:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854852": [
        {
            "ioc_value": "nspowdercoatingnj.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:24:36",
            "last_seen_utc": "2026-07-21 08:25:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854851": [
        {
            "ioc_value": "mhuhx.longhornlodgemo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:22:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854850": [
        {
            "ioc_value": "xbzh.kafekarachi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:22:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854849": [
        {
            "ioc_value": "longhornlodgemo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 08:22:34",
            "last_seen_utc": "2026-07-21 08:22:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854819": [
        {
            "ioc_value": "167.172.80.107:12345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 08:20:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854848": [
        {
            "ioc_value": "47.108.140.10:20881",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 08:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854787": [
        {
            "ioc_value": "gbgl.kafekarachi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 07:28:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854786": [
        {
            "ioc_value": "qbmuv.loganlooneyresume.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 07:26:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854785": [
        {
            "ioc_value": "loganlooneyresume.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 07:21:23",
            "last_seen_utc": "2026-07-21 07:22:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854784": [
        {
            "ioc_value": "94.26.83.138:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 07:20:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9ceeacd7f64359972fc44c73798a4e215effeff4bda4f6e309bedc67bc0c8d38/",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854782": [
        {
            "ioc_value": "94.26.83.138:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 07:20:33",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9ceeacd7f64359972fc44c73798a4e215effeff4bda4f6e309bedc67bc0c8d38/",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854783": [
        {
            "ioc_value": "94.26.83.138:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 07:20:33",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9ceeacd7f64359972fc44c73798a4e215effeff4bda4f6e309bedc67bc0c8d38/",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854781": [
        {
            "ioc_value": "https://ets.luckyturbo88.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-21 07:20:05",
            "last_seen_utc": "2026-07-21 14:27:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854780": [
        {
            "ioc_value": "ets.luckyturbo88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-21 07:20:04",
            "last_seen_utc": "2026-07-21 14:27:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854779": [
        {
            "ioc_value": "tmnpc.lnlsealcoating.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 07:13:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854778": [
        {
            "ioc_value": "94.198.96.165:63921",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-07-21 07:10:00",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c937d0408fb8ef89b00c2fbcd785ade967210df57b0c5a128d2555b431d4634e/",
            "tags": "LxBaseRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854777": [
        {
            "ioc_value": "lnlsealcoating.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 07:08:07",
            "last_seen_utc": "2026-07-21 07:08:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854776": [
        {
            "ioc_value": "46.151.182.127:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-21 07:05:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ce81e2c7d1beb834bda8a59ac5cd23b9b2700a697dad0358f5837df214af995d/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854775": [
        {
            "ioc_value": "43.165.188.19:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854774": [
        {
            "ioc_value": "43.165.188.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 07:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854773": [
        {
            "ioc_value": "https://ets.aww88.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-21 07:00:08",
            "last_seen_utc": "2026-07-21 14:27:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854772": [
        {
            "ioc_value": "ets.aww88.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-21 07:00:07",
            "last_seen_utc": "2026-07-21 14:27:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854771": [
        {
            "ioc_value": "markdl.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 06:56:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854770": [
        {
            "ioc_value": "202.61.160.189:8383",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcom",
            "malware_alias": "RemoteCommandExecution",
            "malware_printable": "RemCom",
            "first_seen_utc": "2026-07-21 06:55:09",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/af2ddbb1342c32efb23134f2a40d1ad390e85f57296c3dee753c99f867fc0ef2/",
            "tags": "RemCom",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854768": [
        {
            "ioc_value": "ironphantomcore.top",
            "ioc_type": "domain",
            "threat_type": "cc_skimming",
            "malware": "js.magecart",
            "malware_alias": null,
            "malware_printable": "magecart",
            "first_seen_utc": "2026-07-21 06:52:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Magecart",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854769": [
        {
            "ioc_value": "voidhunterkeep.top",
            "ioc_type": "domain",
            "threat_type": "cc_skimming",
            "malware": "js.magecart",
            "malware_alias": null,
            "malware_printable": "magecart",
            "first_seen_utc": "2026-07-21 06:52:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Magecart",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854767": [
        {
            "ioc_value": "http://196.251.107.186/api.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 06:50:09",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/573e68608bbbf05cd7364eb791141deb3daba35b3098d23a047ac66979c75be1/",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854766": [
        {
            "ioc_value": "141.98.10.188:52535",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.purelogs",
            "malware_alias": null,
            "malware_printable": "PureLogs Stealer",
            "first_seen_utc": "2026-07-21 06:47:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b8eca270e07e96f414a4a5ff00c099f1518a9d10ca2f1a4c69800e37b9699fea/",
            "tags": "PureLogsStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854765": [
        {
            "ioc_value": "192.169.7.60:7000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-07-21 06:45:25",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9e1c3817c2b4f5aff5b8ed5288fca53df1ad392022c2fa3b609e0103ec2ae08e/",
            "tags": "XWorm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854764": [
        {
            "ioc_value": "7wzfqmf9.behtarin-site-shartbandi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 06:36:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854763": [
        {
            "ioc_value": "ynwe.jetourmexico.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 06:31:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854762": [
        {
            "ioc_value": "mqljf.newcoservicemower.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 06:30:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854761": [
        {
            "ioc_value": "newcoservicemower.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 06:25:58",
            "last_seen_utc": "2026-07-21 06:26:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854760": [
        {
            "ioc_value": "tourtrade.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.phantom_stealer",
            "malware_alias": null,
            "malware_printable": "Phantom Stealer",
            "first_seen_utc": "2026-07-21 06:14:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2cd6897845961d94d058970266728a7abb4d6fdaff48bb295acdb912dfac9f89/",
            "tags": "PhantomStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854759": [
        {
            "ioc_value": "5.101.84.80:8996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.purelogs",
            "malware_alias": null,
            "malware_printable": "PureLogs Stealer",
            "first_seen_utc": "2026-07-21 06:09:18",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/372d9cfbabe8c80e2b152739ea9ff7debe61b88360e3120c35832738400955df/",
            "tags": "PureLogsStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854758": [
        {
            "ioc_value": "188.132.242.67:7329",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-21 06:06:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/5666f35c1033e019aa4d31dc7c123e39777909e2833e14135f9a3f3642551059/",
            "tags": "Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854757": [
        {
            "ioc_value": "anyqwp6fce.localto.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-21 06:06:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/5666f35c1033e019aa4d31dc7c123e39777909e2833e14135f9a3f3642551059/",
            "tags": "Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854755": [
        {
            "ioc_value": "43.155.169.245:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 06:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854756": [
        {
            "ioc_value": "43.155.169.245:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 06:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854754": [
        {
            "ioc_value": "101.33.76.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 06:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854753": [
        {
            "ioc_value": "46.151.182.159:776",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.purelogs",
            "malware_alias": null,
            "malware_printable": "PureLogs Stealer",
            "first_seen_utc": "2026-07-21 06:03:41",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/5a9ed64a27630a5a35e02d4659efab2e6485b394377a3ae7df4b556959f63fb3/",
            "tags": "PureLogsStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854752": [
        {
            "ioc_value": "lifeisabouthavingfun448.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-07-21 05:59:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1cf3a473824ecd73dd246db96a9a11a3b094cf1052a085f86fa5327f550eecdf/",
            "tags": "Gafgyt",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854751": [
        {
            "ioc_value": "185.196.41.201:35342",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-07-21 05:58:30",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Gafgyt",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854737": [
        {
            "ioc_value": "162.243.163.143:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 05:55:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854750": [
        {
            "ioc_value": "141.11.243.110:586",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "jar.strrat",
            "malware_alias": null,
            "malware_printable": "STRRAT",
            "first_seen_utc": "2026-07-21 05:54:13",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/cc75bd30c623f080ee5dd003c2802a9c97a008f9fd6f4a1c4113a27b1242d290/",
            "tags": "RAT,STRRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854748": [
        {
            "ioc_value": "209.99.186.11:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:52:24",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854749": [
        {
            "ioc_value": "209.99.186.11:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:52:24",
            "last_seen_utc": "2026-07-21 05:52:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854747": [
        {
            "ioc_value": "162.251.120.10:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:50:38",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854739": [
        {
            "ioc_value": "135.136.144.95:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:50:37",
            "last_seen_utc": "2026-07-21 05:50:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854740": [
        {
            "ioc_value": "135.136.144.95:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:50:37",
            "last_seen_utc": "2026-07-21 05:50:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854741": [
        {
            "ioc_value": "135.136.144.95:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:50:37",
            "last_seen_utc": "2026-07-21 05:50:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854742": [
        {
            "ioc_value": "38.92.47.237:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:50:37",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854743": [
        {
            "ioc_value": "38.92.47.237:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:50:37",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854744": [
        {
            "ioc_value": "38.92.47.237:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:50:37",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854745": [
        {
            "ioc_value": "162.251.120.10:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:50:37",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854746": [
        {
            "ioc_value": "162.251.120.10:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:50:37",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854738": [
        {
            "ioc_value": "198.37.105.33:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-21 05:47:56",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854736": [
        {
            "ioc_value": "31.76.252.47:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:46:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/566cc087706f3d3a0e49b9a1d9c8e27090211d80a069162de2e5e8a5b8847414/",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854735": [
        {
            "ioc_value": "https://31.76.252.47/v1/telemetry/config",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:46:41",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/566cc087706f3d3a0e49b9a1d9c8e27090211d80a069162de2e5e8a5b8847414/",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854734": [
        {
            "ioc_value": "wormfear.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-21 05:42:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "OffLoader",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854733": [
        {
            "ioc_value": "173.225.99.250:15500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:36:56",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854732": [
        {
            "ioc_value": "monitorondomainwintgt.store",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:36:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854731": [
        {
            "ioc_value": "157.20.182.81:425",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-07-21 05:35:20",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854730": [
        {
            "ioc_value": "ewmc.jenslittlerugrats.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 05:28:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854729": [
        {
            "ioc_value": "jpsym.mystic-brews.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 05:27:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854728": [
        {
            "ioc_value": "mystic-brews.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 05:25:19",
            "last_seen_utc": "2026-07-21 05:26:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854567": [
        {
            "ioc_value": "ritchie.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:58",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854568": [
        {
            "ioc_value": "meduurst.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:58",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854569": [
        {
            "ioc_value": "monteiro.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:57",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854570": [
        {
            "ioc_value": "bitista.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854571": [
        {
            "ioc_value": "thibahlt.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:55",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854572": [
        {
            "ioc_value": "leconto.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854573": [
        {
            "ioc_value": "carreiro.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854574": [
        {
            "ioc_value": "henreques.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:51",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854575": [
        {
            "ioc_value": "fraitas.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:50",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854576": [
        {
            "ioc_value": "azevedo.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:49",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854577": [
        {
            "ioc_value": "schester.beer",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:49",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854578": [
        {
            "ioc_value": "abernaahy.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854579": [
        {
            "ioc_value": "riviere.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:47",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854580": [
        {
            "ioc_value": "ackeamann.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:43",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854582": [
        {
            "ioc_value": "lombaidi.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:42",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854581": [
        {
            "ioc_value": "robests.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:41",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854583": [
        {
            "ioc_value": "reindardt.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854584": [
        {
            "ioc_value": "schuttc.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:39",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854585": [
        {
            "ioc_value": "bogisibh.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:38",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854586": [
        {
            "ioc_value": "ledesla.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:37",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854587": [
        {
            "ioc_value": "uolguin.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:36",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854588": [
        {
            "ioc_value": "olovier.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854589": [
        {
            "ioc_value": "chauvet.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854590": [
        {
            "ioc_value": "gautter.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:32",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854591": [
        {
            "ioc_value": "riihard.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:31",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854592": [
        {
            "ioc_value": "nonrueden.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:31",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854593": [
        {
            "ioc_value": "northcombe.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:30",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854594": [
        {
            "ioc_value": "omnivectis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:29",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854595": [
        {
            "ioc_value": "willimsen.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:26",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854596": [
        {
            "ioc_value": "ssntana.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:26",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854597": [
        {
            "ioc_value": "fundivox.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:24",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854598": [
        {
            "ioc_value": "exoosito.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854599": [
        {
            "ioc_value": "oelgado.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:22",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854600": [
        {
            "ioc_value": "nitzschi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:22",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854601": [
        {
            "ioc_value": "vtcircuits.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:21",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854602": [
        {
            "ioc_value": "satserfield.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:20",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854603": [
        {
            "ioc_value": "quilborne.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:20",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854604": [
        {
            "ioc_value": "quiglgy.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854605": [
        {
            "ioc_value": "kovkcek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:18",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854606": [
        {
            "ioc_value": "gccsinc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:17",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854607": [
        {
            "ioc_value": "barsows.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:16",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854608": [
        {
            "ioc_value": "ethervane.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:15",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854609": [
        {
            "ioc_value": "raventhorp.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:15",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854610": [
        {
            "ioc_value": "bradtkr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:14",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854611": [
        {
            "ioc_value": "dialectum.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:13",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854612": [
        {
            "ioc_value": "oakington.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:13",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854613": [
        {
            "ioc_value": "quorumix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:12",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854614": [
        {
            "ioc_value": "saxonfield.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:11",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854615": [
        {
            "ioc_value": "sigmatauethifarma.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:11",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854616": [
        {
            "ioc_value": "hegmaen.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:10",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854617": [
        {
            "ioc_value": "orantow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:09",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854618": [
        {
            "ioc_value": "gileert.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:08",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854619": [
        {
            "ioc_value": "bartach.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:07",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854620": [
        {
            "ioc_value": "almontm.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:06",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854621": [
        {
            "ioc_value": "moielli.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:03",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854622": [
        {
            "ioc_value": "corraia.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:02",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854623": [
        {
            "ioc_value": "henriqueq.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:21:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854624": [
        {
            "ioc_value": "bbvalues.uk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854625": [
        {
            "ioc_value": "treviro.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:57",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854626": [
        {
            "ioc_value": "eichmnnn.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854627": [
        {
            "ioc_value": "gerrirsen.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:55",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854628": [
        {
            "ioc_value": "diranda.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:55",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854629": [
        {
            "ioc_value": "loureiru.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854630": [
        {
            "ioc_value": "bernardi.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854631": [
        {
            "ioc_value": "marqueq.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:51",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854632": [
        {
            "ioc_value": "abernaehy.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:50",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854633": [
        {
            "ioc_value": "keneedy.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:49",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854634": [
        {
            "ioc_value": "reynoldy.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854635": [
        {
            "ioc_value": "heethcote.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854636": [
        {
            "ioc_value": "okunevk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:46",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854637": [
        {
            "ioc_value": "dground.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:45",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854638": [
        {
            "ioc_value": "meharsons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854639": [
        {
            "ioc_value": "leusceke.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:43",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854640": [
        {
            "ioc_value": "zgsjyxzx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:42",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854641": [
        {
            "ioc_value": "luthel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:42",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854642": [
        {
            "ioc_value": "jnlysj.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-21 05:20:41",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1854643": [
        {
            "ioc_value": "https://www.studiotecnicoareanova.it/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www.studiotecnicoareanova.it",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1854658": [
        {
            "ioc_value": "137.184.135.42:37215",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 05:20:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854668": [
        {
            "ioc_value": "149.28.128.253:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 05:20:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854534": [
        {
            "ioc_value": "testewin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:25",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/",
            "tags": "BananaRAT,banking-trojan,BL-Networks,brazil,cloudflare-tunnel,powershell",
            "anonymous": 0,
            "reporter": "DENNISAROSS"
        }
    ],
    "1854535": [
        {
            "ioc_value": "149.56.12.51:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:24",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/",
            "tags": "BananaRAT,banking-trojan,BL-Networks,brazil,powershell",
            "anonymous": 0,
            "reporter": "DENNISAROSS"
        }
    ],
    "1854536": [
        {
            "ioc_value": "162.33.178.68:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/",
            "tags": "BananaRAT,banking-trojan,BL-Networks,brazil,powershell",
            "anonymous": 0,
            "reporter": "DENNISAROSS"
        }
    ],
    "1854537": [
        {
            "ioc_value": "http://162.33.178.68/msedge.txt",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:22",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": true,
            "reference": "https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/",
            "tags": "BananaRAT,banking-trojan,BL-Networks,brazil,masquerading,powershell",
            "anonymous": 0,
            "reporter": "DENNISAROSS"
        }
    ],
    "1854544": [
        {
            "ioc_value": "206.166.251.123:8591",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:20",
            "last_seen_utc": null,
            "confidence_level": 70,
            "is_compromised": true,
            "reference": null,
            "tags": "BL-Networks,credential-market,darknet,Kraken-market,Tor-client",
            "anonymous": 0,
            "reporter": "DENNISAROSS"
        }
    ],
    "1854543": [
        {
            "ioc_value": "45.76.182.55:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 05:20:19",
            "last_seen_utc": "2026-07-21 09:52:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854547": [
        {
            "ioc_value": "64.52.80.235:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:17",
            "last_seen_utc": null,
            "confidence_level": 70,
            "is_compromised": true,
            "reference": null,
            "tags": "BL-Networks,cross-platform,homebrew-lure,JAR,java,payload-delivery",
            "anonymous": 0,
            "reporter": "DENNISAROSS"
        }
    ],
    "1854548": [
        {
            "ioc_value": "hometwfrbas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:16",
            "last_seen_utc": null,
            "confidence_level": 70,
            "is_compromised": true,
            "reference": null,
            "tags": "BL-Networks,cross-platform,DGA-style-domain,homebrew-lure,JAR,java,payload-delivery",
            "anonymous": 0,
            "reporter": "DENNISAROSS"
        }
    ],
    "1854549": [
        {
            "ioc_value": "149.28.128.253:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 05:20:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854559": [
        {
            "ioc_value": "https://www.fluorite.eu/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www.fluorite.eu",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1854563": [
        {
            "ioc_value": "45.61.136.49:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:12",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": true,
            "reference": null,
            "tags": "AMOS,AtomicStealer,BL-Networks,Mach-O,macOS,payload-delivery",
            "anonymous": 0,
            "reporter": "DENNISAROSS"
        }
    ],
    "1854562": [
        {
            "ioc_value": "ebaa6717e0011710c3cc8f4b2fd7fb767a3a0e4d01415957d9b24919650a7a09",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-07-21 05:20:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "dll,sideloading,stealer,vidar",
            "anonymous": 0,
            "reporter": "emmpallis"
        }
    ],
    "1854530": [
        {
            "ioc_value": "193.149.187.77:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:01",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "BL-Networks,BlankGrabber,PyInstaller,python,stealer",
            "anonymous": 0,
            "reporter": "DENNISAROSS"
        }
    ],
    "1854531": [
        {
            "ioc_value": "http://193.149.187.77/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:20:00",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "BL-Networks,BlankGrabber,open-directory,PyInstaller,python,stealer",
            "anonymous": 0,
            "reporter": "DENNISAROSS"
        }
    ],
    "1854532": [
        {
            "ioc_value": "https://theprosperinghouse.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:19:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/theprosperinghouse.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1854533": [
        {
            "ioc_value": "https://theholecompany.net/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 05:19:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/theholecompany.net",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1854528": [
        {
            "ioc_value": "logintrust5845.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.mints_loader",
            "malware_alias": null,
            "malware_printable": "MintsLoader",
            "first_seen_utc": "2026-07-21 05:19:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://tria.ge/260720-w22dqsc13x/behavioral1",
            "tags": "clickfix,MINTSLOADER",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1854527": [
        {
            "ioc_value": "syshash4392.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.mints_loader",
            "malware_alias": null,
            "malware_printable": "MintsLoader",
            "first_seen_utc": "2026-07-21 05:19:52",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://tria.ge/260720-w22dqsc13x/behavioral1",
            "tags": "clickfix,MINTSLOADER",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1854526": [
        {
            "ioc_value": "authservice6020.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.mints_loader",
            "malware_alias": null,
            "malware_printable": "MintsLoader",
            "first_seen_utc": "2026-07-21 05:19:51",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://tria.ge/260720-w22dqsc13x/behavioral1",
            "tags": "clickfix,MINTSLOADER",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1854525": [
        {
            "ioc_value": "portalbyte8345.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.mints_loader",
            "malware_alias": null,
            "malware_printable": "MintsLoader",
            "first_seen_utc": "2026-07-21 05:19:50",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://tria.ge/260720-w22dqsc13x/behavioral1",
            "tags": "clickfix,MINTSLOADER",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1854524": [
        {
            "ioc_value": "webtask6566.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.mints_loader",
            "malware_alias": null,
            "malware_printable": "MintsLoader",
            "first_seen_utc": "2026-07-21 05:19:49",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://tria.ge/260720-w22dqsc13x/behavioral1",
            "tags": "clickfix,MINTSLOADER",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1854523": [
        {
            "ioc_value": "apibyte4811.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.mints_loader",
            "malware_alias": null,
            "malware_printable": "MintsLoader",
            "first_seen_utc": "2026-07-21 05:19:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://tria.ge/260720-w22dqsc13x/behavioral1",
            "tags": "clickfix,MINTSLOADER",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1854522": [
        {
            "ioc_value": "statpass3183.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.mints_loader",
            "malware_alias": null,
            "malware_printable": "MintsLoader",
            "first_seen_utc": "2026-07-21 05:19:47",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://tria.ge/260720-w22dqsc13x/behavioral1",
            "tags": "clickfix,MINTSLOADER",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1854521": [
        {
            "ioc_value": "1629bqt9p34elwv.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.mints_loader",
            "malware_alias": null,
            "malware_printable": "MintsLoader",
            "first_seen_utc": "2026-07-21 05:19:45",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://tria.ge/260720-w22dqsc13x/behavioral1",
            "tags": "clickfix,MINTSLOADER",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1854520": [
        {
            "ioc_value": "basehex1267.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.mints_loader",
            "malware_alias": null,
            "malware_printable": "MintsLoader",
            "first_seen_utc": "2026-07-21 05:19:44",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://tria.ge/260720-w22dqsc13x/behavioral1",
            "tags": "clickfix,MINTSLOADER",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1854717": [
        {
            "ioc_value": "162.243.163.143:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-21 05:18:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854726": [
        {
            "ioc_value": "103.43.18.230:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 05:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854727": [
        {
            "ioc_value": "8.133.197.201:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-21 05:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854725": [
        {
            "ioc_value": "103.43.18.230:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 05:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854724": [
        {
            "ioc_value": "195.242.118.106:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-21 05:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854723": [
        {
            "ioc_value": "bopyq.myhillcountrygrass.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 04:43:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854722": [
        {
            "ioc_value": "myhillcountrygrass.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 04:38:22",
            "last_seen_utc": "2026-07-21 04:38:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854721": [
        {
            "ioc_value": "hvao.jbgroup21.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 04:35:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854720": [
        {
            "ioc_value": "1s3hqwvr.varzeshlife.ir",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 04:32:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854719": [
        {
            "ioc_value": "byrio.muscle-up-yavne.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 04:15:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854718": [
        {
            "ioc_value": "muscle-up-yavne.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 04:12:19",
            "last_seen_utc": "2026-07-21 04:12:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854716": [
        {
            "ioc_value": "101.42.255.92:222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 04:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854715": [
        {
            "ioc_value": "195.242.118.106:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-21 04:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854714": [
        {
            "ioc_value": "ndpyt.mechanic-on-site.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 04:04:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854713": [
        {
            "ioc_value": "mechanic-on-site.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 03:59:16",
            "last_seen_utc": "2026-07-21 03:59:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854704": [
        {
            "ioc_value": "avfzq.maia-bentley.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 03:42:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854698": [
        {
            "ioc_value": "ewyjl357.flashhomebuyerskc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 03:38:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854696": [
        {
            "ioc_value": "maia-bentley.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 03:37:50",
            "last_seen_utc": "2026-07-21 03:38:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854695": [
        {
            "ioc_value": "iahg2idr.evansunitedspringcarnivalsherman.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 03:36:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854692": [
        {
            "ioc_value": "flashhomebuyerskc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 03:34:06",
            "last_seen_utc": "2026-07-21 03:34:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854691": [
        {
            "ioc_value": "drburgymicrobiome.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 03:33:56",
            "last_seen_utc": "2026-07-21 03:34:02",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854689": [
        {
            "ioc_value": "evansunitedspringcarnivalsherman.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 03:32:52",
            "last_seen_utc": "2026-07-21 03:33:55",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854688": [
        {
            "ioc_value": "gytm.onjabet1.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 03:31:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854686": [
        {
            "ioc_value": "195.242.118.106:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-21 03:05:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854687": [
        {
            "ioc_value": "195.242.118.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-21 03:05:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854685": [
        {
            "ioc_value": "8.137.149.67:3443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 03:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854684": [
        {
            "ioc_value": "8.137.149.67:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 03:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854683": [
        {
            "ioc_value": "47.94.162.43:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 03:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854682": [
        {
            "ioc_value": "foivs.highkickstkd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 02:42:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854677": [
        {
            "ioc_value": "xhtn.nextbahis.one",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 02:29:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854676": [
        {
            "ioc_value": "luy6lvmh.site-takhtenard-sharti-betland.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 02:28:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854672": [
        {
            "ioc_value": "8.137.149.67:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 02:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854671": [
        {
            "ioc_value": "101.200.193.211:44322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 02:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854662": [
        {
            "ioc_value": "ikkqh.dermexcel.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 01:32:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854661": [
        {
            "ioc_value": "dermexcel.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 01:31:39",
            "last_seen_utc": "2026-07-21 01:31:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854660": [
        {
            "ioc_value": "jilc.kaltourusa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 01:30:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854659": [
        {
            "ioc_value": "kaltourusa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 01:28:47",
            "last_seen_utc": "2026-07-21 01:29:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854657": [
        {
            "ioc_value": "cstee.diamonddumpsterrental.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 01:23:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854656": [
        {
            "ioc_value": "diamonddumpsterrental.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 01:21:13",
            "last_seen_utc": "2026-07-21 01:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854655": [
        {
            "ioc_value": "8.163.49.50:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 01:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854653": [
        {
            "ioc_value": "47.94.162.43:111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 01:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854654": [
        {
            "ioc_value": "8.163.49.50:3389",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 01:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854652": [
        {
            "ioc_value": "47.94.162.43:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 01:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854651": [
        {
            "ioc_value": "xdox.groeschelcompany.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 00:33:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854650": [
        {
            "ioc_value": "dgctf.concretewestgj.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 00:32:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854649": [
        {
            "ioc_value": "yeo0jmkq.kimsnailsalonmadison.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 00:26:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854648": [
        {
            "ioc_value": "kimsnailsalonmadison.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-21 00:25:35",
            "last_seen_utc": "2026-07-21 00:25:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "21July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854647": [
        {
            "ioc_value": "47.94.162.43:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 00:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854645": [
        {
            "ioc_value": "117.72.39.83:21",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 00:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854646": [
        {
            "ioc_value": "47.236.130.154:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 00:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854644": [
        {
            "ioc_value": "117.72.175.125:15000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 00:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854566": [
        {
            "ioc_value": "ovzdi.jetbet.download",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 23:41:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854565": [
        {
            "ioc_value": "gjwc.kalientestore.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 23:28:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854564": [
        {
            "ioc_value": "kalientestore.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 23:27:31",
            "last_seen_utc": "2026-07-20 23:27:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854560": [
        {
            "ioc_value": "154.12.86.154:8003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 23:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854561": [
        {
            "ioc_value": "47.236.130.154:2052",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 23:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854558": [
        {
            "ioc_value": "mlmgp.jenslittlerugrats.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 22:37:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854557": [
        {
            "ioc_value": "dwvygj31.dermatologycongress.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 22:37:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854556": [
        {
            "ioc_value": "jenslittlerugrats.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 22:35:40",
            "last_seen_utc": "2026-07-21 05:26:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854555": [
        {
            "ioc_value": "h51ee0ex.emeraldualzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 22:35:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854554": [
        {
            "ioc_value": "designfarmarchitects.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 22:33:21",
            "last_seen_utc": "2026-07-20 22:33:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854553": [
        {
            "ioc_value": "4gfsvs7l.jennyrussianbluepalace.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 22:28:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854552": [
        {
            "ioc_value": "sutf.kafekarachi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 22:27:40",
            "last_seen_utc": "2026-07-21 17:34:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854551": [
        {
            "ioc_value": "jennyrussianbluepalace.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 22:25:10",
            "last_seen_utc": "2026-07-20 22:25:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854550": [
        {
            "ioc_value": "47.101.51.235:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 22:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854546": [
        {
            "ioc_value": "wakgo.jbgroup21.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 21:40:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854545": [
        {
            "ioc_value": "zztz.jetourmexico.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 21:27:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854542": [
        {
            "ioc_value": "117.72.175.125:8090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 21:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854541": [
        {
            "ioc_value": "154.12.86.154:33306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 21:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854539": [
        {
            "ioc_value": "117.72.178.246:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 21:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854540": [
        {
            "ioc_value": "117.72.178.246:6379",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 21:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854538": [
        {
            "ioc_value": "15.235.3.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 21:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854529": [
        {
            "ioc_value": "txvii.hazaratbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 20:37:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854519": [
        {
            "ioc_value": "ttvsj7o9.jdexteriorcleaning.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 20:29:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854518": [
        {
            "ioc_value": "atlasgridflow.florenth.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 20:28:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854517": [
        {
            "ioc_value": "xkzh.highkickstkd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 20:27:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854514": [
        {
            "ioc_value": "https://foh.aww88.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 20:25:05",
            "last_seen_utc": "2026-07-21 06:27:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854515": [
        {
            "ioc_value": "foh.luckyturbo88.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 20:25:05",
            "last_seen_utc": "2026-07-21 06:27:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854516": [
        {
            "ioc_value": "https://foh.luckyturbo88.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 20:25:05",
            "last_seen_utc": "2026-07-21 06:27:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854513": [
        {
            "ioc_value": "foh.aww88.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 20:25:04",
            "last_seen_utc": "2026-07-21 06:27:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854512": [
        {
            "ioc_value": "jdexteriorcleaning.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 20:24:31",
            "last_seen_utc": "2026-07-20 20:25:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854511": [
        {
            "ioc_value": "macro3siteview.florenth.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 20:13:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854510": [
        {
            "ioc_value": "43.139.50.42:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 20:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854509": [
        {
            "ioc_value": "117.72.178.246:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 20:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854508": [
        {
            "ioc_value": "94.154.43.77:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-20 19:45:56",
            "last_seen_utc": "2026-07-21 17:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854507": [
        {
            "ioc_value": "77.237.114.150:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-07-20 19:45:43",
            "last_seen_utc": "2026-07-21 17:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854506": [
        {
            "ioc_value": "46.29.162.159:52310",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:45:29",
            "last_seen_utc": "2026-07-21 17:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854505": [
        {
            "ioc_value": "23.94.197.120:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 19:45:07",
            "last_seen_utc": "2026-07-21 17:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854504": [
        {
            "ioc_value": "220.154.3.197:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:45:02",
            "last_seen_utc": "2026-07-21 17:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854503": [
        {
            "ioc_value": "203.83.238.164:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:44:22",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854502": [
        {
            "ioc_value": "2.27.248.61:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-20 19:44:19",
            "last_seen_utc": "2026-07-21 17:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854501": [
        {
            "ioc_value": "181.234.136.109:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-07-20 19:43:58",
            "last_seen_utc": "2026-07-21 17:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854500": [
        {
            "ioc_value": "176.12.79.82:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:54",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854499": [
        {
            "ioc_value": "lunarwaveunit.grovessa.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 19:43:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854498": [
        {
            "ioc_value": "151.243.101.44:21343",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:37",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854496": [
        {
            "ioc_value": "14.22.75.6:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:29",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854497": [
        {
            "ioc_value": "14.22.75.6:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:29",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854495": [
        {
            "ioc_value": "12.202.180.13:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 19:43:22",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854494": [
        {
            "ioc_value": "vuwvp.drdavidzweiback.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 19:35:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854493": [
        {
            "ioc_value": "klca.hieliao-app.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 19:30:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854492": [
        {
            "ioc_value": "iemb.hansikaenterprises.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 19:24:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854468": [
        {
            "ioc_value": "161.35.125.247:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 19:12:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854471": [
        {
            "ioc_value": "img2.mekebibsolomonlaw.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2026-07-20 19:11:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116953642300360994",
            "tags": "SocGholish",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854474": [
        {
            "ioc_value": "hajar-tricks.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.5t_downloader",
            "malware_alias": null,
            "malware_printable": "5.t Downloader",
            "first_seen_utc": "2026-07-20 19:11:58",
            "last_seen_utc": "2026-07-21 01:56:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854478": [
        {
            "ioc_value": "167.172.80.107:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 19:11:56",
            "last_seen_utc": "2026-07-21 02:03:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854490": [
        {
            "ioc_value": "15.235.3.224:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 19:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854491": [
        {
            "ioc_value": "15.235.3.224:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 19:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854488": [
        {
            "ioc_value": "47.236.130.154:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 19:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854489": [
        {
            "ioc_value": "43.139.108.161:21",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 19:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854477": [
        {
            "ioc_value": "http://giftorcharden.comxa.com/Panel/gate.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.pony",
            "malware_alias": "Siplog,Fareit",
            "malware_printable": "Pony",
            "first_seen_utc": "2026-07-20 18:35:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Pony",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854476": [
        {
            "ioc_value": "cunts.colg1.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 18:34:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854475": [
        {
            "ioc_value": "jnhygwu4.gulfbreezervrentals.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 18:25:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854473": [
        {
            "ioc_value": "gulfbreezervrentals.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 18:24:07",
            "last_seen_utc": "2026-07-20 18:24:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854472": [
        {
            "ioc_value": "zvni.frizzhairforecast.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 18:13:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854470": [
        {
            "ioc_value": "121.43.181.37:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 18:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854469": [
        {
            "ioc_value": "syqmn.calirayalake.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 18:04:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854467": [
        {
            "ioc_value": "85.17.192.152:55615",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.redline_stealer",
            "malware_alias": "RECORDSTEALER",
            "malware_printable": "RedLine Stealer",
            "first_seen_utc": "2026-07-20 17:45:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RedLineStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854466": [
        {
            "ioc_value": "z52rumys.customhomebuildersplainfield.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 17:33:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854465": [
        {
            "ioc_value": "47ytdzjs.economywindowsparts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 17:32:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854464": [
        {
            "ioc_value": "gravitfluxbox.grovessa.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 17:23:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854463": [
        {
            "ioc_value": "47.236.130.154:38721",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 17:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854460": [
        {
            "ioc_value": "120.76.143.184:111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 17:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854461": [
        {
            "ioc_value": "47.236.130.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 17:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854462": [
        {
            "ioc_value": "47.236.130.154:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 17:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854459": [
        {
            "ioc_value": "101.42.255.92:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 17:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854458": [
        {
            "ioc_value": "kzsf.concretewestgj.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 17:04:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854457": [
        {
            "ioc_value": "tjhsq.onjabet1.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 17:02:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854456": [
        {
            "ioc_value": "concretewestgj.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 17:02:13",
            "last_seen_utc": "2026-07-21 00:32:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854455": [
        {
            "ioc_value": "urbanhostgate.grovessa.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 16:48:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854454": [
        {
            "ioc_value": "smartmeshsys2.petalune.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 16:33:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854453": [
        {
            "ioc_value": "2zm9lhlg.groeschelcompany.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 16:27:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854452": [
        {
            "ioc_value": "groeschelcompany.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 16:23:34",
            "last_seen_utc": "2026-07-21 00:28:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854450": [
        {
            "ioc_value": "52.86.125.111:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 16:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854451": [
        {
            "ioc_value": "47.236.130.154:7627",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 16:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854449": [
        {
            "ioc_value": "52.86.125.111:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 16:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854448": [
        {
            "ioc_value": "zpbn.comptonanimalrescue.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 16:04:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854447": [
        {
            "ioc_value": "lxlwn.nextbahis.one",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 16:04:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854446": [
        {
            "ioc_value": "comptonanimalrescue.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 16:04:03",
            "last_seen_utc": "2026-07-20 16:04:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854445": [
        {
            "ioc_value": "glmm.colg1.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 16:03:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854444": [
        {
            "ioc_value": "lcare.mrslopezsings.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 16:02:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854418": [
        {
            "ioc_value": "45.76.146.2:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 15:55:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854426": [
        {
            "ioc_value": "https://meduurst.space/api/v1/status",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-20 15:55:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116952942977891438",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854428": [
        {
            "ioc_value": "nodemetrics9095.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-20 15:55:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116952942977891438",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854427": [
        {
            "ioc_value": "https://nodemetrics9095.com/update/package",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-20 15:55:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116952942977891438",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854429": [
        {
            "ioc_value": "https://aurorapavilion.top/acl/principal-payload.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-07-20 15:55:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854433": [
        {
            "ioc_value": "165.232.88.245:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 15:55:17",
            "last_seen_utc": "2026-07-21 17:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854434": [
        {
            "ioc_value": "134.209.93.215:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 15:55:17",
            "last_seen_utc": "2026-07-21 17:46:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854435": [
        {
            "ioc_value": "157.245.77.63:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 15:55:16",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854436": [
        {
            "ioc_value": "64.227.69.17:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 15:55:16",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854437": [
        {
            "ioc_value": "134.122.48.179:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 15:55:16",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854438": [
        {
            "ioc_value": "164.92.153.43:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 15:55:15",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854439": [
        {
            "ioc_value": "209.38.99.84:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 15:55:15",
            "last_seen_utc": "2026-07-21 17:47:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854440": [
        {
            "ioc_value": "188.166.121.223:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 15:55:14",
            "last_seen_utc": "2026-07-21 17:47:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854441": [
        {
            "ioc_value": "68.183.0.134:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 15:55:14",
            "last_seen_utc": "2026-07-21 17:46:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854442": [
        {
            "ioc_value": "188.166.58.104:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 15:55:14",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854443": [
        {
            "ioc_value": "wctvn.mrslopezsings.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 15:54:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854432": [
        {
            "ioc_value": "lvcrn.monicarobles.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 15:29:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854431": [
        {
            "ioc_value": "monicarobles.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 15:24:46",
            "last_seen_utc": "2026-07-21 08:32:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854430": [
        {
            "ioc_value": "drsvt.nextbahis.poker",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 15:22:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854425": [
        {
            "ioc_value": "axoo.colg1.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 15:07:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854423": [
        {
            "ioc_value": "101.200.193.211:44323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 15:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854424": [
        {
            "ioc_value": "45.87.53.6:38778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 15:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854421": [
        {
            "ioc_value": "117.72.39.83:44333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 15:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854422": [
        {
            "ioc_value": "117.72.39.83:20091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 15:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854420": [
        {
            "ioc_value": "149.104.28.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 15:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854419": [
        {
            "ioc_value": "colg1.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 15:03:54",
            "last_seen_utc": "2026-07-21 00:31:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854416": [
        {
            "ioc_value": "162.243.163.143:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 14:48:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854417": [
        {
            "ioc_value": "xhbgt.nextbahis.blog",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 14:47:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854415": [
        {
            "ioc_value": "aeiyi.jetbet.download",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 14:32:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854414": [
        {
            "ioc_value": "pjjuosk1.fredcoplumbingpros.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 14:26:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854413": [
        {
            "ioc_value": "energy4665.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-20 14:25:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/356106324c797ba967a2a8cde2156e866fe008332046747866efa82a99e62083/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854412": [
        {
            "ioc_value": "https://dif.loloxsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 14:25:05",
            "last_seen_utc": "2026-07-20 19:27:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854411": [
        {
            "ioc_value": "dif.loloxsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 14:25:04",
            "last_seen_utc": "2026-07-20 19:27:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854389": [
        {
            "ioc_value": "https://aurorapavilion.top/acl/trace-serializer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-07-20 14:14:47",
            "last_seen_utc": "2026-07-20 14:08:55",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854390": [
        {
            "ioc_value": "aurorapavilion.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-07-20 14:14:47",
            "last_seen_utc": "2026-07-20 14:08:57",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854391": [
        {
            "ioc_value": "https://aurorapavilion.top/acl/principal-core.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-07-20 14:14:47",
            "last_seen_utc": "2026-07-20 14:08:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854397": [
        {
            "ioc_value": "https://blocuriizolatetermic.primariapetrosani.ro/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 14:14:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/blocuriizolatetermic.primariapetrosani.ro",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1854404": [
        {
            "ioc_value": "meduurst.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-20 14:14:46",
            "last_seen_utc": "2026-07-20 15:11:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854405": [
        {
            "ioc_value": "https://meduurst.space/api/v1/session",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-20 14:14:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854406": [
        {
            "ioc_value": "https://meduurst.space/api/v1/verify",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-20 14:14:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1854409": [
        {
            "ioc_value": "https://dif.brslot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 14:10:05",
            "last_seen_utc": "2026-07-20 19:27:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854408": [
        {
            "ioc_value": "dif.brslot.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 14:10:04",
            "last_seen_utc": "2026-07-20 19:27:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854407": [
        {
            "ioc_value": "igsx.closedfistllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 14:08:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854402": [
        {
            "ioc_value": "45.77.89.29:8484",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854403": [
        {
            "ioc_value": "117.72.39.83:20443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854400": [
        {
            "ioc_value": "149.104.28.204:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 14:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854401": [
        {
            "ioc_value": "149.104.28.204:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 14:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854399": [
        {
            "ioc_value": "aruhq.jbgroup21.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 14:04:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854398": [
        {
            "ioc_value": "vastlogicweb.petalune.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 13:43:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854396": [
        {
            "ioc_value": "stellar5bit.petalune.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 13:28:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854395": [
        {
            "ioc_value": "clouderfaster.cc",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 13:22:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854394": [
        {
            "ioc_value": "wbpypinui.generososbakerycafe.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 13:15:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0xa770,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854393": [
        {
            "ioc_value": "https://nenodescolado.com.br/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 13:15:04",
            "last_seen_utc": "2026-07-20 15:30:38",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854392": [
        {
            "ioc_value": "generososbakerycafe.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 13:12:22",
            "last_seen_utc": "2026-07-20 13:12:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854387": [
        {
            "ioc_value": "43.143.128.126:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 13:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854388": [
        {
            "ioc_value": "149.104.28.204:9879",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 13:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854386": [
        {
            "ioc_value": "47.108.140.10:8099",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 13:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854385": [
        {
            "ioc_value": "43.138.148.100:10022",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854384": [
        {
            "ioc_value": "43.138.148.100:20000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854383": [
        {
            "ioc_value": "cglp.cleantruckchecksac.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 13:03:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854382": [
        {
            "ioc_value": "embvx.hazaratbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 13:02:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854380": [
        {
            "ioc_value": "grandnode3unit.solavern.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:43:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854381": [
        {
            "ioc_value": "freetasksite8.petalune.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:43:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854369": [
        {
            "ioc_value": "162.243.163.143:12345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 12:35:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854379": [
        {
            "ioc_value": "a6du2gsx.fit2leadconference.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:34:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854378": [
        {
            "ioc_value": "hag0wqv7.estrelamardedetizadora.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:33:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854377": [
        {
            "ioc_value": "fit2leadconference.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:33:13",
            "last_seen_utc": "2026-07-20 12:33:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854376": [
        {
            "ioc_value": "estrelamardedetizadora.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:31:46",
            "last_seen_utc": "2026-07-20 12:32:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854375": [
        {
            "ioc_value": "qaqatrf8.dermatologycongress.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:26:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854374": [
        {
            "ioc_value": "bcmej6hr.goodlifelakerentals.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:26:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854373": [
        {
            "ioc_value": "2gfxwchj.emeraldualzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:23:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854372": [
        {
            "ioc_value": "dermatologycongress.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:22:55",
            "last_seen_utc": "2026-07-20 22:34:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854371": [
        {
            "ioc_value": "goodlifelakerentals.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:22:38",
            "last_seen_utc": "2026-07-20 12:23:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854370": [
        {
            "ioc_value": "emeraldualzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:21:41",
            "last_seen_utc": "2026-07-20 22:33:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854216": [
        {
            "ioc_value": "159.223.212.162:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 12:20:31",
            "last_seen_utc": "2026-07-20 14:06:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854228": [
        {
            "ioc_value": "https://solaric.com.ph/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 12:20:31",
            "last_seen_utc": "2026-07-21 05:30:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/c90fffe0-fc10-4608-99b1-01d0ff1b5f4d",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "ThreatOpsX"
        }
    ],
    "1854229": [
        {
            "ioc_value": "167.99.46.90:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 12:20:30",
            "last_seen_utc": "2026-07-20 14:07:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854230": [
        {
            "ioc_value": "209.38.38.123:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 12:20:30",
            "last_seen_utc": "2026-07-20 14:07:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854231": [
        {
            "ioc_value": "161.35.85.184:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 12:20:29",
            "last_seen_utc": "2026-07-20 14:06:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854232": [
        {
            "ioc_value": "209.38.44.99:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 12:20:29",
            "last_seen_utc": "2026-07-20 14:08:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854233": [
        {
            "ioc_value": "152.42.140.47:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 12:20:28",
            "last_seen_utc": "2026-07-20 14:07:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854234": [
        {
            "ioc_value": "134.122.57.112:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 12:20:28",
            "last_seen_utc": "2026-07-20 14:07:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854235": [
        {
            "ioc_value": "209.38.106.41:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 12:20:28",
            "last_seen_utc": "2026-07-20 14:09:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854236": [
        {
            "ioc_value": "206.189.6.103:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 12:20:27",
            "last_seen_utc": "2026-07-20 13:54:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854244": [
        {
            "ioc_value": "178.62.251.175:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-20 12:20:27",
            "last_seen_utc": "2026-07-20 14:07:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854340": [
        {
            "ioc_value": "167.172.80.107:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 12:20:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854368": [
        {
            "ioc_value": "bhrbc90m.fredcoplumbingpros.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:16:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854366": [
        {
            "ioc_value": "https://bechisalbinoantenne.it/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 12:15:04",
            "last_seen_utc": "2026-07-20 13:30:38",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854367": [
        {
            "ioc_value": "https://adminbyrequest.agilemtech.ae/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 12:15:04",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854365": [
        {
            "ioc_value": "xgu7k53h.economywindowsparts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:14:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854364": [
        {
            "ioc_value": "fredcoplumbingpros.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:13:27",
            "last_seen_utc": "2026-07-20 14:23:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854363": [
        {
            "ioc_value": "ea168jci.customhomebuildersplainfield.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:13:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854362": [
        {
            "ioc_value": "economywindowsparts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:12:51",
            "last_seen_utc": "2026-07-20 17:32:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854361": [
        {
            "ioc_value": "customhomebuildersplainfield.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:11:38",
            "last_seen_utc": "2026-07-20 17:33:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854360": [
        {
            "ioc_value": "kwgn9wkj.cupprimosouth.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:10:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854359": [
        {
            "ioc_value": "cupprimosouth.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:10:23",
            "last_seen_utc": "2026-07-20 12:10:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854358": [
        {
            "ioc_value": "vrdh.calirayalake.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:07:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854357": [
        {
            "ioc_value": "43.130.249.174:3232",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 12:05:49",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/77ed2de688c8f7e1315dc239763f72079ab0eb883591b81f5fbb9266ae4407d5/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854356": [
        {
            "ioc_value": "166.88.132.80:2323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-07-20 12:05:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/77ed2de688c8f7e1315dc239763f72079ab0eb883591b81f5fbb9266ae4407d5/",
            "tags": "xworm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854354": [
        {
            "ioc_value": "47.94.13.0:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 12:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854355": [
        {
            "ioc_value": "43.143.128.126:6379",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 12:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854353": [
        {
            "ioc_value": "yywem.drdavidzweiback.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 12:03:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854352": [
        {
            "ioc_value": "8iuwoa4l.of-tencent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:56:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854349": [
        {
            "ioc_value": "https://viv.brslot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:55:05",
            "last_seen_utc": "2026-07-20 13:27:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854350": [
        {
            "ioc_value": "viv.loloxsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:55:05",
            "last_seen_utc": "2026-07-20 13:27:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854351": [
        {
            "ioc_value": "https://viv.loloxsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:55:05",
            "last_seen_utc": "2026-07-20 13:27:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854348": [
        {
            "ioc_value": "viv.brslot.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:55:04",
            "last_seen_utc": "2026-07-20 13:27:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854347": [
        {
            "ioc_value": "kkid.hightidesuffolk.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:48:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854346": [
        {
            "ioc_value": "xcavl.crossonerecords.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:46:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854345": [
        {
            "ioc_value": "hightidesuffolk.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:44:59",
            "last_seen_utc": "2026-07-20 11:45:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854344": [
        {
            "ioc_value": "crossonerecords.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:44:28",
            "last_seen_utc": "2026-07-20 11:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854343": [
        {
            "ioc_value": "54e20j57.mrslopezsings.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:43:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854342": [
        {
            "ioc_value": "y0fui15e.corgiwarehouse.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:42:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854341": [
        {
            "ioc_value": "mrslopezsings.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:42:18",
            "last_seen_utc": "2026-07-20 16:02:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854339": [
        {
            "ioc_value": "corgiwarehouse.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:41:30",
            "last_seen_utc": "2026-07-21 13:37:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854338": [
        {
            "ioc_value": "20ntquqt.varzeshlife.ir",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:34:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854337": [
        {
            "ioc_value": "1eriimge.consultingsolutionsjp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:33:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854336": [
        {
            "ioc_value": "consultingsolutionsjp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:31:28",
            "last_seen_utc": "2026-07-20 11:31:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854335": [
        {
            "ioc_value": "uz1hqtn3.phtaxiservices.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:23:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854332": [
        {
            "ioc_value": "3fc95667b98c637ba785b67dff1bd15ff7a21f082d25894c3a78ec1b6206fcd7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-07-20 11:23:17",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854333": [
        {
            "ioc_value": "e17f76e0b4c47a5f54ca51b105be0dd29df50c7c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-07-20 11:23:17",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854334": [
        {
            "ioc_value": "eff8675fac22c49107a2a42d3c735f10",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-07-20 11:23:17",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854329": [
        {
            "ioc_value": "f47ac99afe9dbccccf308de99a8c791c675810047d11bd4613c5a4a4f08568e7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-07-20 11:23:16",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854330": [
        {
            "ioc_value": "3a838467763d722b11890d0cd331144aeac5f8f9",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-07-20 11:23:16",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854331": [
        {
            "ioc_value": "159e06ef198371caf78e9a168b5ef4e9",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.rhadamanthys",
            "malware_alias": null,
            "malware_printable": "Rhadamanthys",
            "first_seen_utc": "2026-07-20 11:23:16",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854325": [
        {
            "ioc_value": "84b7baaa2e134146258d883388114f18",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:23:15",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854326": [
        {
            "ioc_value": "0a4b3b6e4de78361552735cbbc95a1819a7338c810e7f31e1a3d68a06a5252bb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:23:15",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854327": [
        {
            "ioc_value": "2dc11386a208dfe528ef8fdd70d7b81290e7b5ce",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:23:15",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854328": [
        {
            "ioc_value": "788fc952b7bdc334fc677426dcf2af39",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:23:15",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854322": [
        {
            "ioc_value": "aac21459dc203d21c539a72d54221102",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-07-20 11:23:14",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854323": [
        {
            "ioc_value": "3c3f12531045b7eedfe25e0f291d4792b0d8c8366f8de043e2fa8ecf34ccb913",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:23:14",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854324": [
        {
            "ioc_value": "91f2324c19f08256d45bfc675a80efd6ad1e8748",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:23:14",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854320": [
        {
            "ioc_value": "78e53037a3b94c1a14f4c8283f27b1b9b6a0601515fe6b4cdc28ac8fce9b938f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-07-20 11:23:13",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854321": [
        {
            "ioc_value": "61a27756cba4c8be0a6465912de786b90f6f8de1",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-07-20 11:23:13",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854317": [
        {
            "ioc_value": "164e4dd739dacd0e13fb125905abd4ef3293391d34405421ddad4470826c1941",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-07-20 11:23:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854318": [
        {
            "ioc_value": "ed5e0b6b2cab48f0d86d7f2b6cd7354ce760c7ac",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-07-20 11:23:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854319": [
        {
            "ioc_value": "7aff39817fd60f3ea5b9298e8838b481",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-07-20 11:23:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854315": [
        {
            "ioc_value": "1a096f222444db6d4a189dc14d0461423e7bda96",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:23:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854316": [
        {
            "ioc_value": "ea96de1d5ee80bbe8795d352f7ac3e30",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:23:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854311": [
        {
            "ioc_value": "43fe17a95010413fce338858f7f675708e1f3b9fb1998a436881c35dbe49825f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 11:23:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854312": [
        {
            "ioc_value": "29fb8a163ec801d7e28fe0e8e817f8501b6cae86",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 11:23:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854313": [
        {
            "ioc_value": "eb3fd1706066aecf68f002c744100218",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 11:23:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854314": [
        {
            "ioc_value": "7a8f47c4a4d9870b838791d51abafab65b8279e5c347add2b7e5aaa0222ab84a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 11:23:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854308": [
        {
            "ioc_value": "58328b7f4fecb0407da1947937b41162e23a61559d6f49526ec1683febad6ddc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:23:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854309": [
        {
            "ioc_value": "1c89e143465d44f7d3fa6561436624b6990027fb",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:23:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854310": [
        {
            "ioc_value": "10cc531b5f4765f53cd3a58a2c23ffcf",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:23:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854305": [
        {
            "ioc_value": "2112d749000ec32a1eeb719eb1e0daee69cda7946eab3049f5d2fd83bac566c2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:23:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854306": [
        {
            "ioc_value": "22d0daad3abfb17c90862ac3fd80746738c9074e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:23:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854307": [
        {
            "ioc_value": "d8d19575c1de6c091ebf0624596478fa",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:23:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854304": [
        {
            "ioc_value": "d1dc20911470ed43af8bce0355fd0cf7",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-07-20 11:23:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854302": [
        {
            "ioc_value": "80571d10fe416a63ceb0c3b582c547573c41c1b1108ebda0e5604edf4532ff97",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-07-20 11:22:51",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854303": [
        {
            "ioc_value": "cf7fa092c3cec9deb2bb4a008535f540a6d1ec46",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-07-20 11:22:51",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854299": [
        {
            "ioc_value": "2d1a5a0c9b43b6dbff32bd3b66d1a96c0d36773f5b7b546fcb9da93580f9246a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-07-20 11:22:50",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854300": [
        {
            "ioc_value": "50d5e712edfc416e508aaf221110d6b4a3df93e2",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-07-20 11:22:50",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854301": [
        {
            "ioc_value": "8465b5392ea382ceec662c25ea7acc34",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-07-20 11:22:50",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854296": [
        {
            "ioc_value": "e16ea5b5892442616eb4b0d8e53a242e6532b77db42202d33b78ef9461745cc5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-07-20 11:22:49",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854297": [
        {
            "ioc_value": "74983470e89aea81c6f0de3a50616b5ddd1988fe",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-07-20 11:22:49",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854298": [
        {
            "ioc_value": "b3f9d748284ba06c5f74c062b11c6066",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-07-20 11:22:49",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854293": [
        {
            "ioc_value": "9aa928b433983f53758e42961aa0cf8096a4211a5562bfcd7ba3cb63d902282b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.phantom_stealer",
            "malware_alias": null,
            "malware_printable": "Phantom Stealer",
            "first_seen_utc": "2026-07-20 11:22:48",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854294": [
        {
            "ioc_value": "98c8c5d84a81cc068d24a68b1e2bb3dc7babae41",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.phantom_stealer",
            "malware_alias": null,
            "malware_printable": "Phantom Stealer",
            "first_seen_utc": "2026-07-20 11:22:48",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854295": [
        {
            "ioc_value": "c8a7ae786c0294734130e1685a6f5ae3",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.phantom_stealer",
            "malware_alias": null,
            "malware_printable": "Phantom Stealer",
            "first_seen_utc": "2026-07-20 11:22:48",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854290": [
        {
            "ioc_value": "d3adedb75d5f43ee0a1400fa5be76e4f734ec031d40b426a390ec5f453a40859",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-07-20 11:22:47",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854291": [
        {
            "ioc_value": "6f1cc02617b24127df7fb482c2e1c9496c0aafbc",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-07-20 11:22:47",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854292": [
        {
            "ioc_value": "0c9381cfd85e2d1aad8ccbe8bec861ca",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-07-20 11:22:47",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854286": [
        {
            "ioc_value": "6b1f9dee6182e98eabff20baa433fced12a7f584e4973eb7b020f6a0c297fcec",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-07-20 11:22:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854287": [
        {
            "ioc_value": "a3b4e81b5da8cf8a500cb87939e2be9bff352145",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-07-20 11:22:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854288": [
        {
            "ioc_value": "a563ff5a153b001223ff8d93d68405c9",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-07-20 11:22:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854289": [
        {
            "ioc_value": "bjastqph.chrisbrownallegiantstadium.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:22:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854283": [
        {
            "ioc_value": "330f79845eb9694405707e1b2ef8621e8673920b3da8ccb3a4136418b7404254",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.phantom_stealer",
            "malware_alias": null,
            "malware_printable": "Phantom Stealer",
            "first_seen_utc": "2026-07-20 11:22:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854284": [
        {
            "ioc_value": "e162d5f789a9cba57f46da154fabdde31a72683b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.phantom_stealer",
            "malware_alias": null,
            "malware_printable": "Phantom Stealer",
            "first_seen_utc": "2026-07-20 11:22:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854285": [
        {
            "ioc_value": "e14ec518b3e9768fd51d95f13c60dea1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.phantom_stealer",
            "malware_alias": null,
            "malware_printable": "Phantom Stealer",
            "first_seen_utc": "2026-07-20 11:22:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854281": [
        {
            "ioc_value": "ea88765037a10234f4558c076d3bb1805fe402f6",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-07-20 11:22:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854282": [
        {
            "ioc_value": "a3f6cbc6b8366c4378504eedbb2408d1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-07-20 11:22:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854280": [
        {
            "ioc_value": "865884c27b7ee53c1744c183ca07ce310b4485dfa085fe3ed3c658e38f7d99f2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-07-20 11:22:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854277": [
        {
            "ioc_value": "a0abe6eb238036b9a233799296c270282a19f603ed5560d4874a277fa55b17c3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.socks5_systemz",
            "malware_alias": "ProxyBox",
            "malware_printable": "Socks5Systemz",
            "first_seen_utc": "2026-07-20 11:22:42",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854278": [
        {
            "ioc_value": "ae67101984cab3956d8a8f50c36418a102909723",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.socks5_systemz",
            "malware_alias": "ProxyBox",
            "malware_printable": "Socks5Systemz",
            "first_seen_utc": "2026-07-20 11:22:42",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854279": [
        {
            "ioc_value": "a77da66551da74d743efd55f09d46dc8",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.socks5_systemz",
            "malware_alias": "ProxyBox",
            "malware_printable": "Socks5Systemz",
            "first_seen_utc": "2026-07-20 11:22:42",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854275": [
        {
            "ioc_value": "a302b2902da6ebf1c6f9b79158320bb4111d75a0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:22:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854276": [
        {
            "ioc_value": "791d27fd45d5ac5f25235b46547129ad",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:22:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854272": [
        {
            "ioc_value": "7a5ce656b36a081d0f93d5add93a9c8ddc329abf",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 11:22:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854273": [
        {
            "ioc_value": "44ddc80c714f91959bcaa1aeb3cfe1d5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 11:22:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854274": [
        {
            "ioc_value": "940f0d74f64672c50d4b6ed704aefa743d81b7cdfbeb6666a00f690f80b7b001",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:22:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854268": [
        {
            "ioc_value": "e6290924b6e7a434776239ae19e79b02e88c3a6bef1b0e1d61041cc4176dec6e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:22:39",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854269": [
        {
            "ioc_value": "ea9efc587962f4a1286aa26d274354039472d436",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:22:39",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854270": [
        {
            "ioc_value": "a757a8b09d99acc2835fd0d26541e46c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-20 11:22:39",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854271": [
        {
            "ioc_value": "26fc8807ce9a5e6dc534c237d84c2ac7491755532a2078878bc8fb1695fcb2eb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 11:22:39",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854265": [
        {
            "ioc_value": "707d1f44be9210b1f0dd678a37aef925c4b09c3072289a575fadad571470ed2f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-07-20 11:22:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854266": [
        {
            "ioc_value": "2f8782ed3f725c8df861b7c3c3b54c5b37f0c87d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-07-20 11:22:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854267": [
        {
            "ioc_value": "ca9050aa6e139627dd5c0d4cdd5e3eaa",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-07-20 11:22:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854261": [
        {
            "ioc_value": "584e516edb5fc2b79960940b18cd65b5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-07-20 11:22:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854262": [
        {
            "ioc_value": "b4991986b29c3882404e7078ccd37954f9f9676bb766f83161199eee1f1b85d0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.krakenkeylogger",
            "malware_alias": null,
            "malware_printable": "KrakenKeylogger",
            "first_seen_utc": "2026-07-20 11:22:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854263": [
        {
            "ioc_value": "f2cf888fb2133a89254455c4f50df81db384912a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.krakenkeylogger",
            "malware_alias": null,
            "malware_printable": "KrakenKeylogger",
            "first_seen_utc": "2026-07-20 11:22:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854264": [
        {
            "ioc_value": "4be889e143b460ccf80fc02e44840ee0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.krakenkeylogger",
            "malware_alias": null,
            "malware_printable": "KrakenKeylogger",
            "first_seen_utc": "2026-07-20 11:22:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854260": [
        {
            "ioc_value": "4ad57334dee1fafb11f25b63df07a64370153ea7",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-07-20 11:22:36",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854259": [
        {
            "ioc_value": "7132a14099e6824598c5899dea19a4b8f4d89683bb01774b402674da1d4fee2f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-07-20 11:22:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854257": [
        {
            "ioc_value": "616a15883f34627757fe19b12324ed8f0583b739",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.privateloader",
            "malware_alias": null,
            "malware_printable": "PrivateLoader",
            "first_seen_utc": "2026-07-20 11:22:19",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854258": [
        {
            "ioc_value": "be9aee8c3cb56fa17d293d48dd0fc1d1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.privateloader",
            "malware_alias": null,
            "malware_printable": "PrivateLoader",
            "first_seen_utc": "2026-07-20 11:22:19",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854255": [
        {
            "ioc_value": "3270606f7138f08b0c4e051d0a9ebc2b",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-20 11:22:18",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854256": [
        {
            "ioc_value": "65ab49119c845801f29a57e8aa177146b2ffbd289d4278109b146f933380f951",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.privateloader",
            "malware_alias": null,
            "malware_printable": "PrivateLoader",
            "first_seen_utc": "2026-07-20 11:22:18",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854253": [
        {
            "ioc_value": "d5e71f60f77f8f7853d80ff308d7b0420e20600fe03af2529a2c8e740ed52943",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-20 11:22:17",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854254": [
        {
            "ioc_value": "da7422fee4ab158c1ffb61b901e854fa375d57c0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-20 11:22:17",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854252": [
        {
            "ioc_value": "chrisbrownallegiantstadium.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:21:35",
            "last_seen_utc": "2026-07-20 11:21:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854251": [
        {
            "ioc_value": "g2o19aql.charmedanddangerousplush.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:13:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854250": [
        {
            "ioc_value": "mevd0fjv.phimmoichilla.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:12:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854249": [
        {
            "ioc_value": "charmedanddangerousplush.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:11:40",
            "last_seen_utc": "2026-07-20 11:11:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854247": [
        {
            "ioc_value": "117.72.189.142:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 11:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854248": [
        {
            "ioc_value": "192.144.211.249:888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 11:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854246": [
        {
            "ioc_value": "106.52.255.211:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 11:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854245": [
        {
            "ioc_value": "103.236.92.210:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 11:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854243": [
        {
            "ioc_value": "biirwl32.patxisdublin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:01:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854242": [
        {
            "ioc_value": "tq6ay9c3.broadwaylotterytickets.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 11:00:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854241": [
        {
            "ioc_value": "broadwaylotterytickets.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:59:27",
            "last_seen_utc": "2026-07-20 10:59:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854240": [
        {
            "ioc_value": "186.241.66.4:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-20 10:55:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854239": [
        {
            "ioc_value": "okv4iaii.contempoconstructiontx.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:51:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854238": [
        {
            "ioc_value": "fgsnlppf.jadoou.lat",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:50:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854237": [
        {
            "ioc_value": "contempoconstructiontx.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:50:40",
            "last_seen_utc": "2026-07-20 10:50:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854227": [
        {
            "ioc_value": "tgbft.countertops-dfw.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:45:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854226": [
        {
            "ioc_value": "giwl.highkickstkd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:45:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854225": [
        {
            "ioc_value": "107.173.47.142:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-20 10:45:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854224": [
        {
            "ioc_value": "highkickstkd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:44:35",
            "last_seen_utc": "2026-07-21 02:37:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854223": [
        {
            "ioc_value": "countertops-dfw.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:44:04",
            "last_seen_utc": "2026-07-20 10:44:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854222": [
        {
            "ioc_value": "3efofny3.cielohillsevents.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:40:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854221": [
        {
            "ioc_value": "cielohillsevents.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:39:29",
            "last_seen_utc": "2026-07-20 10:39:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854220": [
        {
            "ioc_value": "hpnohznb.site-takhtenard-sharti-betland.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:33:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854219": [
        {
            "ioc_value": "u9p8kb56.crvbl.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:33:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854218": [
        {
            "ioc_value": "wnq8bmsb.derbi.promo",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:32:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854217": [
        {
            "ioc_value": "crvbl.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:30:25",
            "last_seen_utc": "2026-07-20 10:30:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854215": [
        {
            "ioc_value": "f9e2ff2h.site-asli-bedon-filter-1xbet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:23:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854212": [
        {
            "ioc_value": "https://pressao.sinprodf.org.br/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 10:15:03",
            "last_seen_utc": "2026-07-20 11:30:18",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854213": [
        {
            "ioc_value": "https://academyda.co/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 10:15:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854214": [
        {
            "ioc_value": "https://carmag.nl/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 10:15:03",
            "last_seen_utc": "2026-07-20 11:30:17",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854210": [
        {
            "ioc_value": "101.34.222.38:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 10:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854211": [
        {
            "ioc_value": "124.220.77.21:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 10:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854208": [
        {
            "ioc_value": "101.201.53.137:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 10:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854209": [
        {
            "ioc_value": "101.34.222.38:111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 10:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854207": [
        {
            "ioc_value": "103.142.147.19:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 10:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854205": [
        {
            "ioc_value": "apexstorm6link.solavern.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:03:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854206": [
        {
            "ioc_value": "neogateway9hub.solavern.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 10:03:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854204": [
        {
            "ioc_value": "ddsr.hieliao-app.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 09:49:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854203": [
        {
            "ioc_value": "lightsiteview1.solavern.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 09:48:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854202": [
        {
            "ioc_value": "cnxst.jardins-do-mar.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 09:48:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854201": [
        {
            "ioc_value": "89.124.104.192:49999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 09:45:58",
            "last_seen_utc": "2026-07-21 17:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854200": [
        {
            "ioc_value": "220.154.3.197:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:45:09",
            "last_seen_utc": "2026-07-21 17:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854198": [
        {
            "ioc_value": "203.83.238.164:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:44:25",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854199": [
        {
            "ioc_value": "203.83.238.164:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:44:25",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854197": [
        {
            "ioc_value": "192.227.219.71:34471",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 09:44:15",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854196": [
        {
            "ioc_value": "185.212.131.28:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:44:09",
            "last_seen_utc": "2026-07-21 17:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854195": [
        {
            "ioc_value": "185.212.128.155:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:44:07",
            "last_seen_utc": "2026-07-21 17:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854194": [
        {
            "ioc_value": "hieliao-app.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 09:44:05",
            "last_seen_utc": "2026-07-20 19:26:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854193": [
        {
            "ioc_value": "169.58.12.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:43:51",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854192": [
        {
            "ioc_value": "154.83.186.39:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-20 09:43:39",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854191": [
        {
            "ioc_value": "147.93.191.75:20800",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 09:43:35",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854190": [
        {
            "ioc_value": "147.93.191.75:20700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 09:43:34",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854189": [
        {
            "ioc_value": "jardins-do-mar.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 09:43:25",
            "last_seen_utc": "2026-07-21 13:37:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854188": [
        {
            "ioc_value": "103.185.249.13:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:43:11",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854187": [
        {
            "ioc_value": "ryr4q9kj.playantwatch.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 09:22:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854186": [
        {
            "ioc_value": "vividmeshflow.solavern.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 09:18:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854185": [
        {
            "ioc_value": "https://graduadosocialcordoba.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 09:15:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854184": [
        {
            "ioc_value": "20.230.138.200:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 09:14:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854183": [
        {
            "ioc_value": "121.40.141.52:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 09:14:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854182": [
        {
            "ioc_value": "216.250.255.1:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 09:14:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854181": [
        {
            "ioc_value": "115.191.29.91:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 09:14:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854179": [
        {
            "ioc_value": "103.142.147.18:5700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854180": [
        {
            "ioc_value": "103.142.147.18:59517",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854178": [
        {
            "ioc_value": "103.142.147.17:5700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854177": [
        {
            "ioc_value": "103.142.147.17:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854176": [
        {
            "ioc_value": "boldlogicgate4.mistbriar.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 08:58:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854175": [
        {
            "ioc_value": "cyki.hayleymarienorman.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 08:45:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854174": [
        {
            "ioc_value": "jsthk.jademckenzieco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 08:45:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854173": [
        {
            "ioc_value": "swift7tasknet.mistbriar.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 08:43:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854172": [
        {
            "ioc_value": "hayleymarienorman.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 08:43:34",
            "last_seen_utc": "2026-07-20 08:44:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854171": [
        {
            "ioc_value": "jademckenzieco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 08:42:52",
            "last_seen_utc": "2026-07-20 08:42:57",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854170": [
        {
            "ioc_value": "twyd6y14.elizabethspizzadenton.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 08:22:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854169": [
        {
            "ioc_value": "01ejjpa2.behtarin-site-shartbandi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 08:07:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854168": [
        {
            "ioc_value": "152.42.185.244:5678",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 08:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854166": [
        {
            "ioc_value": "122.51.215.90:111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 08:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854167": [
        {
            "ioc_value": "122.51.215.90:6379",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 08:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854164": [
        {
            "ioc_value": "106.52.255.211:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 08:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854165": [
        {
            "ioc_value": "122.51.215.90:5672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 08:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854160": [
        {
            "ioc_value": "62.60.156.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854161": [
        {
            "ioc_value": "62.60.156.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854162": [
        {
            "ioc_value": "167.233.225.221:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854163": [
        {
            "ioc_value": "178.105.212.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854152": [
        {
            "ioc_value": "62.60.156.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854153": [
        {
            "ioc_value": "144.76.97.182:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854154": [
        {
            "ioc_value": "62.60.148.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854155": [
        {
            "ioc_value": "37.27.227.56:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854156": [
        {
            "ioc_value": "167.233.223.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854157": [
        {
            "ioc_value": "37.27.235.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854158": [
        {
            "ioc_value": "65.108.197.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854159": [
        {
            "ioc_value": "188.40.215.132:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854146": [
        {
            "ioc_value": "46.224.109.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854147": [
        {
            "ioc_value": "178.105.203.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854148": [
        {
            "ioc_value": "62.60.156.150:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854149": [
        {
            "ioc_value": "195.201.33.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854150": [
        {
            "ioc_value": "168.119.108.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854151": [
        {
            "ioc_value": "46.4.77.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854137": [
        {
            "ioc_value": "sei.loloxsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854138": [
        {
            "ioc_value": "okx.loloxsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854139": [
        {
            "ioc_value": "ylp.brslot.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854140": [
        {
            "ioc_value": "mgg.brslot.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854141": [
        {
            "ioc_value": "wvg.brslot.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854142": [
        {
            "ioc_value": "fwb.brslot.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854143": [
        {
            "ioc_value": "h1r.brslot.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854144": [
        {
            "ioc_value": "sei.brslot.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854145": [
        {
            "ioc_value": "okx.brslot.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854132": [
        {
            "ioc_value": "ylp.loloxsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854133": [
        {
            "ioc_value": "mgg.loloxsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854134": [
        {
            "ioc_value": "wvg.loloxsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854135": [
        {
            "ioc_value": "fwb.loloxsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854136": [
        {
            "ioc_value": "h1r.loloxsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:51:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854131": [
        {
            "ioc_value": "https://178.105.212.106/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854125": [
        {
            "ioc_value": "https://37.27.235.227/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854126": [
        {
            "ioc_value": "https://65.108.197.198/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854127": [
        {
            "ioc_value": "https://188.40.215.132/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854128": [
        {
            "ioc_value": "https://62.60.156.152/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854129": [
        {
            "ioc_value": "https://62.60.156.105/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854130": [
        {
            "ioc_value": "https://167.233.225.221/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854120": [
        {
            "ioc_value": "https://62.60.156.9/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854121": [
        {
            "ioc_value": "https://144.76.97.182/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854122": [
        {
            "ioc_value": "https://62.60.148.253/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854123": [
        {
            "ioc_value": "https://37.27.227.56/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854124": [
        {
            "ioc_value": "https://167.233.223.34/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854115": [
        {
            "ioc_value": "https://178.105.203.113/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854116": [
        {
            "ioc_value": "https://62.60.156.150/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854117": [
        {
            "ioc_value": "https://195.201.33.212/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854118": [
        {
            "ioc_value": "https://168.119.108.231/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854119": [
        {
            "ioc_value": "https://46.4.77.212/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854111": [
        {
            "ioc_value": "https://h1r.brslot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854112": [
        {
            "ioc_value": "https://sei.brslot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854113": [
        {
            "ioc_value": "https://okx.brslot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854114": [
        {
            "ioc_value": "https://46.224.109.175/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854106": [
        {
            "ioc_value": "https://okx.loloxsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854107": [
        {
            "ioc_value": "https://ylp.brslot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854108": [
        {
            "ioc_value": "https://mgg.brslot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854109": [
        {
            "ioc_value": "https://wvg.brslot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854110": [
        {
            "ioc_value": "https://fwb.brslot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854101": [
        {
            "ioc_value": "https://mgg.loloxsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854102": [
        {
            "ioc_value": "https://wvg.loloxsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854103": [
        {
            "ioc_value": "https://fwb.loloxsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854104": [
        {
            "ioc_value": "https://h1r.loloxsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854105": [
        {
            "ioc_value": "https://sei.loloxsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854098": [
        {
            "ioc_value": "https://t.me/np33yk",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854099": [
        {
            "ioc_value": "https://steamcommunity.com/profiles/76561198671804195",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854100": [
        {
            "ioc_value": "https://ylp.loloxsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:50:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854097": [
        {
            "ioc_value": "pkspm.informatik-ai.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 07:47:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854096": [
        {
            "ioc_value": "todn.hansikaenterprises.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 07:43:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854095": [
        {
            "ioc_value": "hansikaenterprises.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 07:43:04",
            "last_seen_utc": "2026-07-20 19:21:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854094": [
        {
            "ioc_value": "informatik-ai.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 07:42:24",
            "last_seen_utc": "2026-07-20 07:42:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854091": [
        {
            "ioc_value": "https://kmd.brslot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:35:05",
            "last_seen_utc": "2026-07-20 11:27:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854092": [
        {
            "ioc_value": "kmd.loloxsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:35:05",
            "last_seen_utc": "2026-07-20 11:27:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854093": [
        {
            "ioc_value": "https://kmd.loloxsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:35:05",
            "last_seen_utc": "2026-07-20 11:27:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854090": [
        {
            "ioc_value": "kmd.brslot.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:35:04",
            "last_seen_utc": "2026-07-20 11:27:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1854089": [
        {
            "ioc_value": "https://hastehair.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-20 07:15:03",
            "last_seen_utc": "2026-07-20 13:30:38",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854087": [
        {
            "ioc_value": "113.44.90.0:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854088": [
        {
            "ioc_value": "111.229.144.163:5003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854086": [
        {
            "ioc_value": "113.44.90.0:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 07:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854085": [
        {
            "ioc_value": "113.44.90.0:6379",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 07:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854084": [
        {
            "ioc_value": "oqtr.haleywoodportfolio.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 06:45:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854083": [
        {
            "ioc_value": "tztgw.impactpromotionsclt.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 06:44:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854082": [
        {
            "ioc_value": "haleywoodportfolio.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 06:42:33",
            "last_seen_utc": "2026-07-20 06:43:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854081": [
        {
            "ioc_value": "impactpromotionsclt.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 06:41:52",
            "last_seen_utc": "2026-07-20 06:41:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854080": [
        {
            "ioc_value": "primeglow2unit.mistbriar.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 06:38:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853931": [
        {
            "ioc_value": "https://rolems.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rolems.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853933": [
        {
            "ioc_value": "https://www.nr-7releases.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www.nr-7releases.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853932": [
        {
            "ioc_value": "https://rumahlift.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rumahlift.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853934": [
        {
            "ioc_value": "https://moroneyaccountants.ie/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/moroneyaccountants.ie",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853935": [
        {
            "ioc_value": "https://yourhomeguide.co.uk/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/yourhomeguide.co.uk",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853936": [
        {
            "ioc_value": "https://mazradioaurora.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/mazradioaurora.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853937": [
        {
            "ioc_value": "https://lucianasalomao.com.br/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/lucianasalomao.com.br",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853938": [
        {
            "ioc_value": "https://guiasantosdumont.com.br/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/guiasantosdumont.com.br",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853939": [
        {
            "ioc_value": "https://instantfixservices.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/instantfixservices.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853940": [
        {
            "ioc_value": "https://mobilitate.primariapetrosani.ro/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/mobilitate.primariapetrosani.ro",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853941": [
        {
            "ioc_value": "https://toufafashion.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/toufafashion.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853943": [
        {
            "ioc_value": "https://www.casadesignsrl.it/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www.casadesignsrl.it",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853942": [
        {
            "ioc_value": "https://dailyinterior.co.uk/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/dailyinterior.co.uk",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853944": [
        {
            "ioc_value": "https://euregio-camper.de/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/euregio-camper.de",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853957": [
        {
            "ioc_value": "159.65.143.171:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 06:28:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853963": [
        {
            "ioc_value": "bognervopi.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://urlscan.io/result/019f780a-dfa5-7038-a6b7-f3cac68c2e4f/",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "darses"
        }
    ],
    "1853964": [
        {
            "ioc_value": "tcp://45.153.34.153/rondo.dus",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:33",
            "last_seen_utc": "2026-07-21 02:50:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://greedybear.honeynet.org",
            "tags": "honeypot",
            "anonymous": 0,
            "reporter": "greedybear"
        }
    ],
    "1853970": [
        {
            "ioc_value": "https://daoyiyuan.cn/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:28:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/daoyiyuan.cn",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853973": [
        {
            "ioc_value": "162.249.125.140:4569",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-20 06:28:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Mirai,nc",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1853974": [
        {
            "ioc_value": "162.249.125.140:4568",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-20 06:28:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Mirai,nc",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1853975": [
        {
            "ioc_value": "162.249.125.140:9018",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-20 06:28:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Mirai,nc",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1853976": [
        {
            "ioc_value": "nvms9000.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-20 06:28:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Mirai,nc",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1853977": [
        {
            "ioc_value": "137.184.135.42:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 06:28:31",
            "last_seen_utc": "2026-07-21 10:06:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853980": [
        {
            "ioc_value": "168.144.135.136:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 06:28:29",
            "last_seen_utc": "2026-07-21 14:39:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853986": [
        {
            "ioc_value": "161.35.125.247:9035",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 06:28:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854055": [
        {
            "ioc_value": "162.243.163.143:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 06:28:28",
            "last_seen_utc": "2026-07-21 03:47:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854064": [
        {
            "ioc_value": "162.243.163.143:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 06:28:27",
            "last_seen_utc": "2026-07-21 10:13:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854065": [
        {
            "ioc_value": "159.65.143.171:37215",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 06:28:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854072": [
        {
            "ioc_value": "159.65.143.171:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 06:28:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854077": [
        {
            "ioc_value": "167.172.80.107:9035",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-20 06:28:26",
            "last_seen_utc": "2026-07-21 07:30:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1854079": [
        {
            "ioc_value": "signalwestport.mistbriar.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 06:23:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854078": [
        {
            "ioc_value": "t13ecldw.calculadoracomisiones.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 06:21:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854075": [
        {
            "ioc_value": "106.52.255.211:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854076": [
        {
            "ioc_value": "187.151.124.199:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-07-20 06:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854074": [
        {
            "ioc_value": "43.143.128.126:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 06:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854073": [
        {
            "ioc_value": "proxyfastzone.lunavera.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 06:03:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854071": [
        {
            "ioc_value": "brightnode9sys.lunavera.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 05:53:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854070": [
        {
            "ioc_value": "llttu.hurtigegevinster.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 05:46:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854069": [
        {
            "ioc_value": "rbnz.hairbyniki.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 05:45:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854068": [
        {
            "ioc_value": "hairbyniki.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 05:42:00",
            "last_seen_utc": "2026-07-20 05:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854067": [
        {
            "ioc_value": "hurtigegevinster.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 05:41:15",
            "last_seen_utc": "2026-07-20 05:41:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854066": [
        {
            "ioc_value": "trendscanview.lunavera.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 05:38:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854063": [
        {
            "ioc_value": "ksuqx.cnbgladespring.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 05:07:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854062": [
        {
            "ioc_value": "cnbgladespring.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 05:05:20",
            "last_seen_utc": "2026-07-20 05:05:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854061": [
        {
            "ioc_value": "106.52.255.211:4806",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 05:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854060": [
        {
            "ioc_value": "106.52.255.211:48060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 05:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854059": [
        {
            "ioc_value": "106.52.255.211:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 05:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854058": [
        {
            "ioc_value": "dduf.bolesfarms.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 05:01:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854057": [
        {
            "ioc_value": "ldgcg.closedfistllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 04:57:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854056": [
        {
            "ioc_value": "closedfistllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 04:56:10",
            "last_seen_utc": "2026-07-20 14:04:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854054": [
        {
            "ioc_value": "xbwtz.cleantruckchecksac.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 04:31:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854053": [
        {
            "ioc_value": "cleantruckchecksac.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 04:29:29",
            "last_seen_utc": "2026-07-20 13:02:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854052": [
        {
            "ioc_value": "dnrlgtwo.frizzhairforecast.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 04:24:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854051": [
        {
            "ioc_value": "alkh.jbgroup21.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 04:13:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854050": [
        {
            "ioc_value": "43.143.7.85:5672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 04:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854048": [
        {
            "ioc_value": "122.51.215.90:15672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 04:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854049": [
        {
            "ioc_value": "103.236.95.191:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 04:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854047": [
        {
            "ioc_value": "124.220.6.158:123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 04:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854046": [
        {
            "ioc_value": "103.142.147.19:59518",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 04:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854044": [
        {
            "ioc_value": "marblewavegate.thorniva.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 03:28:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854045": [
        {
            "ioc_value": "silica4path.lunavera.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 03:28:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854043": [
        {
            "ioc_value": "hrykp.varzeshlife.ir",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 03:23:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854042": [
        {
            "ioc_value": "pylonstaticbase.thorniva.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 03:13:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854041": [
        {
            "ioc_value": "auyc.pikachuplush.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 03:06:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854039": [
        {
            "ioc_value": "139.199.89.128:45251",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 03:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854040": [
        {
            "ioc_value": "139.199.89.128:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 03:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854038": [
        {
            "ioc_value": "124.220.6.158:8097",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 03:05:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854036": [
        {
            "ioc_value": "pikachuplush.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 03:04:30",
            "last_seen_utc": "2026-07-21 15:03:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854037": [
        {
            "ioc_value": "fby6y3nd.illuigiitaliancuisine.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 03:04:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854035": [
        {
            "ioc_value": "oceanicmesh7.thorniva.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 03:03:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854034": [
        {
            "ioc_value": "illuigiitaliancuisine.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 03:02:52",
            "last_seen_utc": "2026-07-20 03:03:55",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1854033": [
        {
            "ioc_value": "g1wgxqj5.nextbahis.one",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 02:20:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854032": [
        {
            "ioc_value": "hnhdl.hazaratbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 02:20:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854031": [
        {
            "ioc_value": "clinkscalesdrugssc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 02:10:37",
            "last_seen_utc": "2026-07-20 02:11:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854030": [
        {
            "ioc_value": "gofq.phtaxiservices.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 02:09:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854027": [
        {
            "ioc_value": "103.142.147.19:5230",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 02:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854028": [
        {
            "ioc_value": "103.142.147.18:59518",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 02:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854029": [
        {
            "ioc_value": "120.76.143.184:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 02:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854026": [
        {
            "ioc_value": "103.142.147.17:59518",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 02:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854025": [
        {
            "ioc_value": "phtaxiservices.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 02:04:21",
            "last_seen_utc": "2026-07-21 14:03:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1854024": [
        {
            "ioc_value": "uxlcj.fontanayoga.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 01:20:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854023": [
        {
            "ioc_value": "ftvfx.faux-paws.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 01:18:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854021": [
        {
            "ioc_value": "canyonsyncbox.thorniva.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 01:18:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854022": [
        {
            "ioc_value": "vertex2urban.thorniva.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 01:18:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854020": [
        {
            "ioc_value": "8c21b2fbded2faeb6db2e7a20c513cdb",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.redline_stealer",
            "malware_alias": "RECORDSTEALER",
            "malware_printable": "RedLine Stealer",
            "first_seen_utc": "2026-07-20 01:16:13",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854017": [
        {
            "ioc_value": "52f56cc1abe3ed2f437aaae0c74f5db9",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-07-20 01:16:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854018": [
        {
            "ioc_value": "b59653f1e2b8dae784ca4211199d2887ea676d27e7af9d057a625cf9281c17e0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.redline_stealer",
            "malware_alias": "RECORDSTEALER",
            "malware_printable": "RedLine Stealer",
            "first_seen_utc": "2026-07-20 01:16:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854019": [
        {
            "ioc_value": "38b837cc5fe814ca9580f9029386aa405f8e94df",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.redline_stealer",
            "malware_alias": "RECORDSTEALER",
            "malware_printable": "RedLine Stealer",
            "first_seen_utc": "2026-07-20 01:16:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854014": [
        {
            "ioc_value": "9c986d7e311ce1e8db7bd65b8271a87d",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-20 01:16:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854015": [
        {
            "ioc_value": "5f85e22acb86ebc9031256efb11af9f1eed58621312a0c0bf448fe699e809c92",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-07-20 01:16:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854016": [
        {
            "ioc_value": "196515f98d4a043751629ffdc6e4fc371391b5b3",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-07-20 01:16:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854010": [
        {
            "ioc_value": "5a8031f3c9ff3c65ebaa0aa60f9e59feba83c71c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.phorpiex",
            "malware_alias": "Tldr,Trik,TwizT,phorphiex",
            "malware_printable": "Phorpiex",
            "first_seen_utc": "2026-07-20 01:16:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854011": [
        {
            "ioc_value": "b0c4fe17a83df1621ce3db824684bb55",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.phorpiex",
            "malware_alias": "Tldr,Trik,TwizT,phorphiex",
            "malware_printable": "Phorpiex",
            "first_seen_utc": "2026-07-20 01:16:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854012": [
        {
            "ioc_value": "40c98ff9673f67cfa82d9e2e16a2e55644f71fec87e2d92f25821a2b917f8145",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-20 01:16:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854013": [
        {
            "ioc_value": "5c542d609013e48e6095af6ce5ef28208a35bb3f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-20 01:16:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854007": [
        {
            "ioc_value": "0bf07f316fe80ace56c947a2021e56a07dab0d6b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-07-20 01:16:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854008": [
        {
            "ioc_value": "d0b2dbfbc3a1d6474628f5268cf884fc",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-07-20 01:16:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854009": [
        {
            "ioc_value": "2ac492ce3b66a7979ceba5f26c594f0a69698d19b2ffdb56ac8b741dc30f8e5e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.phorpiex",
            "malware_alias": "Tldr,Trik,TwizT,phorphiex",
            "malware_printable": "Phorpiex",
            "first_seen_utc": "2026-07-20 01:16:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854004": [
        {
            "ioc_value": "602862693c2edba1df17afd61b4fcdc3a5ca139f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-20 01:16:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854005": [
        {
            "ioc_value": "0561a3921c93fe5913454241362e80e2",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-20 01:16:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854006": [
        {
            "ioc_value": "2c292ea5d66b3aa9b531e60f55d6af341d101961a649614d022111ff743492f3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-07-20 01:16:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854003": [
        {
            "ioc_value": "e6f4c46f2a72a4d8b1eda2c2c431c64d73eae7057221b35a6fc16138e4dc4d43",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-20 01:15:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854000": [
        {
            "ioc_value": "e85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-07-20 01:15:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854001": [
        {
            "ioc_value": "16646bfd7f6554cd170fb373ce813c24f37e829e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-07-20 01:15:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1854002": [
        {
            "ioc_value": "f8e68cddf13a94d821a4b265172a0e32",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-07-20 01:15:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1853999": [
        {
            "ioc_value": "5d11d7b9b175695c197014bc6aa2fbdb",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-07-20 01:15:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1853997": [
        {
            "ioc_value": "a86c023a02f1454738b39f753f50777c238b4ea296ffc76cd41c3059f216be10",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-07-20 01:15:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1853998": [
        {
            "ioc_value": "c25b20a5f15a0f69e0343b539bb4408a4e3739db",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-07-20 01:15:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1853995": [
        {
            "ioc_value": "103.142.147.17:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 01:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853996": [
        {
            "ioc_value": "103.142.147.17:5230",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 01:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853994": [
        {
            "ioc_value": "117.72.175.125:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 01:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853993": [
        {
            "ioc_value": "117.72.39.83:58080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 01:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853992": [
        {
            "ioc_value": "vqwj.phimmoichilla.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 01:03:39",
            "last_seen_utc": "2026-07-21 13:02:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853991": [
        {
            "ioc_value": "basalt9logic.thorniva.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 00:58:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853990": [
        {
            "ioc_value": "quartz5prism.veloria.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 00:43:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853989": [
        {
            "ioc_value": "dbomd.famscargo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 00:20:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853988": [
        {
            "ioc_value": "ijm1e9p4.chrisbrownstlouis.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 00:10:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853987": [
        {
            "ioc_value": "chrisbrownstlouis.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 00:09:57",
            "last_seen_utc": "2026-07-20 00:10:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "20July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1853985": [
        {
            "ioc_value": "sonicpathhub.veloria.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 00:08:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853983": [
        {
            "ioc_value": "116.198.233.179:3344",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 00:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853984": [
        {
            "ioc_value": "117.72.175.125:58888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 00:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853981": [
        {
            "ioc_value": "117.72.39.83:20081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 00:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853982": [
        {
            "ioc_value": "116.198.233.179:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-20 00:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853979": [
        {
            "ioc_value": "dtzu.patxisdublin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 00:03:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853978": [
        {
            "ioc_value": "patxisdublin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-20 00:02:47",
            "last_seen_utc": "2026-07-21 12:02:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853972": [
        {
            "ioc_value": "http://192.162.199.186/aB7xTy2N/mAjOR.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-07-19 23:45:09",
            "last_seen_utc": "2026-07-21 06:50:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amadey",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853971": [
        {
            "ioc_value": "http://196.251.107.186/qK3mRv9L/pLdWr.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-07-19 23:45:06",
            "last_seen_utc": "2026-07-21 06:50:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amadey",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853969": [
        {
            "ioc_value": "8g7kgrp5.frisbeeburgerllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 23:23:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853968": [
        {
            "ioc_value": "imrmd.drdavidzweiback.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 23:17:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853967": [
        {
            "ioc_value": "192.197.113.54:332",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-19 23:15:44",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e6f4c46f2a72a4d8b1eda2c2c431c64d73eae7057221b35a6fc16138e4dc4d43/",
            "tags": "valleyrat_s2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853966": [
        {
            "ioc_value": "117.72.181.104:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 23:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853965": [
        {
            "ioc_value": "117.72.39.83:28395",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 23:05:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853962": [
        {
            "ioc_value": "moszp.jetbet.download",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 22:35:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853961": [
        {
            "ioc_value": "edtbi.jetbet.download",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 22:27:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853960": [
        {
            "ioc_value": "zwhun.hazaratbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 22:22:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853959": [
        {
            "ioc_value": "wxfwe0h3.chrisbrowndetroit.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 22:10:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853958": [
        {
            "ioc_value": "chrisbrowndetroit.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 22:09:34",
            "last_seen_utc": "2026-07-19 22:10:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853956": [
        {
            "ioc_value": "117.72.39.83:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 22:05:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853955": [
        {
            "ioc_value": "164.92.79.49:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-19 22:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853954": [
        {
            "ioc_value": "45.136.13.247:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 22:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853952": [
        {
            "ioc_value": "154.219.115.123:60002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 22:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853953": [
        {
            "ioc_value": "45.136.13.247:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 22:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853951": [
        {
            "ioc_value": "wz43qign.houseofhakka.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 22:04:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853950": [
        {
            "ioc_value": "houseofhakka.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 22:03:22",
            "last_seen_utc": "2026-07-19 22:03:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "19July2026,ClearFake,Commandline,MacOS",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1853949": [
        {
            "ioc_value": "154.82.93.242:778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-07-19 22:00:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853948": [
        {
            "ioc_value": "194.156.79.151:55615",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.redline_stealer",
            "malware_alias": "RECORDSTEALER",
            "malware_printable": "RedLine Stealer",
            "first_seen_utc": "2026-07-19 21:50:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RedLineStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853947": [
        {
            "ioc_value": "qpduk.hazaratbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 21:48:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853946": [
        {
            "ioc_value": "vectorpointbit.veloria.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 21:48:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853945": [
        {
            "ioc_value": "silicon8host.veloria.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 21:33:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853930": [
        {
            "ioc_value": "alpha4gateweb.glenmora.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 21:08:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853928": [
        {
            "ioc_value": "38.242.212.5:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 21:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853929": [
        {
            "ioc_value": "38.242.212.5:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 21:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853927": [
        {
            "ioc_value": "38.242.212.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 21:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853926": [
        {
            "ioc_value": "yvryz.gepco-energy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:48:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853925": [
        {
            "ioc_value": "yferx.gepco-energy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:43:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853924": [
        {
            "ioc_value": "xxklt.gamehazarat.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:41:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853923": [
        {
            "ioc_value": "cucumber-oslo.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-07-19 20:39:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/7502ed3956c621d9442e51343a9d9fd22fb080d1a9edcffc1386901ebb4da9ec/",
            "tags": "NWHStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853922": [
        {
            "ioc_value": "cyberflux9unit.glenmora.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:38:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853921": [
        {
            "ioc_value": "atibr.gamehazarat.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:37:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853920": [
        {
            "ioc_value": "konr.domirunway.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:36:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853919": [
        {
            "ioc_value": "oqjvp.gamehazarat.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:28:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853918": [
        {
            "ioc_value": "etaru.oasis-active.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:18:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853917": [
        {
            "ioc_value": "oasis-active.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:17:22",
            "last_seen_utc": "2026-07-19 20:18:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853916": [
        {
            "ioc_value": "canss.mountoliveccc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:16:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853915": [
        {
            "ioc_value": "mountoliveccc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:15:31",
            "last_seen_utc": "2026-07-19 20:15:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853914": [
        {
            "ioc_value": "uwaho.midiowagrowth.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:14:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853913": [
        {
            "ioc_value": "midiowagrowth.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:12:53",
            "last_seen_utc": "2026-07-19 20:13:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853730": [
        {
            "ioc_value": "195.201.63.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:48",
            "last_seen_utc": "2026-07-20 07:51:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d4e81a7304049c20e0b606220ff924dc48c70d46a8ab466c97d7c6a896e886f5/",
            "tags": "c2,vidar",
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1853731": [
        {
            "ioc_value": "https://195.201.63.48/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:47",
            "last_seen_utc": "2026-07-20 07:50:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d4e81a7304049c20e0b606220ff924dc48c70d46a8ab466c97d7c6a896e886f5/",
            "tags": "c2,vidar",
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1853732": [
        {
            "ioc_value": "unixcheats.shop",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-19 20:10:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1853733": [
        {
            "ioc_value": "https://frolen.life/def.ps1",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-19 20:10:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/76d750e2ddfed6f984d95ab0419a085e21f124924c4ab64be5732a1d93719299",
            "tags": null,
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1853734": [
        {
            "ioc_value": "frolen.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-19 20:10:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/76d750e2ddfed6f984d95ab0419a085e21f124924c4ab64be5732a1d93719299",
            "tags": null,
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1853735": [
        {
            "ioc_value": "https://telegram.me/f4g7ha",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://bazaar.abuse.ch/sample/76d750e2ddfed6f984d95ab0419a085e21f124924c4ab64be5732a1d93719299",
            "tags": "c2,vidar",
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1853736": [
        {
            "ioc_value": "rgb.arizonafamilylawfirm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:43",
            "last_seen_utc": "2026-07-19 12:28:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/76d750e2ddfed6f984d95ab0419a085e21f124924c4ab64be5732a1d93719299",
            "tags": "c2,vidar",
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1853751": [
        {
            "ioc_value": "167.172.80.107:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 20:10:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853788": [
        {
            "ioc_value": "137.184.135.42:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 20:10:38",
            "last_seen_utc": "2026-07-21 08:12:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853792": [
        {
            "ioc_value": "161.35.125.247:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 20:10:35",
            "last_seen_utc": "2026-07-20 13:46:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853793": [
        {
            "ioc_value": "168.144.135.136:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 20:10:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853809": [
        {
            "ioc_value": "159.65.143.171:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 20:10:28",
            "last_seen_utc": "2026-07-21 01:58:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853823": [
        {
            "ioc_value": "http://telco.snovabits.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-19 20:10:21",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853856": [
        {
            "ioc_value": "https://stac.com.vn/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-19 20:10:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/stac.com.vn",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1853858": [
        {
            "ioc_value": "babydiapersinturkey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:19",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,gate",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853859": [
        {
            "ioc_value": "bappytechlab.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853860": [
        {
            "ioc_value": "blocuriizolatetermic.primariapetrosani.ro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853861": [
        {
            "ioc_value": "casadesignsrl.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853862": [
        {
            "ioc_value": "cc-roofingco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853863": [
        {
            "ioc_value": "corambiente.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853864": [
        {
            "ioc_value": "dailyinterior.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853865": [
        {
            "ioc_value": "daoyiyuan.cn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853866": [
        {
            "ioc_value": "datakepri.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853867": [
        {
            "ioc_value": "euregio-camper.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853868": [
        {
            "ioc_value": "guiasantosdumont.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853869": [
        {
            "ioc_value": "instantfixservices.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853870": [
        {
            "ioc_value": "lagrandefm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853871": [
        {
            "ioc_value": "lucianasalomao.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853872": [
        {
            "ioc_value": "mazradioaurora.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853873": [
        {
            "ioc_value": "mobilitate.primariapetrosani.ro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853874": [
        {
            "ioc_value": "moroneyaccountants.ie",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853875": [
        {
            "ioc_value": "mrinterior.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:10:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853876": [
        {
            "ioc_value": "nr-7releases.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:09:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853877": [
        {
            "ioc_value": "radiozona94fm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:09:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853878": [
        {
            "ioc_value": "reelwalestudio.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:09:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853879": [
        {
            "ioc_value": "rolems.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:09:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853881": [
        {
            "ioc_value": "rumahlift.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:09:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853880": [
        {
            "ioc_value": "roofing-clearwater.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:09:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853882": [
        {
            "ioc_value": "salariadvogados.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:09:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853883": [
        {
            "ioc_value": "soccerpunter.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:09:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853884": [
        {
            "ioc_value": "toufafashion.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:09:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853885": [
        {
            "ioc_value": "yourhomeguide.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 20:09:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar,WordPress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1853895": [
        {
            "ioc_value": "45fb50f074613b46672fac2ce2f30f1dd5f4e15a3d7f1fd53c333b1e198dbbc3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.unidentified_001",
            "malware_alias": null,
            "malware_printable": "Unidentified macOS 001 (UnionCryptoTrader)",
            "first_seen_utc": "2026-07-19 20:09:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/45fb50f074613b46672fac2ce2f30f1dd5f4e15a3d7f1fd53c333b1e198dbbc3",
            "tags": "AMOS,ClickFix,macOS,stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853907": [
        {
            "ioc_value": "137.184.135.42:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 20:09:47",
            "last_seen_utc": "2026-07-21 16:25:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853912": [
        {
            "ioc_value": "38.242.212.5:1390",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 20:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853910": [
        {
            "ioc_value": "154.219.115.123:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 20:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853911": [
        {
            "ioc_value": "1.92.135.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 20:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853909": [
        {
            "ioc_value": "104.245.245.146:5202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ave_maria",
            "malware_alias": "AVE_MARIA,AveMariaRAT,Warzone RAT,WarzoneRAT,avemaria",
            "malware_printable": "Ave Maria",
            "first_seen_utc": "2026-07-19 20:05:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AveMariaRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853908": [
        {
            "ioc_value": "w8sxay63.varzeshlife.ir",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 20:04:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853906": [
        {
            "ioc_value": "ivclr.mango-sushi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 19:56:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853905": [
        {
            "ioc_value": "ikyu.domirunway.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 19:56:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853904": [
        {
            "ioc_value": "89.223.24.227:52709",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-07-19 19:45:39",
            "last_seen_utc": "2026-07-21 17:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853903": [
        {
            "ioc_value": "213.160.77.221:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-19 19:44:23",
            "last_seen_utc": "2026-07-21 17:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853902": [
        {
            "ioc_value": "209.160.115.136:8624",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-19 19:44:19",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853901": [
        {
            "ioc_value": "178.105.144.206:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 19:43:50",
            "last_seen_utc": "2026-07-21 17:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853900": [
        {
            "ioc_value": "159.65.232.209:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-19 19:43:41",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853899": [
        {
            "ioc_value": "157.230.235.215:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-19 19:43:40",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853898": [
        {
            "ioc_value": "14.22.75.6:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-19 19:43:26",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853897": [
        {
            "ioc_value": "fbbzh.mango-sushi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 19:40:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853896": [
        {
            "ioc_value": "mango-sushi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 19:39:43",
            "last_seen_utc": "2026-07-19 19:55:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "19July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1853894": [
        {
            "ioc_value": "litsotravels.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 19:29:43",
            "last_seen_utc": "2026-07-19 19:29:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853893": [
        {
            "ioc_value": "koin99.link",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 19:19:43",
            "last_seen_utc": "2026-07-19 19:20:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853892": [
        {
            "ioc_value": "istudiosgl.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 19:14:32",
            "last_seen_utc": "2026-07-19 19:14:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853891": [
        {
            "ioc_value": "cydm.domirunway.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 19:10:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853890": [
        {
            "ioc_value": "domirunway.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 19:09:30",
            "last_seen_utc": "2026-07-19 20:36:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853889": [
        {
            "ioc_value": "divoraworld.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 19:08:21",
            "last_seen_utc": "2026-07-19 19:09:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853888": [
        {
            "ioc_value": "1.92.135.168:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 19:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853887": [
        {
            "ioc_value": "154.219.115.123:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 19:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853886": [
        {
            "ioc_value": "154.219.115.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 19:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853857": [
        {
            "ioc_value": "zenithlogicbase.glenmora.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 18:33:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853855": [
        {
            "ioc_value": "fsjkul62.onjabet1.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 18:21:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853854": [
        {
            "ioc_value": "bwwxd.polarstartire.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 18:15:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853853": [
        {
            "ioc_value": "https://thebusinesswebclub.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 18:15:02",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853852": [
        {
            "ioc_value": "polarstartire.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 18:13:49",
            "last_seen_utc": "2026-07-21 17:04:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853851": [
        {
            "ioc_value": "wnbl.divanailsachse.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 18:12:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853850": [
        {
            "ioc_value": "kelforge6ix.immer-weeping.garden",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 18:08:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853848": [
        {
            "ioc_value": "divanailsachse.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 18:07:48",
            "last_seen_utc": "2026-07-19 18:07:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "19July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1853849": [
        {
            "ioc_value": "divanailsachse.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 18:07:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853847": [
        {
            "ioc_value": "umq3dj7m.tampabayspin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 18:05:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853846": [
        {
            "ioc_value": "101.33.225.32:888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 18:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853844": [
        {
            "ioc_value": "81.70.21.248:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 18:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853845": [
        {
            "ioc_value": "82.156.139.85:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 18:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853843": [
        {
            "ioc_value": "81.70.21.248:5672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 18:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853842": [
        {
            "ioc_value": "64.90.17.181:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 18:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853839": [
        {
            "ioc_value": "https://qar.arizonafamilylawfirm.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 17:27:03",
            "last_seen_utc": "2026-07-21 17:26:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "bhipk,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853840": [
        {
            "ioc_value": "qar.arizonafamilylawfirm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 17:27:03",
            "last_seen_utc": "2026-07-21 17:26:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "bhipk,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853836": [
        {
            "ioc_value": "https://laplateforme93-rh.fr/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 17:15:02",
            "last_seen_utc": "2026-07-19 19:30:16",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1853835": [
        {
            "ioc_value": "playantwatch.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 17:13:07",
            "last_seen_utc": "2026-07-21 16:04:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853833": [
        {
            "ioc_value": "faux-paws.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 17:05:07",
            "last_seen_utc": "2026-07-20 01:18:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853811": [
        {
            "ioc_value": "famscargo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 16:04:38",
            "last_seen_utc": "2026-07-20 00:17:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853767": [
        {
            "ioc_value": "fontanayoga.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 13:03:05",
            "last_seen_utc": "2026-07-20 01:19:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853765": [
        {
            "ioc_value": "markol.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_webinject",
            "malware_alias": null,
            "malware_printable": "Unknown Webinject",
            "first_seen_utc": "2026-07-19 12:22:05",
            "last_seen_utc": "2026-07-20 13:26:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1853763": [
        {
            "ioc_value": "gepco-energy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 12:10:47",
            "last_seen_utc": "2026-07-19 20:46:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853747": [
        {
            "ioc_value": "frizzhairforecast.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 11:09:59",
            "last_seen_utc": "2026-07-20 18:11:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "19July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1853729": [
        {
            "ioc_value": "154.12.85.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 10:16:42",
            "last_seen_utc": "2026-07-20 09:14:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853728": [
        {
            "ioc_value": "47.116.60.211:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 10:16:28",
            "last_seen_utc": "2026-07-20 09:14:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853710": [
        {
            "ioc_value": "167.172.80.107:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 10:14:28",
            "last_seen_utc": "2026-07-21 17:50:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853711": [
        {
            "ioc_value": "161.35.125.247:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 10:14:27",
            "last_seen_utc": "2026-07-21 16:39:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853712": [
        {
            "ioc_value": "159.65.143.171:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 10:14:27",
            "last_seen_utc": "2026-07-21 17:41:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853713": [
        {
            "ioc_value": "168.144.135.136:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 10:14:26",
            "last_seen_utc": "2026-07-21 17:44:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853715": [
        {
            "ioc_value": "137.184.135.42:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 10:14:25",
            "last_seen_utc": "2026-07-21 17:47:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853716": [
        {
            "ioc_value": "162.243.163.143:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 10:14:25",
            "last_seen_utc": "2026-07-21 16:37:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853726": [
        {
            "ioc_value": "frisbeeburgerllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 10:09:33",
            "last_seen_utc": "2026-07-19 23:20:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853719": [
        {
            "ioc_value": "bolesfarms.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 10:01:21",
            "last_seen_utc": "2026-07-20 04:56:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853718": [
        {
            "ioc_value": "91.92.47.95:56999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-19 09:46:24",
            "last_seen_utc": "2026-07-21 17:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853717": [
        {
            "ioc_value": "185.147.83.58:64213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 09:44:11",
            "last_seen_utc": "2026-07-21 17:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853702": [
        {
            "ioc_value": "jackpot168.de.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 09:00:22",
            "last_seen_utc": "2026-07-20 04:05:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "19July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1853700": [
        {
            "ioc_value": "coolriverpizzaca.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-19 08:49:34",
            "last_seen_utc": "2026-07-19 20:24:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "19July2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1853537": [
        {
            "ioc_value": "149.28.158.66:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-19 07:08:13",
            "last_seen_utc": "2026-07-20 21:57:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1853568": [
        {
            "ioc_value": "38.76.169.75:870",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 23:46:07",
            "last_seen_utc": "2026-07-21 17:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853567": [
        {
            "ioc_value": "130.94.34.66:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 23:45:54",
            "last_seen_utc": "2026-07-21 17:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853535": [
        {
            "ioc_value": "elizabethspizzadenton.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-18 19:55:59",
            "last_seen_utc": "2026-07-20 08:21:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853534": [
        {
            "ioc_value": "64.89.161.190:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 19:45:54",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853533": [
        {
            "ioc_value": "5.35.91.124:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-18 19:45:46",
            "last_seen_utc": "2026-07-21 17:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853531": [
        {
            "ioc_value": "198.23.185.95:20100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 19:44:24",
            "last_seen_utc": "2026-07-21 17:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853532": [
        {
            "ioc_value": "198.23.185.95:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 19:44:24",
            "last_seen_utc": "2026-07-21 17:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853530": [
        {
            "ioc_value": "193.93.193.135:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-18 19:44:20",
            "last_seen_utc": "2026-07-21 17:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853529": [
        {
            "ioc_value": "147.93.191.75:20100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 19:43:34",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853528": [
        {
            "ioc_value": "144.172.88.233:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-18 19:43:31",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852848": [
        {
            "ioc_value": "oosterhout.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-18 17:33:08",
            "last_seen_utc": "2026-07-20 10:10:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116935949654273518",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1853428": [
        {
            "ioc_value": "103.86.65.202:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 17:31:55",
            "last_seen_utc": "2026-07-21 17:46:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853427": [
        {
            "ioc_value": "15.224.128.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 17:31:42",
            "last_seen_utc": "2026-07-20 09:14:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853338": [
        {
            "ioc_value": "159.94.211.163:14443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 09:47:35",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853337": [
        {
            "ioc_value": "158.94.211.163:14443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 09:47:34",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853335": [
        {
            "ioc_value": "46.246.12.19:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 09:46:23",
            "last_seen_utc": "2026-07-21 17:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853334": [
        {
            "ioc_value": "45.55.98.175:60560",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-18 09:46:14",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853333": [
        {
            "ioc_value": "31.57.93.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-18 09:45:59",
            "last_seen_utc": "2026-07-21 17:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853331": [
        {
            "ioc_value": "217.217.97.111:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-18 09:45:49",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853330": [
        {
            "ioc_value": "2.59.132.84:7434",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 09:44:45",
            "last_seen_utc": "2026-07-21 17:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853329": [
        {
            "ioc_value": "198.23.185.95:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 09:44:41",
            "last_seen_utc": "2026-07-21 17:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853328": [
        {
            "ioc_value": "138.124.90.26:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-18 09:43:33",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853327": [
        {
            "ioc_value": "auth-id-browser.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-18 09:33:31",
            "last_seen_utc": "2026-07-20 12:56:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1853179": [
        {
            "ioc_value": "sei.ambiltogel.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-17 22:55:07",
            "last_seen_utc": "2026-07-21 17:26:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1853180": [
        {
            "ioc_value": "https://sei.ambiltogel.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-17 22:55:07",
            "last_seen_utc": "2026-07-21 17:26:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1852991": [
        {
            "ioc_value": "45.194.17.39:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-17 21:46:50",
            "last_seen_utc": "2026-07-21 17:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852912": [
        {
            "ioc_value": "20.2.87.168:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-17 21:05:07",
            "last_seen_utc": "2026-07-21 17:44:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1852892": [
        {
            "ioc_value": "62.109.10.128:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-17 19:45:58",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852890": [
        {
            "ioc_value": "46.225.160.243:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-17 19:45:49",
            "last_seen_utc": "2026-07-21 17:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852891": [
        {
            "ioc_value": "46.246.82.7:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-17 19:45:49",
            "last_seen_utc": "2026-07-21 17:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852889": [
        {
            "ioc_value": "221.212.219.56:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-17 19:45:23",
            "last_seen_utc": "2026-07-21 17:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852888": [
        {
            "ioc_value": "207.180.29.217:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:44:34",
            "last_seen_utc": "2026-07-21 17:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852887": [
        {
            "ioc_value": "198.23.185.95:50",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:44:27",
            "last_seen_utc": "2026-07-21 17:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852886": [
        {
            "ioc_value": "181.235.4.60:5010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:44:05",
            "last_seen_utc": "2026-07-21 17:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852885": [
        {
            "ioc_value": "178.83.226.199:9091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-17 19:44:03",
            "last_seen_utc": "2026-07-21 17:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852884": [
        {
            "ioc_value": "157.20.182.17:1665",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:43:48",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852883": [
        {
            "ioc_value": "15.235.149.212:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-17 19:43:41",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852881": [
        {
            "ioc_value": "147.93.191.75:50",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:43:39",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852882": [
        {
            "ioc_value": "149.104.110.202:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-17 19:43:39",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852880": [
        {
            "ioc_value": "104.249.10.121:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-17 19:43:17",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852879": [
        {
            "ioc_value": "104.168.0.147:1989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:43:15",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852872": [
        {
            "ioc_value": "175.43.223.223:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-17 18:05:06",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1852802": [
        {
            "ioc_value": "https://okx.kliksm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-17 11:10:08",
            "last_seen_utc": "2026-07-21 07:26:55",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1852801": [
        {
            "ioc_value": "okx.kliksm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-17 11:10:07",
            "last_seen_utc": "2026-07-21 07:26:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1852769": [
        {
            "ioc_value": "http://144.31.57.94/350be244a2f97a3a4ca8.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-07-17 09:14:30",
            "last_seen_utc": "2026-07-19 20:08:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "build1,c2,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1852752": [
        {
            "ioc_value": "103.43.18.230:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-17 07:30:32",
            "last_seen_utc": "2026-07-21 04:05:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852689": [
        {
            "ioc_value": "g3b4hjbg.calculadoracomisiones.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-16 23:50:53",
            "last_seen_utc": "2026-07-21 08:33:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1852688": [
        {
            "ioc_value": "wig5l9be.calirayalake.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-16 23:50:46",
            "last_seen_utc": "2026-07-20 18:03:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1852649": [
        {
            "ioc_value": "80.240.21.145:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 19:46:46",
            "last_seen_utc": "2026-07-21 17:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852648": [
        {
            "ioc_value": "64.177.120.228:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 19:46:37",
            "last_seen_utc": "2026-07-21 17:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852647": [
        {
            "ioc_value": "5.200.192.159:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-16 19:46:28",
            "last_seen_utc": "2026-07-21 17:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852646": [
        {
            "ioc_value": "45.32.90.122:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 19:46:15",
            "last_seen_utc": "2026-07-21 17:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852645": [
        {
            "ioc_value": "43.225.157.146:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 19:46:09",
            "last_seen_utc": "2026-07-21 17:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852644": [
        {
            "ioc_value": "217.60.241.10:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 19:45:50",
            "last_seen_utc": "2026-07-21 17:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852643": [
        {
            "ioc_value": "199.247.22.101:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 19:44:42",
            "last_seen_utc": "2026-07-21 17:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852642": [
        {
            "ioc_value": "194.32.142.225:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-16 19:44:38",
            "last_seen_utc": "2026-07-21 17:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852641": [
        {
            "ioc_value": "188.166.40.236:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 19:44:30",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852640": [
        {
            "ioc_value": "154.19.229.197:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-16 19:43:49",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852491": [
        {
            "ioc_value": "203.91.75.89:5005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-16 09:47:53",
            "last_seen_utc": "2026-07-21 17:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852490": [
        {
            "ioc_value": "85.120.217.235:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:46:58",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852489": [
        {
            "ioc_value": "64.89.161.190:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:46",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852486": [
        {
            "ioc_value": "5.56.25.238:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:37",
            "last_seen_utc": "2026-07-21 17:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852487": [
        {
            "ioc_value": "5.56.25.238:6723",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:37",
            "last_seen_utc": "2026-07-21 17:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852488": [
        {
            "ioc_value": "5.56.25.238:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:37",
            "last_seen_utc": "2026-07-21 17:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852485": [
        {
            "ioc_value": "37.60.239.250:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:12",
            "last_seen_utc": "2026-07-21 17:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852484": [
        {
            "ioc_value": "217.60.241.10:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:45:57",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852483": [
        {
            "ioc_value": "209.99.189.225:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:45:04",
            "last_seen_utc": "2026-07-21 17:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852482": [
        {
            "ioc_value": "207.180.250.181:20300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:44:58",
            "last_seen_utc": "2026-07-21 17:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852480": [
        {
            "ioc_value": "204.44.93.75:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-16 09:44:56",
            "last_seen_utc": "2026-07-21 17:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852481": [
        {
            "ioc_value": "204.44.93.75:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-16 09:44:56",
            "last_seen_utc": "2026-07-21 17:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852479": [
        {
            "ioc_value": "192.142.37.30:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:44:40",
            "last_seen_utc": "2026-07-21 17:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852478": [
        {
            "ioc_value": "154.19.229.85:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-16 09:43:52",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852477": [
        {
            "ioc_value": "147.124.219.0:8805",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:43:47",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852475": [
        {
            "ioc_value": "109.123.230.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:43:25",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852476": [
        {
            "ioc_value": "109.123.230.199:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:43:25",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852474": [
        {
            "ioc_value": "104.168.134.25:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:43:19",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851423": [
        {
            "ioc_value": "5m1ugnlr.yekbetyek.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-16 06:36:29",
            "last_seen_utc": "2026-07-20 04:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851421": [
        {
            "ioc_value": "ohdvttqo.tampabayspin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-16 06:15:25",
            "last_seen_utc": "2026-07-19 18:02:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851412": [
        {
            "ioc_value": "cdctvukr.taktikkbet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-16 05:30:31",
            "last_seen_utc": "2026-07-21 04:27:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851370": [
        {
            "ioc_value": "120.192.20.243:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-07-16 04:25:10",
            "last_seen_utc": "2026-07-20 06:05:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "24444,c2,censys,quasar",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1851316": [
        {
            "ioc_value": "vvopvrgbi.gamehazarat.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-15 21:55:15",
            "last_seen_utc": "2026-07-19 20:41:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851315": [
        {
            "ioc_value": "107.174.254.62:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-15 21:46:16",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851307": [
        {
            "ioc_value": "xpzjxywai.funxbet.casino",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-15 20:56:47",
            "last_seen_utc": "2026-07-21 01:28:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851303": [
        {
            "ioc_value": "tafhu17n.nextbahis.blog",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-15 20:36:09",
            "last_seen_utc": "2026-07-20 14:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851302": [
        {
            "ioc_value": "qzjihweyr.nextbahis.poker",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-15 20:27:34",
            "last_seen_utc": "2026-07-20 15:21:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851289": [
        {
            "ioc_value": "64.23.182.12:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 19:46:03",
            "last_seen_utc": "2026-07-21 17:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851290": [
        {
            "ioc_value": "64.89.160.127:2026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 19:46:03",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851288": [
        {
            "ioc_value": "5.56.25.238:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 19:45:56",
            "last_seen_utc": "2026-07-21 17:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851286": [
        {
            "ioc_value": "216.250.249.83:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 19:45:24",
            "last_seen_utc": "2026-07-21 17:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851287": [
        {
            "ioc_value": "216.250.249.83:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 19:45:24",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851284": [
        {
            "ioc_value": "204.44.93.75:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 19:44:38",
            "last_seen_utc": "2026-07-21 17:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851285": [
        {
            "ioc_value": "204.44.93.75:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 19:44:38",
            "last_seen_utc": "2026-07-21 17:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851283": [
        {
            "ioc_value": "185.212.131.22:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 19:44:19",
            "last_seen_utc": "2026-07-21 17:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851282": [
        {
            "ioc_value": "185.115.164.59:7723",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 19:44:13",
            "last_seen_utc": "2026-07-21 17:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851281": [
        {
            "ioc_value": "178.73.192.16:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-15 19:44:08",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851280": [
        {
            "ioc_value": "162.35.175.224:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 19:43:55",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851279": [
        {
            "ioc_value": "104.225.104.237:3020",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-15 19:43:16",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851278": [
        {
            "ioc_value": "104.168.134.25:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 19:43:15",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851277": [
        {
            "ioc_value": "103.83.86.48:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 19:43:14",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851276": [
        {
            "ioc_value": "103.11.41.10:17328",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 19:43:06",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851275": [
        {
            "ioc_value": "ajzzqcazg.nextbahis.one",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-15 19:37:43",
            "last_seen_utc": "2026-07-21 17:03:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851211": [
        {
            "ioc_value": "dohnx2bh.hazaratbet.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-15 15:35:23",
            "last_seen_utc": "2026-07-21 02:35:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851168": [
        {
            "ioc_value": "kxxpvutsn.derbi.promo",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-15 13:41:40",
            "last_seen_utc": "2026-07-20 18:02:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1850972": [
        {
            "ioc_value": "82.47.101.76:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-15 09:46:24",
            "last_seen_utc": "2026-07-21 17:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850971": [
        {
            "ioc_value": "74.0.32.137:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 09:46:18",
            "last_seen_utc": "2026-07-21 17:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850969": [
        {
            "ioc_value": "216.250.254.245:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 09:45:31",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850967": [
        {
            "ioc_value": "213.152.186.188:18856",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 09:44:48",
            "last_seen_utc": "2026-07-21 17:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850966": [
        {
            "ioc_value": "204.44.69.214:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 09:44:41",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850965": [
        {
            "ioc_value": "192.255.195.147:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 09:44:28",
            "last_seen_utc": "2026-07-21 17:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850964": [
        {
            "ioc_value": "191.104.219.22:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-07-15 09:44:26",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850962": [
        {
            "ioc_value": "124.198.132.119:5220",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 09:43:27",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850961": [
        {
            "ioc_value": "104.225.104.237:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-15 09:43:17",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850960": [
        {
            "ioc_value": "103.11.41.10:62452",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 09:43:08",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850959": [
        {
            "ioc_value": "103.11.41.10:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 09:43:06",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850906": [
        {
            "ioc_value": "118.89.69.45:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-15 07:41:18",
            "last_seen_utc": "2026-07-20 09:14:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850805": [
        {
            "ioc_value": "217.217.97.75:8787",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 05:20:03",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850746": [
        {
            "ioc_value": "206.119.178.109:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-14 21:46:37",
            "last_seen_utc": "2026-07-21 17:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850712": [
        {
            "ioc_value": "87.232.83.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-14 19:46:04",
            "last_seen_utc": "2026-07-21 17:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850711": [
        {
            "ioc_value": "85.206.168.238:4646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 19:46:01",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850710": [
        {
            "ioc_value": "64.89.161.190:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:45:50",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850709": [
        {
            "ioc_value": "45.74.7.107:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 19:45:34",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850708": [
        {
            "ioc_value": "45.155.69.254:1488",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 19:45:31",
            "last_seen_utc": "2026-07-21 17:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850707": [
        {
            "ioc_value": "217.60.241.10:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:45:13",
            "last_seen_utc": "2026-07-21 17:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850704": [
        {
            "ioc_value": "192.169.7.60:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:44:18",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850705": [
        {
            "ioc_value": "192.169.7.60:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:44:18",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850703": [
        {
            "ioc_value": "191.101.130.245:5199",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:44:17",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850702": [
        {
            "ioc_value": "185.223.57.86:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:44:12",
            "last_seen_utc": "2026-07-21 17:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850701": [
        {
            "ioc_value": "185.115.164.59:53353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 19:44:06",
            "last_seen_utc": "2026-07-21 17:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850700": [
        {
            "ioc_value": "158.94.211.63:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 19:43:47",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850699": [
        {
            "ioc_value": "155.103.71.115:15608",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 19:43:43",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850698": [
        {
            "ioc_value": "151.145.34.33:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-07-14 19:43:39",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850697": [
        {
            "ioc_value": "147.182.143.172:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-14 19:43:36",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850696": [
        {
            "ioc_value": "147.124.214.170:4056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:43:35",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850695": [
        {
            "ioc_value": "103.83.86.48:1616",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 19:43:14",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850666": [
        {
            "ioc_value": "45.55.232.28:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 18:05:08",
            "last_seen_utc": "2026-07-21 17:45:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1850270": [
        {
            "ioc_value": "rrfljnpj.site-takhtenard-sharti-betland.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-14 13:03:34",
            "last_seen_utc": "2026-07-21 02:26:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1850217": [
        {
            "ioc_value": "96.9.231.213:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:47:18",
            "last_seen_utc": "2026-07-21 17:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850216": [
        {
            "ioc_value": "47.109.181.81:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:46:38",
            "last_seen_utc": "2026-07-21 17:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850215": [
        {
            "ioc_value": "35.78.107.61:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:46:14",
            "last_seen_utc": "2026-07-21 17:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850214": [
        {
            "ioc_value": "216.9.225.38:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 09:45:59",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850213": [
        {
            "ioc_value": "204.44.69.214:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 09:44:51",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850212": [
        {
            "ioc_value": "20.226.72.17:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:44:48",
            "last_seen_utc": "2026-07-21 17:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850211": [
        {
            "ioc_value": "198.135.49.85:62025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 09:44:41",
            "last_seen_utc": "2026-07-21 17:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850210": [
        {
            "ioc_value": "192.255.195.147:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 09:44:34",
            "last_seen_utc": "2026-07-21 17:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850209": [
        {
            "ioc_value": "185.115.164.60:65531",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 09:44:21",
            "last_seen_utc": "2026-07-21 17:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850208": [
        {
            "ioc_value": "185.115.164.60:11883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 09:44:19",
            "last_seen_utc": "2026-07-21 17:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850207": [
        {
            "ioc_value": "172.232.122.241:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:44:05",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850206": [
        {
            "ioc_value": "164.90.202.48:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:44:01",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850205": [
        {
            "ioc_value": "139.199.87.99:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:43:35",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850204": [
        {
            "ioc_value": "130.49.214.23:59838",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 09:43:30",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850203": [
        {
            "ioc_value": "118.89.121.171:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:43:26",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849979": [
        {
            "ioc_value": "85.8.149.156:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 19:45:28",
            "last_seen_utc": "2026-07-21 17:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849978": [
        {
            "ioc_value": "5.175.218.71:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:45:13",
            "last_seen_utc": "2026-07-21 17:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849977": [
        {
            "ioc_value": "45.59.114.202:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-13 19:45:03",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849976": [
        {
            "ioc_value": "37.235.54.142:53236",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-13 19:44:54",
            "last_seen_utc": "2026-07-21 17:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849974": [
        {
            "ioc_value": "23.27.52.106:28736",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-13 19:44:48",
            "last_seen_utc": "2026-07-21 17:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849973": [
        {
            "ioc_value": "212.180.120.35:1604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 19:44:18",
            "last_seen_utc": "2026-07-21 17:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849972": [
        {
            "ioc_value": "204.44.69.214:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:44:13",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849970": [
        {
            "ioc_value": "192.255.195.147:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:44:03",
            "last_seen_utc": "2026-07-21 17:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849971": [
        {
            "ioc_value": "192.255.195.147:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:44:03",
            "last_seen_utc": "2026-07-21 17:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849968": [
        {
            "ioc_value": "188.209.158.161:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 19:44:00",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849969": [
        {
            "ioc_value": "188.209.158.161:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 19:44:00",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849967": [
        {
            "ioc_value": "185.212.131.27:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-13 19:43:57",
            "last_seen_utc": "2026-07-21 17:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849966": [
        {
            "ioc_value": "172.86.119.141:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-13 19:43:44",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849965": [
        {
            "ioc_value": "128.90.105.247:7998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-13 19:43:19",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849964": [
        {
            "ioc_value": "113.31.102.219:21935",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:43:17",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849963": [
        {
            "ioc_value": "103.83.87.107:4098",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:43:11",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849797": [
        {
            "ioc_value": "rqsjaodh.site-asli-bedon-filter-1xbet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-13 16:18:29",
            "last_seen_utc": "2026-07-21 10:34:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1849768": [
        {
            "ioc_value": "2cca57zt.onjabet1.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-13 14:52:41",
            "last_seen_utc": "2026-07-21 03:29:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1849767": [
        {
            "ioc_value": "tzcy9ec8.onjabet1.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-13 14:51:29",
            "last_seen_utc": "2026-07-19 18:19:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1849758": [
        {
            "ioc_value": "133.18.165.80:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 14:05:50",
            "last_seen_utc": "2026-07-20 18:05:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/dc14aa1d739c79a92ae7342a7f6941aab24df1b03fedd0a99d9a57cd972d569d/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849759": [
        {
            "ioc_value": "133.18.165.80:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 14:05:50",
            "last_seen_utc": "2026-07-20 18:05:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/dc14aa1d739c79a92ae7342a7f6941aab24df1b03fedd0a99d9a57cd972d569d/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849751": [
        {
            "ioc_value": "133.18.165.80:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 14:00:05",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849670": [
        {
            "ioc_value": "178.62.228.25:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-13 13:44:44",
            "last_seen_utc": "2026-07-20 09:59:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1849671": [
        {
            "ioc_value": "178.62.235.14:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-13 13:44:43",
            "last_seen_utc": "2026-07-20 09:58:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1849672": [
        {
            "ioc_value": "188.166.1.226:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-13 13:44:42",
            "last_seen_utc": "2026-07-20 09:58:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1849673": [
        {
            "ioc_value": "188.166.105.148:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-13 13:44:41",
            "last_seen_utc": "2026-07-20 09:45:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1849674": [
        {
            "ioc_value": "167.99.42.38:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-13 13:44:40",
            "last_seen_utc": "2026-07-20 08:57:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1849675": [
        {
            "ioc_value": "142.93.231.53:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-13 13:44:39",
            "last_seen_utc": "2026-07-20 10:00:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1849676": [
        {
            "ioc_value": "209.38.46.121:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-13 13:44:37",
            "last_seen_utc": "2026-07-20 10:00:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1849677": [
        {
            "ioc_value": "178.128.249.233:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-13 13:44:37",
            "last_seen_utc": "2026-07-20 09:59:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1849678": [
        {
            "ioc_value": "157.245.71.64:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-13 13:44:36",
            "last_seen_utc": "2026-07-20 09:58:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1849679": [
        {
            "ioc_value": "64.225.73.161:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-07-13 13:44:35",
            "last_seen_utc": "2026-07-20 10:00:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1849657": [
        {
            "ioc_value": "91.92.42.50:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-13 09:46:37",
            "last_seen_utc": "2026-07-21 17:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849656": [
        {
            "ioc_value": "216.9.225.38:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 09:45:31",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849655": [
        {
            "ioc_value": "211.159.223.14:22005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 09:44:45",
            "last_seen_utc": "2026-07-21 17:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849654": [
        {
            "ioc_value": "188.209.158.161:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 09:44:23",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849653": [
        {
            "ioc_value": "136.111.38.101:6932",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 09:43:27",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849567": [
        {
            "ioc_value": "d9xy3942.jetbet.download",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-13 05:51:30",
            "last_seen_utc": "2026-07-20 23:36:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1849551": [
        {
            "ioc_value": "pwuz.jadoou.lat",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-13 04:29:03",
            "last_seen_utc": "2026-07-21 08:35:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1849096": [
        {
            "ioc_value": "85.206.168.238:23501",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 19:46:07",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849094": [
        {
            "ioc_value": "45.198.224.93:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 19:45:37",
            "last_seen_utc": "2026-07-21 17:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849092": [
        {
            "ioc_value": "23.106.52.176:2489",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-12 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849093": [
        {
            "ioc_value": "23.106.52.176:3984",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-12 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849091": [
        {
            "ioc_value": "211.159.223.14:22003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 19:44:38",
            "last_seen_utc": "2026-07-21 17:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849090": [
        {
            "ioc_value": "178.73.218.4:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 19:44:04",
            "last_seen_utc": "2026-07-21 17:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849089": [
        {
            "ioc_value": "157.20.182.18:1665",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-12 19:43:47",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849088": [
        {
            "ioc_value": "137.220.152.132:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 19:43:29",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849087": [
        {
            "ioc_value": "137.220.152.131:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 19:43:28",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849086": [
        {
            "ioc_value": "104.164.46.55:62721",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-12 19:43:14",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849071": [
        {
            "ioc_value": "103.11.41.19:52811",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 19:43:09",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849072": [
        {
            "ioc_value": "103.11.41.19:64045",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 19:43:09",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849033": [
        {
            "ioc_value": "qevb.behtarin-site-shartbandi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-12 16:23:14",
            "last_seen_utc": "2026-07-21 06:33:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1848949": [
        {
            "ioc_value": "93.95.226.207:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-12 09:46:09",
            "last_seen_utc": "2026-07-21 17:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848946": [
        {
            "ioc_value": "45.61.149.187:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-12 09:45:32",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848947": [
        {
            "ioc_value": "45.61.149.187:8004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-12 09:45:32",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848948": [
        {
            "ioc_value": "45.61.149.187:8005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-12 09:45:32",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848945": [
        {
            "ioc_value": "45.198.224.94:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:45:30",
            "last_seen_utc": "2026-07-21 17:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848944": [
        {
            "ioc_value": "38.54.8.74:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:45:25",
            "last_seen_utc": "2026-07-21 17:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848943": [
        {
            "ioc_value": "27.102.137.139:465",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 09:45:16",
            "last_seen_utc": "2026-07-21 17:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848942": [
        {
            "ioc_value": "216.9.225.38:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 09:45:11",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848940": [
        {
            "ioc_value": "172.86.77.116:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 09:43:56",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848937": [
        {
            "ioc_value": "118.107.45.29:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-12 09:43:23",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848938": [
        {
            "ioc_value": "118.107.45.70:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-12 09:43:23",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848939": [
        {
            "ioc_value": "118.107.45.73:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-12 09:43:23",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848936": [
        {
            "ioc_value": "107.172.90.117:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:43:18",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848933": [
        {
            "ioc_value": "104.207.93.150:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-12 09:43:14",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848934": [
        {
            "ioc_value": "104.207.93.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-12 09:43:14",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848857": [
        {
            "ioc_value": "82.156.139.85:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-12 04:05:06",
            "last_seen_utc": "2026-07-20 09:14:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1848815": [
        {
            "ioc_value": "186.241.75.134:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 23:46:14",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848772": [
        {
            "ioc_value": "82.158.229.189:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:05",
            "last_seen_utc": "2026-07-21 17:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848773": [
        {
            "ioc_value": "82.158.229.30:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:05",
            "last_seen_utc": "2026-07-21 17:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848771": [
        {
            "ioc_value": "82.158.229.143:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:04",
            "last_seen_utc": "2026-07-21 17:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848770": [
        {
            "ioc_value": "62.109.10.128:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-11 19:45:53",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848769": [
        {
            "ioc_value": "45.74.7.201:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-11 19:45:41",
            "last_seen_utc": "2026-07-21 17:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848768": [
        {
            "ioc_value": "31.207.4.197:9872",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:45:23",
            "last_seen_utc": "2026-07-21 17:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848767": [
        {
            "ioc_value": "23.106.52.176:59838",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-11 19:45:19",
            "last_seen_utc": "2026-07-21 17:45:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848766": [
        {
            "ioc_value": "216.9.225.38:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-11 19:45:16",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848765": [
        {
            "ioc_value": "185.244.149.240:61443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-11 19:44:14",
            "last_seen_utc": "2026-07-21 17:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848764": [
        {
            "ioc_value": "178.104.249.136:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:43:59",
            "last_seen_utc": "2026-07-21 17:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848759": [
        {
            "ioc_value": "156.234.43.100:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848760": [
        {
            "ioc_value": "156.234.43.101:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848761": [
        {
            "ioc_value": "156.234.43.102:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848762": [
        {
            "ioc_value": "156.234.43.98:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848763": [
        {
            "ioc_value": "156.234.43.99:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848758": [
        {
            "ioc_value": "144.91.76.114:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-11 19:43:33",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848756": [
        {
            "ioc_value": "137.220.152.131:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:27",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848757": [
        {
            "ioc_value": "137.220.152.132:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:27",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848755": [
        {
            "ioc_value": "1.14.234.68:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:43:03",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848617": [
        {
            "ioc_value": "139.155.157.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 11:46:39",
            "last_seen_utc": "2026-07-21 17:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848616": [
        {
            "ioc_value": "123.58.64.57:50040",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 11:46:37",
            "last_seen_utc": "2026-07-21 17:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848615": [
        {
            "ioc_value": "115.190.237.175:6677",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 11:46:31",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848599": [
        {
            "ioc_value": "172.174.154.130:1024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 11:05:05",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1848583": [
        {
            "ioc_value": "137.220.194.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 09:46:53",
            "last_seen_utc": "2026-07-21 17:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848582": [
        {
            "ioc_value": "r0.erloro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 09:46:35",
            "last_seen_utc": "2026-07-21 17:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848581": [
        {
            "ioc_value": "89.144.10.64:1604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-11 09:46:21",
            "last_seen_utc": "2026-07-21 17:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848580": [
        {
            "ioc_value": "69.10.49.136:2005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-11 09:46:08",
            "last_seen_utc": "2026-07-21 17:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848578": [
        {
            "ioc_value": "66.97.33.99:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-11 09:46:07",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848579": [
        {
            "ioc_value": "67.211.221.131:65291",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-11 09:46:07",
            "last_seen_utc": "2026-07-21 17:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848575": [
        {
            "ioc_value": "103.195.238.98:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-11 09:43:11",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848482": [
        {
            "ioc_value": "157.20.182.81:421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-07-11 05:55:11",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848480": [
        {
            "ioc_value": "157.20.182.81:416",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-07-11 05:55:10",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848481": [
        {
            "ioc_value": "196.251.121.90:416",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-07-11 05:55:10",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848358": [
        {
            "ioc_value": "8.134.70.73:6111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 23:46:33",
            "last_seen_utc": "2026-07-21 17:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848357": [
        {
            "ioc_value": "137.220.194.15:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 23:46:08",
            "last_seen_utc": "2026-07-21 17:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848356": [
        {
            "ioc_value": "115.190.237.175:23333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 23:46:00",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848355": [
        {
            "ioc_value": "112.124.106.45:8887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 23:45:58",
            "last_seen_utc": "2026-07-21 17:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848289": [
        {
            "ioc_value": "93.115.172.235:7579",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-10 19:46:10",
            "last_seen_utc": "2026-07-21 17:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848288": [
        {
            "ioc_value": "87.232.83.18:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-10 19:46:04",
            "last_seen_utc": "2026-07-21 17:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848287": [
        {
            "ioc_value": "45.74.7.199:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 19:45:36",
            "last_seen_utc": "2026-07-21 17:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848286": [
        {
            "ioc_value": "45.74.7.191:1202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 19:45:35",
            "last_seen_utc": "2026-07-21 17:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848285": [
        {
            "ioc_value": "216.133.157.16:21935",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 19:45:12",
            "last_seen_utc": "2026-07-21 17:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848284": [
        {
            "ioc_value": "155.103.71.115:13508",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 19:43:41",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848283": [
        {
            "ioc_value": "144.31.117.38:47825",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-10 19:43:32",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848282": [
        {
            "ioc_value": "103.83.86.48:1818",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 19:43:13",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848062": [
        {
            "ioc_value": "bdm.kencangsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-10 13:27:06",
            "last_seen_utc": "2026-07-21 13:26:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "mp44s1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848061": [
        {
            "ioc_value": "https://bdm.kencangsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-10 13:27:05",
            "last_seen_utc": "2026-07-21 13:26:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "mp44s1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847999": [
        {
            "ioc_value": "101.42.255.92:2234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 11:46:34",
            "last_seen_utc": "2026-07-21 17:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847977": [
        {
            "ioc_value": "101.42.255.92:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 10:05:08",
            "last_seen_utc": "2026-07-21 17:46:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1847972": [
        {
            "ioc_value": "94.199.45.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:46:32",
            "last_seen_utc": "2026-07-21 17:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847971": [
        {
            "ioc_value": "85.206.168.238:26076",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:46:22",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847970": [
        {
            "ioc_value": "74.0.32.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-10 09:46:14",
            "last_seen_utc": "2026-07-21 17:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847969": [
        {
            "ioc_value": "54.65.16.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-10 09:46:07",
            "last_seen_utc": "2026-07-21 17:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847968": [
        {
            "ioc_value": "54.248.1.253:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-10 09:46:05",
            "last_seen_utc": "2026-07-21 17:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847967": [
        {
            "ioc_value": "45.74.7.195:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:45:53",
            "last_seen_utc": "2026-07-21 17:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847966": [
        {
            "ioc_value": "38.207.176.218:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-10 09:45:41",
            "last_seen_utc": "2026-07-21 17:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847965": [
        {
            "ioc_value": "207.180.250.181:10900",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-10 09:44:41",
            "last_seen_utc": "2026-07-21 17:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847964": [
        {
            "ioc_value": "20.204.61.204:21891",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:44:38",
            "last_seen_utc": "2026-07-21 17:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847963": [
        {
            "ioc_value": "179.43.149.253:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-10 09:44:08",
            "last_seen_utc": "2026-07-21 17:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847962": [
        {
            "ioc_value": "155.103.69.30:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:43:45",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847961": [
        {
            "ioc_value": "147.124.218.54:62025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-10 09:43:38",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847960": [
        {
            "ioc_value": "13.73.107.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:43:27",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847959": [
        {
            "ioc_value": "104.250.161.126:2061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-10 09:43:16",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847957": [
        {
            "ioc_value": "103.212.187.217:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-10 09:43:13",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847958": [
        {
            "ioc_value": "103.212.187.217:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-10 09:43:13",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847956": [
        {
            "ioc_value": "103.146.231.107:7771",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-10 09:43:12",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847955": [
        {
            "ioc_value": "100.31.133.28:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-10 09:43:03",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847878": [
        {
            "ioc_value": "38.54.61.225:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 03:46:14",
            "last_seen_utc": "2026-07-21 17:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847877": [
        {
            "ioc_value": "101.34.235.198:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 03:45:49",
            "last_seen_utc": "2026-07-21 17:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847868": [
        {
            "ioc_value": "158.178.230.77:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 03:10:21",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847854": [
        {
            "ioc_value": "wzkxsv5k.varzeshlife.ir",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-10 03:00:14",
            "last_seen_utc": "2026-07-21 04:32:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1847818": [
        {
            "ioc_value": "78.17.212.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 23:46:10",
            "last_seen_utc": "2026-07-21 17:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847817": [
        {
            "ioc_value": "59.110.23.216:8181",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 23:46:08",
            "last_seen_utc": "2026-07-21 17:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847753": [
        {
            "ioc_value": "37.72.172.58:4212",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 19:45:23",
            "last_seen_utc": "2026-07-21 17:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847752": [
        {
            "ioc_value": "216.9.225.38:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 19:45:12",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847751": [
        {
            "ioc_value": "213.209.159.91:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 19:44:37",
            "last_seen_utc": "2026-07-21 17:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847750": [
        {
            "ioc_value": "212.46.38.117:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-09 19:44:36",
            "last_seen_utc": "2026-07-21 17:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847749": [
        {
            "ioc_value": "185.244.149.240:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-09 19:44:12",
            "last_seen_utc": "2026-07-21 17:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847748": [
        {
            "ioc_value": "179.43.149.251:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 19:43:58",
            "last_seen_utc": "2026-07-21 17:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847747": [
        {
            "ioc_value": "156.244.11.247:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-09 19:43:41",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847746": [
        {
            "ioc_value": "155.103.71.115:13507",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 19:43:40",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847745": [
        {
            "ioc_value": "13.70.174.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 19:43:24",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847744": [
        {
            "ioc_value": "122.114.12.155:17891",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-09 19:43:22",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847743": [
        {
            "ioc_value": "115.42.60.122:7912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 19:43:21",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847105": [
        {
            "ioc_value": "157.20.182.18:4442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 14:05:07",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1847068": [
        {
            "ioc_value": "203.91.75.89:5006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 11:47:21",
            "last_seen_utc": "2026-07-21 17:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847007": [
        {
            "ioc_value": "91.92.242.180:1880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:46:37",
            "last_seen_utc": "2026-07-21 17:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847006": [
        {
            "ioc_value": "91.219.238.167:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 09:46:36",
            "last_seen_utc": "2026-07-21 17:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847005": [
        {
            "ioc_value": "88.151.72.143:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:46:32",
            "last_seen_utc": "2026-07-21 17:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847004": [
        {
            "ioc_value": "84.247.142.79:8877",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:46:28",
            "last_seen_utc": "2026-07-21 17:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847002": [
        {
            "ioc_value": "68.183.36.161:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:46:19",
            "last_seen_utc": "2026-07-21 17:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847001": [
        {
            "ioc_value": "62.60.226.157:1664",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:46:14",
            "last_seen_utc": "2026-07-21 17:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847000": [
        {
            "ioc_value": "5.230.201.242:1995",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:46:09",
            "last_seen_utc": "2026-07-21 17:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846998": [
        {
            "ioc_value": "45.74.7.194:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:58",
            "last_seen_utc": "2026-07-21 17:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846999": [
        {
            "ioc_value": "45.74.7.196:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:58",
            "last_seen_utc": "2026-07-21 17:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846997": [
        {
            "ioc_value": "45.150.36.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-09 09:45:52",
            "last_seen_utc": "2026-07-21 17:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846996": [
        {
            "ioc_value": "38.60.125.143:12599",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:45:48",
            "last_seen_utc": "2026-07-21 17:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846995": [
        {
            "ioc_value": "37.72.172.58:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 09:45:45",
            "last_seen_utc": "2026-07-21 17:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846992": [
        {
            "ioc_value": "31.57.216.62:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:41",
            "last_seen_utc": "2026-07-21 17:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846993": [
        {
            "ioc_value": "31.57.216.62:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:41",
            "last_seen_utc": "2026-07-21 17:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846994": [
        {
            "ioc_value": "31.57.216.62:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:41",
            "last_seen_utc": "2026-07-21 17:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846991": [
        {
            "ioc_value": "216.9.225.38:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:33",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846990": [
        {
            "ioc_value": "202.1.31.83:2234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-09 09:44:39",
            "last_seen_utc": "2026-07-21 17:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846989": [
        {
            "ioc_value": "186.169.89.64:5471",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:44:21",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846988": [
        {
            "ioc_value": "179.43.149.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 09:44:06",
            "last_seen_utc": "2026-07-21 17:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846987": [
        {
            "ioc_value": "179.43.149.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 09:44:05",
            "last_seen_utc": "2026-07-21 17:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846986": [
        {
            "ioc_value": "178.16.53.193:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:44:04",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846985": [
        {
            "ioc_value": "178.16.53.19:5022",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:44:03",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846984": [
        {
            "ioc_value": "176.120.22.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-07-09 09:44:00",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846983": [
        {
            "ioc_value": "173.249.22.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:43:59",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846982": [
        {
            "ioc_value": "172.94.44.154:7775",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:43:58",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846981": [
        {
            "ioc_value": "158.94.209.117:5022",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:43:47",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846979": [
        {
            "ioc_value": "157.20.182.17:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 09:43:46",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846980": [
        {
            "ioc_value": "157.20.182.18:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 09:43:46",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846977": [
        {
            "ioc_value": "157.173.195.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:43:45",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846978": [
        {
            "ioc_value": "157.173.195.214:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:43:45",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846976": [
        {
            "ioc_value": "144.208.127.243:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-09 09:43:33",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846975": [
        {
            "ioc_value": "144.208.127.243:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-09 09:43:32",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846974": [
        {
            "ioc_value": "142.202.191.251:8624",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:43:30",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846973": [
        {
            "ioc_value": "123.215.57.178:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-09 09:43:22",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846972": [
        {
            "ioc_value": "103.11.41.19:55661",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:43:08",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846948": [
        {
            "ioc_value": "ftp.piovau.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-07-09 08:36:20",
            "last_seen_utc": "2026-07-21 06:17:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/285223e2763c02e8e43b6a78560d66c7d1305abee5bdd67aaf0764d2bb6a9dc2/",
            "tags": "AgentTesla",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846912": [
        {
            "ioc_value": "139.199.89.128:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 06:51:11",
            "last_seen_utc": "2026-07-20 09:14:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846913": [
        {
            "ioc_value": "39.105.201.165:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 06:51:11",
            "last_seen_utc": "2026-07-21 17:46:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846902": [
        {
            "ioc_value": "217.60.241.14:430",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-07-09 06:02:52",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846901": [
        {
            "ioc_value": "157.20.182.81:424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-07-09 06:02:51",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846849": [
        {
            "ioc_value": "193.29.13.44:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 02:05:05",
            "last_seen_utc": "2026-07-21 17:44:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1846829": [
        {
            "ioc_value": "159.75.152.237:6654",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 00:46:41",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846782": [
        {
            "ioc_value": "37.1.213.59:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-07-08 22:36:02",
            "last_seen_utc": "2026-07-21 17:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=37.1.213.59",
            "tags": "Amadey,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846742": [
        {
            "ioc_value": "st1-colud-google.bond",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 19:46:05",
            "last_seen_utc": "2026-07-21 17:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846741": [
        {
            "ioc_value": "89.32.41.50:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-08 19:45:51",
            "last_seen_utc": "2026-07-21 17:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846740": [
        {
            "ioc_value": "89.106.83.84:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:45:50",
            "last_seen_utc": "2026-07-21 17:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846738": [
        {
            "ioc_value": "45.74.7.192:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:45:24",
            "last_seen_utc": "2026-07-21 17:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846739": [
        {
            "ioc_value": "45.74.7.193:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:45:24",
            "last_seen_utc": "2026-07-21 17:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846737": [
        {
            "ioc_value": "216.9.225.38:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:45:00",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846736": [
        {
            "ioc_value": "213.209.159.91:4556",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-08 19:44:32",
            "last_seen_utc": "2026-07-21 17:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846735": [
        {
            "ioc_value": "202.61.130.106:8321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-08 19:44:24",
            "last_seen_utc": "2026-07-21 17:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846734": [
        {
            "ioc_value": "179.43.149.252:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-08 19:43:55",
            "last_seen_utc": "2026-07-21 17:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846733": [
        {
            "ioc_value": "164.68.123.50:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-08 19:43:45",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846732": [
        {
            "ioc_value": "155.103.71.115:13509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:43:38",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846731": [
        {
            "ioc_value": "104.64.192.34:6933",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-08 19:43:14",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846730": [
        {
            "ioc_value": "104.168.7.195:31897",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:43:13",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846729": [
        {
            "ioc_value": "103.11.41.20:516",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:43:09",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846728": [
        {
            "ioc_value": "103.11.41.10:51768",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:43:06",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846508": [
        {
            "ioc_value": "adiapavj.ro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:57:03",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846509": [
        {
            "ioc_value": "alessiachloeperu.com.pe",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:57:02",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846510": [
        {
            "ioc_value": "anfconcepts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:57:01",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846513": [
        {
            "ioc_value": "boxywebtools.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:57:00",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846516": [
        {
            "ioc_value": "childrenhouseschool.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:59",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846518": [
        {
            "ioc_value": "danacgautreaux.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:58",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846521": [
        {
            "ioc_value": "finsightsconsulting.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:57",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846523": [
        {
            "ioc_value": "gotomariko.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:55",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846528": [
        {
            "ioc_value": "ilovebeaver.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:53",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846531": [
        {
            "ioc_value": "kilimanjarodreams.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:48",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846533": [
        {
            "ioc_value": "londonhomeguide.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:47",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846534": [
        {
            "ioc_value": "matierenews.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:47",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846541": [
        {
            "ioc_value": "populardentalcare.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:42",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846543": [
        {
            "ioc_value": "radioondasdelriomayo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:41",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846545": [
        {
            "ioc_value": "savepeny.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:39",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846547": [
        {
            "ioc_value": "sbss.org.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:38",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846550": [
        {
            "ioc_value": "tais-costruzioni.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-08 11:56:37",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1846504": [
        {
            "ioc_value": "185.92.190.185:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 11:46:49",
            "last_seen_utc": "2026-07-21 17:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846505": [
        {
            "ioc_value": "185.92.190.187:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 11:46:49",
            "last_seen_utc": "2026-07-21 17:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846503": [
        {
            "ioc_value": "173.249.27.195:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 11:46:47",
            "last_seen_utc": "2026-07-21 17:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846462": [
        {
            "ioc_value": "89.106.83.75:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 09:46:12",
            "last_seen_utc": "2026-07-21 17:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846461": [
        {
            "ioc_value": "77.72.85.62:59821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-08 09:46:01",
            "last_seen_utc": "2026-07-21 17:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846460": [
        {
            "ioc_value": "45.64.246.163:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-08 09:45:40",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846458": [
        {
            "ioc_value": "202.61.130.170:8321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-08 09:44:32",
            "last_seen_utc": "2026-07-21 17:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846456": [
        {
            "ioc_value": "185.115.164.60:61102",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 09:44:08",
            "last_seen_utc": "2026-07-21 17:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846457": [
        {
            "ioc_value": "185.115.164.60:7572",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 09:44:08",
            "last_seen_utc": "2026-07-21 17:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846455": [
        {
            "ioc_value": "185.115.164.59:11322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 09:44:05",
            "last_seen_utc": "2026-07-21 17:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846454": [
        {
            "ioc_value": "162.248.102.130:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-08 09:43:47",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846453": [
        {
            "ioc_value": "146.19.248.64:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-08 09:43:32",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846419": [
        {
            "ioc_value": "139.226.191.149:2082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 07:40:42",
            "last_seen_utc": "2026-07-20 09:14:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846237": [
        {
            "ioc_value": "185.92.190.183:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 23:46:32",
            "last_seen_utc": "2026-07-21 17:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846238": [
        {
            "ioc_value": "185.92.190.184:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 23:46:32",
            "last_seen_utc": "2026-07-21 17:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846239": [
        {
            "ioc_value": "185.92.190.186:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 23:46:32",
            "last_seen_utc": "2026-07-21 17:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846193": [
        {
            "ioc_value": "89.106.83.80:1202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:45:56",
            "last_seen_utc": "2026-07-21 17:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846192": [
        {
            "ioc_value": "89.106.83.74:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:45:55",
            "last_seen_utc": "2026-07-21 17:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846191": [
        {
            "ioc_value": "8.133.197.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-07 19:45:48",
            "last_seen_utc": "2026-07-21 17:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846190": [
        {
            "ioc_value": "62.192.173.164:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-07 19:45:41",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846189": [
        {
            "ioc_value": "213.165.42.57:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-07 19:44:33",
            "last_seen_utc": "2026-07-21 17:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846188": [
        {
            "ioc_value": "198.135.54.39:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:44:18",
            "last_seen_utc": "2026-07-21 17:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846187": [
        {
            "ioc_value": "185.115.164.60:9292",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:44:03",
            "last_seen_utc": "2026-07-21 17:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846185": [
        {
            "ioc_value": "185.115.164.59:60729",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:44:00",
            "last_seen_utc": "2026-07-21 17:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846186": [
        {
            "ioc_value": "185.115.164.59:62538",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:44:00",
            "last_seen_utc": "2026-07-21 17:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846184": [
        {
            "ioc_value": "185.115.164.59:11832",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:43:59",
            "last_seen_utc": "2026-07-21 17:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846183": [
        {
            "ioc_value": "178.73.192.3:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-07 19:43:55",
            "last_seen_utc": "2026-07-21 17:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846182": [
        {
            "ioc_value": "172.93.144.150:8580",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-07 19:43:50",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846181": [
        {
            "ioc_value": "155.103.69.30:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:43:37",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846180": [
        {
            "ioc_value": "154.82.93.89:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-07 19:43:36",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846179": [
        {
            "ioc_value": "144.172.88.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-07-07 19:43:29",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846178": [
        {
            "ioc_value": "135.181.182.96:8930",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:43:24",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846177": [
        {
            "ioc_value": "128.90.112.249:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:43:21",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846176": [
        {
            "ioc_value": "103.11.41.20:64567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 19:43:09",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846052": [
        {
            "ioc_value": "92.243.66.59:8448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 11:47:17",
            "last_seen_utc": "2026-07-21 17:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846051": [
        {
            "ioc_value": "68.64.178.130:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 11:47:12",
            "last_seen_utc": "2026-07-21 17:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846050": [
        {
            "ioc_value": "47.236.40.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 11:47:08",
            "last_seen_utc": "2026-07-21 17:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846003": [
        {
            "ioc_value": "93.152.224.44:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-07 09:46:09",
            "last_seen_utc": "2026-07-21 17:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846002": [
        {
            "ioc_value": "91.92.33.250:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-07 09:46:08",
            "last_seen_utc": "2026-07-21 17:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846001": [
        {
            "ioc_value": "89.106.83.79:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 09:46:04",
            "last_seen_utc": "2026-07-21 17:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846000": [
        {
            "ioc_value": "69.166.206.151:7022",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 09:45:52",
            "last_seen_utc": "2026-07-21 17:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845999": [
        {
            "ioc_value": "209.54.103.155:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 09:44:33",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845998": [
        {
            "ioc_value": "188.191.96.216:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-07 09:44:13",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845997": [
        {
            "ioc_value": "155.103.69.30:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 09:43:38",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845996": [
        {
            "ioc_value": "103.11.41.10:7145",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 09:43:07",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845803": [
        {
            "ioc_value": "217.60.97.2:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-06 19:45:03",
            "last_seen_utc": "2026-07-21 17:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845802": [
        {
            "ioc_value": "20.204.61.204:22001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-06 19:44:23",
            "last_seen_utc": "2026-07-21 17:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845801": [
        {
            "ioc_value": "199.119.137.129:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-06 19:44:19",
            "last_seen_utc": "2026-07-21 17:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845800": [
        {
            "ioc_value": "198.135.50.174:62025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-06 19:44:17",
            "last_seen_utc": "2026-07-21 17:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845799": [
        {
            "ioc_value": "185.115.164.60:56479",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-06 19:44:00",
            "last_seen_utc": "2026-07-21 17:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845798": [
        {
            "ioc_value": "185.115.164.59:10761",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-06 19:43:58",
            "last_seen_utc": "2026-07-21 17:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845797": [
        {
            "ioc_value": "138.226.236.193:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-06 19:43:25",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845796": [
        {
            "ioc_value": "125.104.168.68:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-06 19:43:21",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845795": [
        {
            "ioc_value": "103.11.41.20:52998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-06 19:43:09",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845794": [
        {
            "ioc_value": "103.11.41.10:62715",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-06 19:43:07",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845793": [
        {
            "ioc_value": "103.11.41.10:16774",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-06 19:43:06",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845588": [
        {
            "ioc_value": "38.46.218.34:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-07-06 10:58:18",
            "last_seen_utc": "2026-07-21 13:35:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "loader,Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1845508": [
        {
            "ioc_value": "101.34.235.198:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-06 09:46:41",
            "last_seen_utc": "2026-07-21 17:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845507": [
        {
            "ioc_value": "82.23.248.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-06 09:46:17",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845506": [
        {
            "ioc_value": "5.231.70.95:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-06 09:46:01",
            "last_seen_utc": "2026-07-21 17:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845505": [
        {
            "ioc_value": "23.95.217.96:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-06 09:45:31",
            "last_seen_utc": "2026-07-21 17:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845504": [
        {
            "ioc_value": "222.167.211.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-06 09:45:29",
            "last_seen_utc": "2026-07-21 17:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845503": [
        {
            "ioc_value": "216.203.20.22:18190",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-06 09:45:27",
            "last_seen_utc": "2026-07-21 17:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845502": [
        {
            "ioc_value": "203.161.57.75:8234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-06 09:44:36",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845500": [
        {
            "ioc_value": "2.27.62.201:62404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-06 09:44:34",
            "last_seen_utc": "2026-07-21 17:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845501": [
        {
            "ioc_value": "2.56.212.64:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-06 09:44:34",
            "last_seen_utc": "2026-07-21 17:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845499": [
        {
            "ioc_value": "2.27.122.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-06 09:44:33",
            "last_seen_utc": "2026-07-21 17:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845498": [
        {
            "ioc_value": "2.137.3.71:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-07-06 09:44:31",
            "last_seen_utc": "2026-07-21 17:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845497": [
        {
            "ioc_value": "173.249.41.141:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-06 09:43:59",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845496": [
        {
            "ioc_value": "157.245.54.75:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-07-06 09:43:45",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845495": [
        {
            "ioc_value": "153.75.89.71:10414",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-06 09:43:39",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845494": [
        {
            "ioc_value": "144.31.151.138:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-06 09:43:33",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845493": [
        {
            "ioc_value": "143.198.120.167:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-06 09:43:32",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845348": [
        {
            "ioc_value": "35.239.131.165:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-06 05:05:04",
            "last_seen_utc": "2026-07-21 17:45:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1845325": [
        {
            "ioc_value": "209.200.246.194:25885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-05 23:46:25",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845324": [
        {
            "ioc_value": "115.190.225.63:53783",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-05 23:46:07",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845296": [
        {
            "ioc_value": "88.216.73.83:9920",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-05 19:46:03",
            "last_seen_utc": "2026-07-21 17:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845295": [
        {
            "ioc_value": "77.105.169.126:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-05 19:45:53",
            "last_seen_utc": "2026-07-21 17:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845294": [
        {
            "ioc_value": "31.220.93.222:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-05 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845293": [
        {
            "ioc_value": "194.26.192.117:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-05 19:44:18",
            "last_seen_utc": "2026-07-21 17:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845292": [
        {
            "ioc_value": "144.172.88.128:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 19:43:30",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845291": [
        {
            "ioc_value": "138.226.237.250:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-05 19:43:26",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845290": [
        {
            "ioc_value": "109.123.239.180:52607",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-07-05 19:43:18",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845289": [
        {
            "ioc_value": "103.11.41.20:12431",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-05 19:43:08",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845011": [
        {
            "ioc_value": "111.229.248.198:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-05 13:33:27",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844990": [
        {
            "ioc_value": "141.255.162.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-05 11:46:59",
            "last_seen_utc": "2026-07-21 17:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844989": [
        {
            "ioc_value": "107.173.85.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-05 11:46:46",
            "last_seen_utc": "2026-07-21 17:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844960": [
        {
            "ioc_value": "http://91.202.233.134/4d95d68e3fc64f3bbbf5.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-07-05 09:50:45",
            "last_seen_utc": "2026-07-21 17:18:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1095cf2951bbc8b1ecd33798afad192449a102aa1b976fb60bf566a08d693587/",
            "tags": "stealc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844959": [
        {
            "ioc_value": "66.29.145.236:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-05 09:46:26",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844958": [
        {
            "ioc_value": "37.117.191.175:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-05 09:45:50",
            "last_seen_utc": "2026-07-21 17:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844956": [
        {
            "ioc_value": "188.191.96.216:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-05 09:44:25",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844957": [
        {
            "ioc_value": "188.191.96.216:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-05 09:44:25",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844955": [
        {
            "ioc_value": "185.221.196.71:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-05 09:44:21",
            "last_seen_utc": "2026-07-21 17:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844954": [
        {
            "ioc_value": "185.115.164.59:3917",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-05 09:44:14",
            "last_seen_utc": "2026-07-21 17:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844953": [
        {
            "ioc_value": "170.168.15.43:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-05 09:43:57",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844952": [
        {
            "ioc_value": "155.103.69.30:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-05 09:43:44",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844951": [
        {
            "ioc_value": "144.31.62.81:56123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-05 09:43:36",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844949": [
        {
            "ioc_value": "143.92.43.241:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 09:43:35",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844950": [
        {
            "ioc_value": "143.92.43.246:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 09:43:35",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844948": [
        {
            "ioc_value": "143.92.43.160:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 09:43:34",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844947": [
        {
            "ioc_value": "104.198.64.39:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-05 09:43:15",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844861": [
        {
            "ioc_value": "110.40.147.249:60010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 23:45:52",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844860": [
        {
            "ioc_value": "107.173.3.53:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 23:45:51",
            "last_seen_utc": "2026-07-21 17:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844853": [
        {
            "ioc_value": "64.227.143.36:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 21:46:30",
            "last_seen_utc": "2026-07-21 17:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844840": [
        {
            "ioc_value": "92.4.65.88:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-04 19:45:47",
            "last_seen_utc": "2026-07-21 17:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844839": [
        {
            "ioc_value": "62.85.21.181:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-04 19:45:31",
            "last_seen_utc": "2026-07-21 17:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844838": [
        {
            "ioc_value": "45.77.108.53:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-04 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844837": [
        {
            "ioc_value": "209.99.188.80:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-04 19:44:23",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844836": [
        {
            "ioc_value": "185.115.164.60:9330",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 19:43:56",
            "last_seen_utc": "2026-07-21 17:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844835": [
        {
            "ioc_value": "179.43.149.250:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-04 19:43:50",
            "last_seen_utc": "2026-07-21 17:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844834": [
        {
            "ioc_value": "155.103.69.30:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 19:43:33",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844833": [
        {
            "ioc_value": "138.226.236.101:1202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 19:43:23",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844832": [
        {
            "ioc_value": "104.168.0.147:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 19:43:11",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844831": [
        {
            "ioc_value": "103.11.41.20:64252",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 19:43:08",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844830": [
        {
            "ioc_value": "102.220.160.94:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 19:43:04",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844655": [
        {
            "ioc_value": "103.42.30.154:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 15:05:05",
            "last_seen_utc": "2026-07-21 17:46:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1844524": [
        {
            "ioc_value": "www.dservices.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.bahamut",
            "malware_alias": null,
            "malware_printable": "Bahamut",
            "first_seen_utc": "2026-07-04 13:24:02",
            "last_seen_utc": "2026-07-21 17:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=www.dservices.space",
            "tags": "Bahamut,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844517": [
        {
            "ioc_value": "117.72.159.96:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 13:05:05",
            "last_seen_utc": "2026-07-21 17:46:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1844505": [
        {
            "ioc_value": "209.200.246.194:47196",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 11:47:19",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844506": [
        {
            "ioc_value": "209.200.246.194:53221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 11:47:19",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844504": [
        {
            "ioc_value": "134.122.135.66:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 11:47:06",
            "last_seen_utc": "2026-07-21 17:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844487": [
        {
            "ioc_value": "13.196.44.85:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-04 10:08:48",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.shodan.io/search?query=product%3A%22Brute+Ratel+C4%22",
            "tags": "Brute Ratel C4,BrutelRatel",
            "anonymous": 0,
            "reporter": "abdelrahman816"
        }
    ],
    "1844477": [
        {
            "ioc_value": "46.246.4.7:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-04 09:46:01",
            "last_seen_utc": "2026-07-21 17:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844476": [
        {
            "ioc_value": "46.151.182.138:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 09:46:00",
            "last_seen_utc": "2026-07-21 17:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844475": [
        {
            "ioc_value": "211.159.223.14:21891",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 09:44:47",
            "last_seen_utc": "2026-07-21 17:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844474": [
        {
            "ioc_value": "207.174.1.243:7203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-04 09:44:42",
            "last_seen_utc": "2026-07-21 17:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844473": [
        {
            "ioc_value": "185.115.164.60:59802",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 09:44:11",
            "last_seen_utc": "2026-07-21 17:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844472": [
        {
            "ioc_value": "185.115.164.59:61737",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 09:44:10",
            "last_seen_utc": "2026-07-21 17:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844471": [
        {
            "ioc_value": "130.12.182.95:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-04 09:43:25",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844469": [
        {
            "ioc_value": "103.11.41.19:4155",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 09:43:09",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844470": [
        {
            "ioc_value": "103.11.41.19:52462",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 09:43:09",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844085": [
        {
            "ioc_value": "186.169.89.64:5010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-04 07:10:33",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRat,DDNS",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1844087": [
        {
            "ioc_value": "186.169.89.64:9140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-04 07:10:33",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRat,DDNS",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1844216": [
        {
            "ioc_value": "45.207.199.148:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-03 23:46:54",
            "last_seen_utc": "2026-07-21 17:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844166": [
        {
            "ioc_value": "86.109.75.177:17635",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-03 19:46:03",
            "last_seen_utc": "2026-07-21 17:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844165": [
        {
            "ioc_value": "46.246.6.3:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-03 19:45:39",
            "last_seen_utc": "2026-07-21 17:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844164": [
        {
            "ioc_value": "37.244.255.240:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-07-03 19:45:22",
            "last_seen_utc": "2026-07-21 17:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844162": [
        {
            "ioc_value": "212.193.23.223:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-03 19:44:34",
            "last_seen_utc": "2026-07-21 17:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844163": [
        {
            "ioc_value": "212.193.23.223:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-03 19:44:34",
            "last_seen_utc": "2026-07-21 17:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844161": [
        {
            "ioc_value": "185.115.164.60:51500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 19:44:03",
            "last_seen_utc": "2026-07-21 17:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844160": [
        {
            "ioc_value": "185.115.164.59:57459",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 19:44:01",
            "last_seen_utc": "2026-07-21 17:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844159": [
        {
            "ioc_value": "155.103.71.115:14657",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 19:43:38",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844154": [
        {
            "ioc_value": "144.172.107.251:9920",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 19:43:29",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844153": [
        {
            "ioc_value": "103.11.41.20:9950",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 19:43:09",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844079": [
        {
            "ioc_value": "223.166.30.24:2082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-03 15:46:32",
            "last_seen_utc": "2026-07-21 17:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844078": [
        {
            "ioc_value": "172.245.226.120:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-03 15:46:27",
            "last_seen_utc": "2026-07-21 17:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844077": [
        {
            "ioc_value": "1.14.217.176:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-03 15:46:06",
            "last_seen_utc": "2026-07-21 17:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843961": [
        {
            "ioc_value": "94.156.179.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-03 09:46:03",
            "last_seen_utc": "2026-07-21 17:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843960": [
        {
            "ioc_value": "202.1.31.83:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-03 09:44:25",
            "last_seen_utc": "2026-07-21 17:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843959": [
        {
            "ioc_value": "198.23.185.221:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-03 09:44:20",
            "last_seen_utc": "2026-07-21 17:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843958": [
        {
            "ioc_value": "155.103.69.30:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 09:43:35",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843956": [
        {
            "ioc_value": "113.31.102.219:21915",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 09:43:18",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843955": [
        {
            "ioc_value": "103.11.41.20:7805",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 09:43:08",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843954": [
        {
            "ioc_value": "103.11.41.10:54976",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 09:43:06",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843953": [
        {
            "ioc_value": "102.220.160.222:2700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-03 09:43:03",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843838": [
        {
            "ioc_value": "162.35.167.8:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-03 03:05:04",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1843816": [
        {
            "ioc_value": "106.13.78.105:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 23:45:57",
            "last_seen_utc": "2026-07-21 17:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843766": [
        {
            "ioc_value": "45.155.69.97:1202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 19:45:44",
            "last_seen_utc": "2026-07-21 17:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843765": [
        {
            "ioc_value": "23.27.201.213:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 19:45:26",
            "last_seen_utc": "2026-07-21 17:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843764": [
        {
            "ioc_value": "185.122.171.65:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 19:44:10",
            "last_seen_utc": "2026-07-21 17:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843763": [
        {
            "ioc_value": "185.122.171.124:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 19:44:09",
            "last_seen_utc": "2026-07-21 17:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843762": [
        {
            "ioc_value": "177.22.119.174:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-07-02 19:43:58",
            "last_seen_utc": "2026-07-21 17:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843761": [
        {
            "ioc_value": "173.249.24.135:3279",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-02 19:43:57",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843760": [
        {
            "ioc_value": "172.94.18.103:70",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-02 19:43:55",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843757": [
        {
            "ioc_value": "155.103.69.30:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 19:43:39",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843758": [
        {
            "ioc_value": "155.103.69.30:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 19:43:39",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843759": [
        {
            "ioc_value": "155.103.69.30:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 19:43:39",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843754": [
        {
            "ioc_value": "143.92.43.160:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 19:43:31",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843755": [
        {
            "ioc_value": "143.92.43.241:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 19:43:31",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843756": [
        {
            "ioc_value": "143.92.43.246:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 19:43:31",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843753": [
        {
            "ioc_value": "103.11.41.20:4734",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 19:43:09",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843752": [
        {
            "ioc_value": "103.11.41.19:61502",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 19:43:08",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843751": [
        {
            "ioc_value": "103.11.41.10:62534",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 19:43:07",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843750": [
        {
            "ioc_value": "102.117.171.174:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-02 19:43:03",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843500": [
        {
            "ioc_value": "82.157.78.201:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 12:05:06",
            "last_seen_utc": "2026-07-21 17:46:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1843496": [
        {
            "ioc_value": "157.20.182.81:427",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-07-02 11:59:56",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843418": [
        {
            "ioc_value": "220.154.3.197:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-02 11:44:21",
            "last_seen_utc": "2026-07-21 17:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Mythic,MythicC2",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1843475": [
        {
            "ioc_value": "39.106.80.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 10:05:08",
            "last_seen_utc": "2026-07-21 17:46:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1843465": [
        {
            "ioc_value": "82.165.79.60:12001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-02 09:45:46",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843466": [
        {
            "ioc_value": "82.165.79.60:12002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-02 09:45:46",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843464": [
        {
            "ioc_value": "77.110.109.120:32404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 09:45:43",
            "last_seen_utc": "2026-07-21 17:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843463": [
        {
            "ioc_value": "70.34.251.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-07-02 09:45:42",
            "last_seen_utc": "2026-07-21 17:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843462": [
        {
            "ioc_value": "217.60.195.151:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-02 09:44:58",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843461": [
        {
            "ioc_value": "209.54.103.155:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 09:44:25",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843460": [
        {
            "ioc_value": "192.162.242.202:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-07-02 09:44:08",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843458": [
        {
            "ioc_value": "185.115.164.60:16203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 09:43:57",
            "last_seen_utc": "2026-07-21 17:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843459": [
        {
            "ioc_value": "185.115.164.60:4847",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 09:43:57",
            "last_seen_utc": "2026-07-21 17:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843457": [
        {
            "ioc_value": "178.208.168.159:6161",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-02 09:43:50",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843456": [
        {
            "ioc_value": "162.243.54.45:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-02 09:43:39",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843455": [
        {
            "ioc_value": "159.65.42.43:60560",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-02 09:43:38",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843454": [
        {
            "ioc_value": "147.93.191.75:1003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-02 09:43:28",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843453": [
        {
            "ioc_value": "141.94.121.162:6060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 09:43:24",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843452": [
        {
            "ioc_value": "136.111.38.101:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-02 09:43:21",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843451": [
        {
            "ioc_value": "103.11.41.19:54766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 09:43:06",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843432": [
        {
            "ioc_value": "121.43.181.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 08:15:52",
            "last_seen_utc": "2026-07-21 17:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843356": [
        {
            "ioc_value": "23.132.164.13:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 05:00:09",
            "last_seen_utc": "2026-07-21 17:46:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "60223,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1843364": [
        {
            "ioc_value": "158.160.191.88:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-02 03:05:05",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1843349": [
        {
            "ioc_value": "209.200.246.194:19989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 23:46:22",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843350": [
        {
            "ioc_value": "209.200.246.194:37865",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 23:46:22",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843300": [
        {
            "ioc_value": "94.156.179.168:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-01 19:46:10",
            "last_seen_utc": "2026-07-21 17:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843299": [
        {
            "ioc_value": "66.163.114.54:1664",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 19:45:54",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843298": [
        {
            "ioc_value": "62.4.0.66:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-01 19:45:50",
            "last_seen_utc": "2026-07-21 17:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843297": [
        {
            "ioc_value": "27.102.118.100:7253",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 19:45:17",
            "last_seen_utc": "2026-07-21 17:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843295": [
        {
            "ioc_value": "209.54.103.155:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 19:44:35",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843296": [
        {
            "ioc_value": "209.54.103.155:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 19:44:35",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843294": [
        {
            "ioc_value": "209.54.103.155:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 19:44:34",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843293": [
        {
            "ioc_value": "185.46.10.210:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-01 19:44:12",
            "last_seen_utc": "2026-07-21 17:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843292": [
        {
            "ioc_value": "185.235.138.19:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-01 19:44:11",
            "last_seen_utc": "2026-07-21 17:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843291": [
        {
            "ioc_value": "185.115.164.60:63283",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 19:44:05",
            "last_seen_utc": "2026-07-21 17:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843290": [
        {
            "ioc_value": "181.225.233.172:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-01 19:43:58",
            "last_seen_utc": "2026-07-21 17:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843289": [
        {
            "ioc_value": "178.105.68.110:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-01 19:43:56",
            "last_seen_utc": "2026-07-21 17:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843288": [
        {
            "ioc_value": "103.11.41.20:61073",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 19:43:09",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843287": [
        {
            "ioc_value": "103.11.41.10:5007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 19:43:06",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843132": [
        {
            "ioc_value": "cashforcars-pittsburgh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-01 18:59:28",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCF,loader,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1840759": [
        {
            "ioc_value": "82.156.235.177:13321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 11:47:08",
            "last_seen_utc": "2026-07-21 17:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840749": [
        {
            "ioc_value": "42.240.167.114:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-01 09:45:20",
            "last_seen_utc": "2026-07-21 17:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840748": [
        {
            "ioc_value": "41.234.38.59:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-01 09:45:19",
            "last_seen_utc": "2026-07-21 17:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840747": [
        {
            "ioc_value": "36.248.232.173:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-01 09:45:16",
            "last_seen_utc": "2026-07-21 17:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840746": [
        {
            "ioc_value": "34.41.69.140:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-01 09:45:14",
            "last_seen_utc": "2026-07-21 17:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840745": [
        {
            "ioc_value": "195.242.118.161:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-01 09:44:17",
            "last_seen_utc": "2026-07-21 17:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840744": [
        {
            "ioc_value": "185.122.171.157:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 09:44:00",
            "last_seen_utc": "2026-07-21 17:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840743": [
        {
            "ioc_value": "178.16.54.157:3009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-01 09:43:52",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840742": [
        {
            "ioc_value": "16.163.186.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-07-01 09:43:40",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840741": [
        {
            "ioc_value": "137.184.216.236:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-01 09:43:24",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840740": [
        {
            "ioc_value": "130.12.182.95:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-01 09:43:22",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840739": [
        {
            "ioc_value": "109.237.64.48:44704",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-01 09:43:17",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840738": [
        {
            "ioc_value": "107.172.255.49:62722",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-01 09:43:14",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840737": [
        {
            "ioc_value": "103.11.41.20:61557",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 09:43:08",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840736": [
        {
            "ioc_value": "103.11.41.10:61105",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 09:43:07",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840735": [
        {
            "ioc_value": "103.11.41.10:16529",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 09:43:06",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840722": [
        {
            "ioc_value": "119.91.243.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 08:05:06",
            "last_seen_utc": "2026-07-21 17:46:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840704": [
        {
            "ioc_value": "43.144.19.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 07:05:06",
            "last_seen_utc": "2026-07-21 17:46:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840396": [
        {
            "ioc_value": "63.250.57.91:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-01 05:50:04",
            "last_seen_utc": "2026-07-21 17:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "1472D1643B294C63AF66357816F6E5E66B427EBD,AsyncRAT,c2",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1840432": [
        {
            "ioc_value": "107.173.42.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 23:45:49",
            "last_seen_utc": "2026-07-21 17:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840431": [
        {
            "ioc_value": "cdn.soft-update.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 23:45:40",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840388": [
        {
            "ioc_value": "91.92.43.194:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:09",
            "last_seen_utc": "2026-07-21 17:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840389": [
        {
            "ioc_value": "91.92.43.195:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:09",
            "last_seen_utc": "2026-07-21 17:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840390": [
        {
            "ioc_value": "91.92.43.196:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:09",
            "last_seen_utc": "2026-07-21 17:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840387": [
        {
            "ioc_value": "91.92.43.193:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:08",
            "last_seen_utc": "2026-07-21 17:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840386": [
        {
            "ioc_value": "89.125.153.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:05",
            "last_seen_utc": "2026-07-21 17:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840384": [
        {
            "ioc_value": "82.25.63.124:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:45:59",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840385": [
        {
            "ioc_value": "82.25.63.130:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:45:59",
            "last_seen_utc": "2026-07-21 17:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840383": [
        {
            "ioc_value": "23.27.201.213:9898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-30 19:45:16",
            "last_seen_utc": "2026-07-21 17:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840381": [
        {
            "ioc_value": "199.217.99.189:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:44:27",
            "last_seen_utc": "2026-07-21 17:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840382": [
        {
            "ioc_value": "199.91.220.216:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:44:27",
            "last_seen_utc": "2026-07-21 17:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840380": [
        {
            "ioc_value": "193.58.122.50:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 19:44:22",
            "last_seen_utc": "2026-07-21 17:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840379": [
        {
            "ioc_value": "193.24.123.25:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:44:21",
            "last_seen_utc": "2026-07-21 17:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840378": [
        {
            "ioc_value": "185.45.193.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:44:14",
            "last_seen_utc": "2026-07-21 17:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840375": [
        {
            "ioc_value": "138.124.240.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840376": [
        {
            "ioc_value": "138.124.240.76:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840377": [
        {
            "ioc_value": "138.124.240.77:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840374": [
        {
            "ioc_value": "128.90.112.175:7203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-30 19:43:22",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840372": [
        {
            "ioc_value": "107.172.22.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-30 19:43:15",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840373": [
        {
            "ioc_value": "107.172.255.49:62721",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 19:43:15",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840357": [
        {
            "ioc_value": "89.110.90.71:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 17:45:50",
            "last_seen_utc": "2026-07-21 17:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840356": [
        {
            "ioc_value": "83.136.210.50:7077",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 17:45:46",
            "last_seen_utc": "2026-07-21 17:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840354": [
        {
            "ioc_value": "5.8.19.157:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:45:33",
            "last_seen_utc": "2026-07-21 17:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840355": [
        {
            "ioc_value": "5.8.19.158:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:45:33",
            "last_seen_utc": "2026-07-21 17:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840353": [
        {
            "ioc_value": "45.74.7.172:1488",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:45:21",
            "last_seen_utc": "2026-07-21 17:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840352": [
        {
            "ioc_value": "41.216.189.153:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-30 17:45:13",
            "last_seen_utc": "2026-07-21 17:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840351": [
        {
            "ioc_value": "2.26.1.177:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 17:44:15",
            "last_seen_utc": "2026-07-21 17:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840349": [
        {
            "ioc_value": "185.115.164.60:64224",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:43:56",
            "last_seen_utc": "2026-07-21 17:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840350": [
        {
            "ioc_value": "185.117.90.47:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-30 17:43:56",
            "last_seen_utc": "2026-07-21 17:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840348": [
        {
            "ioc_value": "173.249.41.192:773",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:43:47",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840347": [
        {
            "ioc_value": "172.94.18.103:69",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 17:43:45",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840346": [
        {
            "ioc_value": "147.182.176.38:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-30 17:43:27",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840345": [
        {
            "ioc_value": "107.172.90.117:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 17:43:13",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840344": [
        {
            "ioc_value": "107.172.238.14:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:43:12",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840341": [
        {
            "ioc_value": "103.11.41.20:10651",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:43:07",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840342": [
        {
            "ioc_value": "103.11.41.20:51997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:43:07",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840343": [
        {
            "ioc_value": "103.11.41.20:55721",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:43:07",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840340": [
        {
            "ioc_value": "102.220.160.222:2500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 17:43:03",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840278": [
        {
            "ioc_value": "115.190.149.214:58004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 11:46:50",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840271": [
        {
            "ioc_value": "152.32.132.177:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 09:54:11",
            "last_seen_utc": "2026-07-20 09:14:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840268": [
        {
            "ioc_value": "94.250.201.212:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 09:46:23",
            "last_seen_utc": "2026-07-21 17:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840267": [
        {
            "ioc_value": "198.135.54.39:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 09:44:26",
            "last_seen_utc": "2026-07-21 17:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840266": [
        {
            "ioc_value": "192.162.199.149:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 09:44:18",
            "last_seen_utc": "2026-07-21 17:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840265": [
        {
            "ioc_value": "170.64.130.99:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 09:43:50",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840264": [
        {
            "ioc_value": "155.103.71.115:14656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 09:43:39",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840263": [
        {
            "ioc_value": "152.42.164.27:65531",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 09:43:36",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840262": [
        {
            "ioc_value": "141.94.121.162:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-30 09:43:27",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840261": [
        {
            "ioc_value": "136.113.49.8:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 09:43:24",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840260": [
        {
            "ioc_value": "103.11.41.10:2120",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 09:43:06",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840219": [
        {
            "ioc_value": "unspanel.rs",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-06-30 06:03:08",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,ErrTraffic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840202": [
        {
            "ioc_value": "1.14.227.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 05:05:05",
            "last_seen_utc": "2026-07-21 17:46:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840203": [
        {
            "ioc_value": "130.12.182.95:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 05:05:05",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840185": [
        {
            "ioc_value": "150.109.186.36:64401",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 23:46:01",
            "last_seen_utc": "2026-07-21 17:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840153": [
        {
            "ioc_value": "81.90.31.253:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-29 19:45:30",
            "last_seen_utc": "2026-07-21 17:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840152": [
        {
            "ioc_value": "193.169.194.63:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-29 19:44:01",
            "last_seen_utc": "2026-07-21 17:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840151": [
        {
            "ioc_value": "185.115.164.60:9486",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 19:43:50",
            "last_seen_utc": "2026-07-21 17:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840150": [
        {
            "ioc_value": "155.138.218.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 19:43:30",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840149": [
        {
            "ioc_value": "128.90.141.238:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-29 19:43:17",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840148": [
        {
            "ioc_value": "128.90.112.249:5202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-29 19:43:16",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840147": [
        {
            "ioc_value": "103.11.41.10:52046",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 19:43:05",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840094": [
        {
            "ioc_value": "104.251.181.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-29 19:05:06",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840093": [
        {
            "ioc_value": "172.245.226.124:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 19:05:05",
            "last_seen_utc": "2026-07-21 17:46:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1839851": [
        {
            "ioc_value": "112.124.71.123:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 15:46:19",
            "last_seen_utc": "2026-07-21 17:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839850": [
        {
            "ioc_value": "answers.microsofl.ip-ddns.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 15:46:07",
            "last_seen_utc": "2026-07-21 17:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839241": [
        {
            "ioc_value": "209.200.246.194:35885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:48",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839240": [
        {
            "ioc_value": "116.213.42.110:5006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:28",
            "last_seen_utc": "2026-07-21 17:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839238": [
        {
            "ioc_value": "updatesrv.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:18",
            "last_seen_utc": "2026-07-21 17:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839239": [
        {
            "ioc_value": "web-analyzer-serv32.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:18",
            "last_seen_utc": "2026-07-21 17:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839221": [
        {
            "ioc_value": "5.8.19.155:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 09:45:40",
            "last_seen_utc": "2026-07-21 17:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839220": [
        {
            "ioc_value": "45.92.158.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 09:45:31",
            "last_seen_utc": "2026-07-21 17:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839219": [
        {
            "ioc_value": "45.74.7.168:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 09:45:28",
            "last_seen_utc": "2026-07-21 17:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839218": [
        {
            "ioc_value": "27.102.137.139:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 09:45:08",
            "last_seen_utc": "2026-07-21 17:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839195": [
        {
            "ioc_value": "193.35.17.42:9956",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-29 09:44:11",
            "last_seen_utc": "2026-07-21 17:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839194": [
        {
            "ioc_value": "192.162.199.149:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-29 09:44:08",
            "last_seen_utc": "2026-07-21 17:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839193": [
        {
            "ioc_value": "178.128.133.69:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-29 09:43:49",
            "last_seen_utc": "2026-07-21 17:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839192": [
        {
            "ioc_value": "107.174.142.104:5543",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-29 09:43:13",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839191": [
        {
            "ioc_value": "104.168.38.165:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-29 09:43:10",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838898": [
        {
            "ioc_value": "38.54.117.107:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 23:45:51",
            "last_seen_utc": "2026-07-21 17:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838897": [
        {
            "ioc_value": "117.72.159.96:8777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 23:45:35",
            "last_seen_utc": "2026-07-21 17:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838896": [
        {
            "ioc_value": "103.73.161.60:9005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 23:45:30",
            "last_seen_utc": "2026-07-21 17:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838803": [
        {
            "ioc_value": "54.180.147.42:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 19:45:13",
            "last_seen_utc": "2026-07-21 17:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838804": [
        {
            "ioc_value": "54.180.147.42:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 19:45:13",
            "last_seen_utc": "2026-07-21 17:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838801": [
        {
            "ioc_value": "5.8.19.157:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:45:11",
            "last_seen_utc": "2026-07-21 17:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838802": [
        {
            "ioc_value": "5.8.19.157:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:45:11",
            "last_seen_utc": "2026-07-21 17:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838800": [
        {
            "ioc_value": "45.94.23.42:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-28 19:45:00",
            "last_seen_utc": "2026-07-21 17:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838799": [
        {
            "ioc_value": "45.150.38.95:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-28 19:44:54",
            "last_seen_utc": "2026-07-21 17:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838798": [
        {
            "ioc_value": "199.247.14.228:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-06-28 19:44:04",
            "last_seen_utc": "2026-07-21 17:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838797": [
        {
            "ioc_value": "185.115.164.59:2892",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:43:47",
            "last_seen_utc": "2026-07-21 17:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838796": [
        {
            "ioc_value": "109.227.35.147:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-06-28 19:43:12",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838793": [
        {
            "ioc_value": "103.11.41.10:8237",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:43:05",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838794": [
        {
            "ioc_value": "103.11.41.19:16666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:43:05",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838795": [
        {
            "ioc_value": "103.11.41.20:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 19:43:05",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838789": [
        {
            "ioc_value": "104.248.201.191:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 19:05:05",
            "last_seen_utc": "2026-07-21 17:46:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838776": [
        {
            "ioc_value": "genova.com.vn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-28 14:37:59",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCF",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1838757": [
        {
            "ioc_value": "45.74.7.173:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:45:16",
            "last_seen_utc": "2026-07-21 17:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838756": [
        {
            "ioc_value": "192.162.199.149:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 09:44:03",
            "last_seen_utc": "2026-07-21 17:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838755": [
        {
            "ioc_value": "185.212.128.231:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-28 09:43:55",
            "last_seen_utc": "2026-07-21 17:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838754": [
        {
            "ioc_value": "177.22.119.145:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-06-28 09:43:45",
            "last_seen_utc": "2026-07-21 17:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838753": [
        {
            "ioc_value": "167.94.81.175:62722",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 09:43:38",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838752": [
        {
            "ioc_value": "159.195.193.179:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-28 09:43:34",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838751": [
        {
            "ioc_value": "141.98.10.150:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:43:21",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838750": [
        {
            "ioc_value": "103.83.87.87:25900",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:43:09",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838749": [
        {
            "ioc_value": "103.11.41.20:201",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:43:06",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838736": [
        {
            "ioc_value": "149.50.96.57:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 07:05:07",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838730": [
        {
            "ioc_value": "47.236.116.9:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-06-28 06:36:01",
            "last_seen_utc": "2026-07-21 17:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=47.236.116.9",
            "tags": "Amadey,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838710": [
        {
            "ioc_value": "45.227.253.121:52445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 23:46:10",
            "last_seen_utc": "2026-07-21 17:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838708": [
        {
            "ioc_value": "134.122.135.120:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 23:45:52",
            "last_seen_utc": "2026-07-21 17:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838709": [
        {
            "ioc_value": "134.122.135.53:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 23:45:52",
            "last_seen_utc": "2026-07-21 17:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838676": [
        {
            "ioc_value": "103.146.231.107:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 19:46:07",
            "last_seen_utc": "2026-07-21 17:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838675": [
        {
            "ioc_value": "85.137.249.185:8977",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:47",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838674": [
        {
            "ioc_value": "80.211.129.141:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:43",
            "last_seen_utc": "2026-07-21 17:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838672": [
        {
            "ioc_value": "68.64.178.130:48951",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:40",
            "last_seen_utc": "2026-07-21 17:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838673": [
        {
            "ioc_value": "69.48.228.170:65531",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:40",
            "last_seen_utc": "2026-07-21 17:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838670": [
        {
            "ioc_value": "5.8.18.155:992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-27 19:45:33",
            "last_seen_utc": "2026-07-21 17:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838671": [
        {
            "ioc_value": "5.8.19.157:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:33",
            "last_seen_utc": "2026-07-21 17:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838669": [
        {
            "ioc_value": "5.206.224.226:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:32",
            "last_seen_utc": "2026-07-21 17:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838668": [
        {
            "ioc_value": "45.74.7.170:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:22",
            "last_seen_utc": "2026-07-21 17:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838666": [
        {
            "ioc_value": "45.74.7.165:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:21",
            "last_seen_utc": "2026-07-21 17:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838667": [
        {
            "ioc_value": "45.74.7.169:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:21",
            "last_seen_utc": "2026-07-21 17:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838665": [
        {
            "ioc_value": "45.141.234.47:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:17",
            "last_seen_utc": "2026-07-21 17:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838664": [
        {
            "ioc_value": "37.220.31.90:61135",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:09",
            "last_seen_utc": "2026-07-21 17:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838663": [
        {
            "ioc_value": "185.212.128.139:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-27 19:43:58",
            "last_seen_utc": "2026-07-21 17:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838662": [
        {
            "ioc_value": "178.83.121.60:48203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:49",
            "last_seen_utc": "2026-07-21 17:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838661": [
        {
            "ioc_value": "173.231.188.244:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:43:46",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838660": [
        {
            "ioc_value": "155.94.163.75:8797",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:32",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838659": [
        {
            "ioc_value": "138.124.84.7:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:43:20",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838657": [
        {
            "ioc_value": "107.174.142.104:6578",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:13",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838658": [
        {
            "ioc_value": "107.174.142.104:7790",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:13",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838656": [
        {
            "ioc_value": "107.173.160.177:2850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-27 19:43:12",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838655": [
        {
            "ioc_value": "104.37.173.203:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:43:10",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838654": [
        {
            "ioc_value": "103.11.41.20:2753",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:43:06",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838653": [
        {
            "ioc_value": "103.11.41.10:49584",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:43:05",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838652": [
        {
            "ioc_value": "101.245.74.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-27 19:43:02",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838629": [
        {
            "ioc_value": "47.86.184.71:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 15:46:40",
            "last_seen_utc": "2026-07-21 17:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838628": [
        {
            "ioc_value": "test.officeplustool.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 15:46:01",
            "last_seen_utc": "2026-07-21 17:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838598": [
        {
            "ioc_value": "103.11.41.20:9087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 09:43:07",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838554": [
        {
            "ioc_value": "128.90.141.159:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 08:05:05",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838555": [
        {
            "ioc_value": "188.212.158.4:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 08:05:05",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838532": [
        {
            "ioc_value": "8.152.212.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 07:05:05",
            "last_seen_utc": "2026-07-21 17:46:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838478": [
        {
            "ioc_value": "47.108.60.27:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 06:24:31",
            "last_seen_utc": "2026-07-21 17:46:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "37963,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1838162": [
        {
            "ioc_value": "196.251.107.186:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.solaris_loader",
            "malware_alias": null,
            "malware_printable": "SolarisLoader",
            "first_seen_utc": "2026-06-27 06:24:16",
            "last_seen_utc": "2026-07-21 17:48:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/69de2958-b593-4d93-802b-6b2601a2f93b",
            "tags": "botnet,injection,solaris",
            "anonymous": 0,
            "reporter": "gh0styippe"
        }
    ],
    "1838520": [
        {
            "ioc_value": "114.132.199.129:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 06:05:06",
            "last_seen_utc": "2026-07-21 17:46:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838498": [
        {
            "ioc_value": "27.124.43.249:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-27 04:05:05",
            "last_seen_utc": "2026-07-21 17:45:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838183": [
        {
            "ioc_value": "82.165.79.60:1336",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-26 19:45:25",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838182": [
        {
            "ioc_value": "5.200.255.45:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-26 19:45:15",
            "last_seen_utc": "2026-07-21 17:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838181": [
        {
            "ioc_value": "45.254.246.208:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-26 19:45:00",
            "last_seen_utc": "2026-07-21 17:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838180": [
        {
            "ioc_value": "209.54.103.150:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-26 19:44:13",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838179": [
        {
            "ioc_value": "193.169.194.63:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-26 19:44:00",
            "last_seen_utc": "2026-07-21 17:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838178": [
        {
            "ioc_value": "141.98.189.248:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-26 19:43:19",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838177": [
        {
            "ioc_value": "103.11.41.19:52814",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-26 19:43:05",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838143": [
        {
            "ioc_value": "64.83.33.240:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:06",
            "last_seen_utc": "2026-07-21 17:48:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=64.83.33.240",
            "tags": "Overlord,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838140": [
        {
            "ioc_value": "192.3.16.35:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:05",
            "last_seen_utc": "2026-07-21 17:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=192.3.16.35",
            "tags": "Overlord,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838141": [
        {
            "ioc_value": "192.3.16.34:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:05",
            "last_seen_utc": "2026-07-21 17:48:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=192.3.16.34",
            "tags": "Overlord,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838142": [
        {
            "ioc_value": "185.103.166.53:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:05",
            "last_seen_utc": "2026-07-21 17:48:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=185.103.166.53",
            "tags": "Overlord,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838139": [
        {
            "ioc_value": "192.109.200.233:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:04",
            "last_seen_utc": "2026-07-21 17:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=192.109.200.233",
            "tags": "Overlord,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838138": [
        {
            "ioc_value": "107.175.115.123:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 14:00:03",
            "last_seen_utc": "2026-07-21 17:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=107.175.115.123",
            "tags": "Overlord,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838137": [
        {
            "ioc_value": "87.120.84.133:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-06-26 13:48:02",
            "last_seen_utc": "2026-07-21 17:48:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=87.120.84.133",
            "tags": "Overlord,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838123": [
        {
            "ioc_value": "https://k1h.hopesm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:15",
            "last_seen_utc": "2026-07-21 17:25:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838124": [
        {
            "ioc_value": "k1h.hopesm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:15",
            "last_seen_utc": "2026-07-21 17:25:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837938": [
        {
            "ioc_value": "107.173.9.99:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-26 09:43:14",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837880": [
        {
            "ioc_value": "122.51.221.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-26 07:18:38",
            "last_seen_utc": "2026-07-21 17:46:14",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1837848": [
        {
            "ioc_value": "49.232.4.71:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 21:05:09",
            "last_seen_utc": "2026-07-21 17:46:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1837843": [
        {
            "ioc_value": "172.245.196.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 20:05:06",
            "last_seen_utc": "2026-07-21 17:46:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1837840": [
        {
            "ioc_value": "217.60.97.3:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-25 19:45:00",
            "last_seen_utc": "2026-07-21 17:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837839": [
        {
            "ioc_value": "217.60.195.194:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 19:44:59",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837838": [
        {
            "ioc_value": "209.54.103.150:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-25 19:44:24",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837837": [
        {
            "ioc_value": "185.192.125.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-25 19:43:58",
            "last_seen_utc": "2026-07-21 17:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837836": [
        {
            "ioc_value": "157.245.171.59:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-25 19:43:34",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837833": [
        {
            "ioc_value": "147.124.223.75:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 19:43:25",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837834": [
        {
            "ioc_value": "147.124.223.75:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 19:43:25",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837835": [
        {
            "ioc_value": "147.124.223.75:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 19:43:25",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837557": [
        {
            "ioc_value": "130.94.59.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 18:05:09",
            "last_seen_utc": "2026-07-21 17:46:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1837517": [
        {
            "ioc_value": "boldtop.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 15:45:59",
            "last_seen_utc": "2026-07-21 17:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837339": [
        {
            "ioc_value": "repack-games.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.5t_downloader",
            "malware_alias": null,
            "malware_printable": "5.t Downloader",
            "first_seen_utc": "2026-06-25 13:55:28",
            "last_seen_utc": "2026-07-21 03:50:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1837335": [
        {
            "ioc_value": "172.245.57.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 11:46:44",
            "last_seen_utc": "2026-07-21 17:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837334": [
        {
            "ioc_value": "124.222.218.12:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 11:46:36",
            "last_seen_utc": "2026-07-21 17:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837333": [
        {
            "ioc_value": "1.94.187.246:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 11:46:22",
            "last_seen_utc": "2026-07-21 17:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837297": [
        {
            "ioc_value": "8.130.74.111:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 09:47:23",
            "last_seen_utc": "2026-07-21 17:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837296": [
        {
            "ioc_value": "159.75.176.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 09:46:55",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837295": [
        {
            "ioc_value": "88.198.11.120:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-06-25 09:46:16",
            "last_seen_utc": "2026-07-21 17:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837294": [
        {
            "ioc_value": "5.101.84.82:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 09:45:52",
            "last_seen_utc": "2026-07-21 17:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837293": [
        {
            "ioc_value": "45.74.7.166:1377",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 09:45:43",
            "last_seen_utc": "2026-07-21 17:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837292": [
        {
            "ioc_value": "27.124.43.249:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-25 09:45:24",
            "last_seen_utc": "2026-07-21 17:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837290": [
        {
            "ioc_value": "209.54.103.150:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-25 09:44:34",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837291": [
        {
            "ioc_value": "209.54.103.150:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-25 09:44:34",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837289": [
        {
            "ioc_value": "185.115.164.59:3731",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 09:44:03",
            "last_seen_utc": "2026-07-21 17:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837287": [
        {
            "ioc_value": "154.219.98.36:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-25 09:43:32",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837286": [
        {
            "ioc_value": "104.250.167.40:9093",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-25 09:43:11",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837285": [
        {
            "ioc_value": "103.11.41.10:55483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 09:43:05",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837243": [
        {
            "ioc_value": "169.239.128.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 08:08:03",
            "last_seen_utc": "2026-07-21 17:46:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837239": [
        {
            "ioc_value": "8.134.255.60:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 08:07:56",
            "last_seen_utc": "2026-07-21 17:46:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837204": [
        {
            "ioc_value": "157.20.182.81:430",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-25 05:28:29",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837197": [
        {
            "ioc_value": "196.251.121.90:421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-25 05:28:28",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837198": [
        {
            "ioc_value": "196.251.121.90:424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-25 05:28:28",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837068": [
        {
            "ioc_value": "clicky.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-25 03:13:24",
            "last_seen_utc": "2026-07-21 02:38:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "gray,script,tracker,unmalicious",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1837171": [
        {
            "ioc_value": "45.227.253.121:25338",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 23:48:40",
            "last_seen_utc": "2026-07-21 17:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837170": [
        {
            "ioc_value": "130.94.59.160:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 23:48:22",
            "last_seen_utc": "2026-07-21 17:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837169": [
        {
            "ioc_value": "121.4.76.54:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 23:48:20",
            "last_seen_utc": "2026-07-21 17:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837093": [
        {
            "ioc_value": "89.124.93.139:49999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-24 19:45:44",
            "last_seen_utc": "2026-07-21 17:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837092": [
        {
            "ioc_value": "83.136.210.74:7077",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 19:45:41",
            "last_seen_utc": "2026-07-21 17:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837091": [
        {
            "ioc_value": "62.85.21.181:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 19:45:33",
            "last_seen_utc": "2026-07-21 17:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837090": [
        {
            "ioc_value": "46.246.4.2:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-24 19:45:21",
            "last_seen_utc": "2026-07-21 17:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837088": [
        {
            "ioc_value": "45.74.7.163:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837089": [
        {
            "ioc_value": "45.74.7.164:6913",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837087": [
        {
            "ioc_value": "45.74.7.155:1202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:45:17",
            "last_seen_utc": "2026-07-21 17:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837086": [
        {
            "ioc_value": "27.124.43.241:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-24 19:44:57",
            "last_seen_utc": "2026-07-21 17:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837085": [
        {
            "ioc_value": "198.23.185.82:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 19:44:11",
            "last_seen_utc": "2026-07-21 17:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837084": [
        {
            "ioc_value": "192.227.219.81:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:44:04",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837082": [
        {
            "ioc_value": "185.115.164.59:65372",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:43:53",
            "last_seen_utc": "2026-07-21 17:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837083": [
        {
            "ioc_value": "185.115.164.60:10251",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:43:53",
            "last_seen_utc": "2026-07-21 17:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837081": [
        {
            "ioc_value": "178.16.55.214:55380",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-24 19:43:46",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837080": [
        {
            "ioc_value": "146.190.80.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-24 19:43:22",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837079": [
        {
            "ioc_value": "141.98.10.150:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:43:21",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837078": [
        {
            "ioc_value": "109.199.97.174:6010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-24 19:43:12",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837077": [
        {
            "ioc_value": "107.173.9.99:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:43:11",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836925": [
        {
            "ioc_value": "60.217.58.49:2121",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 11:48:48",
            "last_seen_utc": "2026-07-21 17:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836924": [
        {
            "ioc_value": "43.131.240.236:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 11:48:29",
            "last_seen_utc": "2026-07-21 17:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836784": [
        {
            "ioc_value": "95.81.79.153:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-24 09:45:56",
            "last_seen_utc": "2026-07-21 17:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836783": [
        {
            "ioc_value": "45.74.7.160:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:45:24",
            "last_seen_utc": "2026-07-21 17:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836782": [
        {
            "ioc_value": "45.138.16.56:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:45:19",
            "last_seen_utc": "2026-07-21 17:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836781": [
        {
            "ioc_value": "38.207.177.71:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-24 09:45:14",
            "last_seen_utc": "2026-07-21 17:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836780": [
        {
            "ioc_value": "217.60.195.194:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:45:00",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836779": [
        {
            "ioc_value": "192.227.219.81:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:44:09",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836777": [
        {
            "ioc_value": "185.115.161.32:6943",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-24 09:43:58",
            "last_seen_utc": "2026-07-21 17:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836778": [
        {
            "ioc_value": "185.115.164.59:30023",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:43:58",
            "last_seen_utc": "2026-07-21 17:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836775": [
        {
            "ioc_value": "154.219.98.36:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-24 09:43:30",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836776": [
        {
            "ioc_value": "154.219.98.36:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-24 09:43:30",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836774": [
        {
            "ioc_value": "141.98.10.150:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:43:23",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836773": [
        {
            "ioc_value": "128.90.115.181:7011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-24 09:43:17",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836771": [
        {
            "ioc_value": "107.172.140.187:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-24 09:43:12",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836772": [
        {
            "ioc_value": "107.173.9.99:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:43:12",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836770": [
        {
            "ioc_value": "107.172.133.195:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:43:11",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836767": [
        {
            "ioc_value": "102.220.160.222:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:43:04",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836768": [
        {
            "ioc_value": "102.220.160.250:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:43:04",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836769": [
        {
            "ioc_value": "102.220.160.250:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:43:04",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836704": [
        {
            "ioc_value": "49.233.9.4:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 03:46:33",
            "last_seen_utc": "2026-07-21 17:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836703": [
        {
            "ioc_value": "www.rmsmarineservice.com.qwqqwq.ggff.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 03:45:54",
            "last_seen_utc": "2026-07-21 17:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836674": [
        {
            "ioc_value": "91.92.242.235:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-23 19:45:49",
            "last_seen_utc": "2026-07-21 17:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836673": [
        {
            "ioc_value": "82.29.100.224:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:45:42",
            "last_seen_utc": "2026-07-21 17:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836672": [
        {
            "ioc_value": "46.29.166.65:3481",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-23 19:45:22",
            "last_seen_utc": "2026-07-21 17:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836671": [
        {
            "ioc_value": "45.74.7.161:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:45:19",
            "last_seen_utc": "2026-07-21 17:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836669": [
        {
            "ioc_value": "45.74.7.156:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836670": [
        {
            "ioc_value": "45.74.7.159:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836668": [
        {
            "ioc_value": "45.138.16.56:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:45:14",
            "last_seen_utc": "2026-07-21 17:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836667": [
        {
            "ioc_value": "2.26.17.59:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:44:13",
            "last_seen_utc": "2026-07-21 17:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836666": [
        {
            "ioc_value": "192.227.219.81:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:44:04",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836665": [
        {
            "ioc_value": "188.23.173.69:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-23 19:44:02",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836664": [
        {
            "ioc_value": "185.115.164.59:51227",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:43:54",
            "last_seen_utc": "2026-07-21 17:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836663": [
        {
            "ioc_value": "178.73.192.17:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-23 19:43:47",
            "last_seen_utc": "2026-07-21 17:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836662": [
        {
            "ioc_value": "156.239.47.147:4221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-23 19:43:29",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836660": [
        {
            "ioc_value": "147.124.213.155:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:43:23",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836661": [
        {
            "ioc_value": "147.93.191.75:20500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:43:23",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836659": [
        {
            "ioc_value": "137.220.59.55:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-23 19:43:18",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836657": [
        {
            "ioc_value": "103.11.41.20:5195",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:43:05",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836658": [
        {
            "ioc_value": "103.11.41.20:53523",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:43:05",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836656": [
        {
            "ioc_value": "103.11.41.10:53496",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-23 19:43:04",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836655": [
        {
            "ioc_value": "102.220.160.250:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:43:03",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836654": [
        {
            "ioc_value": "102.117.173.226:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-23 19:43:02",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836338": [
        {
            "ioc_value": "147.93.191.75:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 13:31:17",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1836278": [
        {
            "ioc_value": "111.231.173.74:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-23 07:14:51",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836238": [
        {
            "ioc_value": "42.193.15.237:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-23 03:46:19",
            "last_seen_utc": "2026-07-21 17:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836201": [
        {
            "ioc_value": "62.234.22.228:51123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 23:46:20",
            "last_seen_utc": "2026-07-21 17:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836148": [
        {
            "ioc_value": "42.193.15.237:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 19:46:25",
            "last_seen_utc": "2026-07-21 17:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836146": [
        {
            "ioc_value": "72.56.68.200:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-06-22 19:45:30",
            "last_seen_utc": "2026-07-21 17:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836145": [
        {
            "ioc_value": "64.89.160.127:60859",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:45:27",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836144": [
        {
            "ioc_value": "217.60.195.194:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:44:50",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836143": [
        {
            "ioc_value": "2.27.5.72:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:44:11",
            "last_seen_utc": "2026-07-21 17:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836141": [
        {
            "ioc_value": "185.115.164.59:50824",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:43:50",
            "last_seen_utc": "2026-07-21 17:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836142": [
        {
            "ioc_value": "185.115.164.60:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:43:50",
            "last_seen_utc": "2026-07-21 17:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836140": [
        {
            "ioc_value": "150.40.117.39:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-22 19:43:24",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836139": [
        {
            "ioc_value": "107.173.9.99:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:43:10",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836137": [
        {
            "ioc_value": "103.11.41.10:9428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:43:04",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836138": [
        {
            "ioc_value": "103.11.41.19:5213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 19:43:04",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835573": [
        {
            "ioc_value": "204.194.54.198:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 09:46:29",
            "last_seen_utc": "2026-07-21 17:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835572": [
        {
            "ioc_value": "ns2.msgkg.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 09:46:01",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835571": [
        {
            "ioc_value": "ns1.msgkg.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 09:45:59",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835570": [
        {
            "ioc_value": "5.101.86.23:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:45:28",
            "last_seen_utc": "2026-07-21 17:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835569": [
        {
            "ioc_value": "46.161.0.48:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:45:23",
            "last_seen_utc": "2026-07-21 17:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835568": [
        {
            "ioc_value": "45.81.243.44:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:45:21",
            "last_seen_utc": "2026-07-21 17:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835567": [
        {
            "ioc_value": "217.60.195.194:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:44:56",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835565": [
        {
            "ioc_value": "205.209.106.158:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:44:19",
            "last_seen_utc": "2026-07-21 17:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835566": [
        {
            "ioc_value": "205.209.106.158:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:44:19",
            "last_seen_utc": "2026-07-21 17:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835564": [
        {
            "ioc_value": "205.209.106.158:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:44:18",
            "last_seen_utc": "2026-07-21 17:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835562": [
        {
            "ioc_value": "192.236.217.70:24047",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:44:05",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835563": [
        {
            "ioc_value": "192.236.217.70:24048",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:44:05",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835561": [
        {
            "ioc_value": "185.212.128.215:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-22 09:43:56",
            "last_seen_utc": "2026-07-21 17:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835560": [
        {
            "ioc_value": "13.140.160.249:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:43:16",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835559": [
        {
            "ioc_value": "107.173.9.99:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:43:10",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835557": [
        {
            "ioc_value": "103.11.41.10:7408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:43:04",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835558": [
        {
            "ioc_value": "103.11.41.19:126",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-22 09:43:04",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835556": [
        {
            "ioc_value": "102.220.160.250:7829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:43:03",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835400": [
        {
            "ioc_value": "216.250.250.247:4521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 07:05:53",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8c63a57313ad2479a758ca018134377043acbeade2b457f7f3392364b78a4a32/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835397": [
        {
            "ioc_value": "196.251.121.90:430",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-22 07:00:14",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835388": [
        {
            "ioc_value": "196.251.121.90:425",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-22 07:00:13",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835389": [
        {
            "ioc_value": "196.251.121.90:427",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-22 07:00:13",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835383": [
        {
            "ioc_value": "51.195.111.212:421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-22 07:00:10",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835384": [
        {
            "ioc_value": "217.60.241.14:421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-22 07:00:10",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835379": [
        {
            "ioc_value": "74.48.84.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 06:39:32",
            "last_seen_utc": "2026-07-21 17:46:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835354": [
        {
            "ioc_value": "paster.so",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.5t_downloader",
            "malware_alias": null,
            "malware_printable": "5.t Downloader",
            "first_seen_utc": "2026-06-22 06:22:30",
            "last_seen_utc": "2026-07-21 03:54:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1835362": [
        {
            "ioc_value": "119.45.166.6:9876",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 03:45:53",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835339": [
        {
            "ioc_value": "115.190.149.214:58848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-21 23:45:40",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834964": [
        {
            "ioc_value": "5.101.86.67:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:45:25",
            "last_seen_utc": "2026-07-21 17:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834962": [
        {
            "ioc_value": "45.154.98.254:2004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 19:45:13",
            "last_seen_utc": "2026-07-21 17:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834963": [
        {
            "ioc_value": "45.154.98.254:2006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 19:45:13",
            "last_seen_utc": "2026-07-21 17:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834960": [
        {
            "ioc_value": "217.60.195.194:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:44:53",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834961": [
        {
            "ioc_value": "217.60.195.194:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:44:53",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834959": [
        {
            "ioc_value": "198.23.185.136:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 19:44:09",
            "last_seen_utc": "2026-07-21 17:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834958": [
        {
            "ioc_value": "194.116.236.239:4020",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:44:05",
            "last_seen_utc": "2026-07-21 17:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834957": [
        {
            "ioc_value": "185.115.164.60:13766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:43:51",
            "last_seen_utc": "2026-07-21 17:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834956": [
        {
            "ioc_value": "156.247.51.40:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-21 19:43:28",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834955": [
        {
            "ioc_value": "147.93.191.75:90",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 19:43:23",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834954": [
        {
            "ioc_value": "137.220.154.16:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-21 19:43:17",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834953": [
        {
            "ioc_value": "103.110.80.154:7444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-21 19:43:05",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834952": [
        {
            "ioc_value": "103.11.41.19:9233",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 19:43:04",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834782": [
        {
            "ioc_value": "87.199.196.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-21 14:00:20",
            "last_seen_utc": "2026-07-21 17:45:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1834771": [
        {
            "ioc_value": "89.42.134.220:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:45:40",
            "last_seen_utc": "2026-07-21 17:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834770": [
        {
            "ioc_value": "51.79.51.255:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-21 09:45:23",
            "last_seen_utc": "2026-07-21 17:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834769": [
        {
            "ioc_value": "45.81.243.44:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:45:12",
            "last_seen_utc": "2026-07-21 17:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834768": [
        {
            "ioc_value": "45.140.14.29:1489",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-21 09:45:07",
            "last_seen_utc": "2026-07-21 17:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834765": [
        {
            "ioc_value": "191.107.87.183:5010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:59",
            "last_seen_utc": "2026-07-21 17:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834766": [
        {
            "ioc_value": "191.107.87.183:8917",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:59",
            "last_seen_utc": "2026-07-21 17:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834767": [
        {
            "ioc_value": "191.107.87.183:9140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:59",
            "last_seen_utc": "2026-07-21 17:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834764": [
        {
            "ioc_value": "185.115.164.59:808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 09:43:51",
            "last_seen_utc": "2026-07-21 17:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834763": [
        {
            "ioc_value": "150.40.117.39:43723",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-21 09:43:24",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834762": [
        {
            "ioc_value": "147.93.191.75:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:22",
            "last_seen_utc": "2026-07-21 08:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834761": [
        {
            "ioc_value": "141.98.10.150:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 09:43:18",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834759": [
        {
            "ioc_value": "103.67.163.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:07",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834760": [
        {
            "ioc_value": "103.67.163.27:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:07",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834758": [
        {
            "ioc_value": "103.6.219.25:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:43:06",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834756": [
        {
            "ioc_value": "103.11.41.10:431",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 09:43:04",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834757": [
        {
            "ioc_value": "103.11.41.10:51490",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-21 09:43:04",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834559": [
        {
            "ioc_value": "116.213.42.110:5005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-20 19:45:51",
            "last_seen_utc": "2026-07-21 17:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834558": [
        {
            "ioc_value": "100.110.56.1:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-20 19:45:45",
            "last_seen_utc": "2026-07-21 17:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834557": [
        {
            "ioc_value": "89.124.107.161:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-20 19:45:29",
            "last_seen_utc": "2026-07-21 17:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834556": [
        {
            "ioc_value": "80.211.129.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-20 19:45:24",
            "last_seen_utc": "2026-07-21 08:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834555": [
        {
            "ioc_value": "8.217.141.231:636",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-20 19:45:23",
            "last_seen_utc": "2026-07-21 08:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834554": [
        {
            "ioc_value": "5.200.176.105:55476",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-20 19:45:13",
            "last_seen_utc": "2026-07-21 08:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834553": [
        {
            "ioc_value": "5.101.85.65:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 19:45:10",
            "last_seen_utc": "2026-07-21 17:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834552": [
        {
            "ioc_value": "47.243.211.244:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-20 19:45:07",
            "last_seen_utc": "2026-07-21 08:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834551": [
        {
            "ioc_value": "45.81.243.44:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:45:01",
            "last_seen_utc": "2026-07-21 17:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834550": [
        {
            "ioc_value": "45.77.254.232:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-20 19:45:00",
            "last_seen_utc": "2026-07-21 08:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834549": [
        {
            "ioc_value": "198.23.185.136:10900",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:44:03",
            "last_seen_utc": "2026-07-21 08:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834547": [
        {
            "ioc_value": "195.20.115.197:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:44:01",
            "last_seen_utc": "2026-07-21 08:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834548": [
        {
            "ioc_value": "195.20.115.197:7829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:44:01",
            "last_seen_utc": "2026-07-21 08:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834546": [
        {
            "ioc_value": "195.20.115.197:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:44:00",
            "last_seen_utc": "2026-07-21 08:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834545": [
        {
            "ioc_value": "188.23.170.123:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-20 19:43:54",
            "last_seen_utc": "2026-07-21 08:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834544": [
        {
            "ioc_value": "162.216.241.206:7997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-20 19:43:30",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834542": [
        {
            "ioc_value": "13.140.160.249:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:43:13",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834543": [
        {
            "ioc_value": "13.140.160.249:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:43:13",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834541": [
        {
            "ioc_value": "104.194.151.163:65381",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 19:43:06",
            "last_seen_utc": "2026-07-21 08:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834540": [
        {
            "ioc_value": "102.220.160.217:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:43:02",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834291": [
        {
            "ioc_value": "43.138.165.203:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-20 14:00:22",
            "last_seen_utc": "2026-07-21 17:46:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1834285": [
        {
            "ioc_value": "43.143.244.134:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-20 11:46:49",
            "last_seen_utc": "2026-07-21 17:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834284": [
        {
            "ioc_value": "139.196.89.43:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-20 11:46:31",
            "last_seen_utc": "2026-07-21 17:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834279": [
        {
            "ioc_value": "5.188.61.49:44443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-20 09:45:43",
            "last_seen_utc": "2026-07-21 17:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834278": [
        {
            "ioc_value": "47.83.254.175:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 09:45:38",
            "last_seen_utc": "2026-07-20 18:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834277": [
        {
            "ioc_value": "45.32.64.12:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 09:45:31",
            "last_seen_utc": "2026-07-21 17:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834276": [
        {
            "ioc_value": "36.50.85.69:1235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 09:45:20",
            "last_seen_utc": "2026-07-21 17:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834275": [
        {
            "ioc_value": "217.60.195.176:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-20 09:45:10",
            "last_seen_utc": "2026-07-21 17:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834274": [
        {
            "ioc_value": "198.23.185.136:20600",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 09:44:18",
            "last_seen_utc": "2026-07-20 08:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834273": [
        {
            "ioc_value": "188.253.104.174:2026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 09:44:08",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834272": [
        {
            "ioc_value": "147.93.191.75:30400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 09:43:25",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834187": [
        {
            "ioc_value": "23.141.12.111:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 23:46:13",
            "last_seen_utc": "2026-07-21 17:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834186": [
        {
            "ioc_value": "149.88.66.234:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 23:46:03",
            "last_seen_utc": "2026-07-21 17:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834185": [
        {
            "ioc_value": "116.204.36.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 23:45:54",
            "last_seen_utc": "2026-07-21 17:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834170": [
        {
            "ioc_value": "97.74.92.237:63334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-19 19:45:40",
            "last_seen_utc": "2026-07-21 17:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834169": [
        {
            "ioc_value": "45.81.243.44:7089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:45:09",
            "last_seen_utc": "2026-07-21 17:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834168": [
        {
            "ioc_value": "211.235.43.192:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:44:17",
            "last_seen_utc": "2026-07-21 17:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834167": [
        {
            "ioc_value": "205.209.106.158:5228",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:44:13",
            "last_seen_utc": "2026-07-21 17:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834165": [
        {
            "ioc_value": "2.27.5.37:8912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 19:44:09",
            "last_seen_utc": "2026-07-20 08:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834166": [
        {
            "ioc_value": "2.27.5.42:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 19:44:09",
            "last_seen_utc": "2026-07-20 08:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834164": [
        {
            "ioc_value": "198.23.185.136:60",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:44:06",
            "last_seen_utc": "2026-07-19 18:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834163": [
        {
            "ioc_value": "194.48.251.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-19 19:44:04",
            "last_seen_utc": "2026-07-21 08:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834162": [
        {
            "ioc_value": "155.103.71.115:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 19:43:26",
            "last_seen_utc": "2026-07-21 08:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834161": [
        {
            "ioc_value": "141.98.10.150:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 19:43:18",
            "last_seen_utc": "2026-07-19 18:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834160": [
        {
            "ioc_value": "107.172.238.13:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 19:43:09",
            "last_seen_utc": "2026-07-20 08:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834159": [
        {
            "ioc_value": "102.220.160.222:2025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:43:03",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834134": [
        {
            "ioc_value": "81.69.253.132:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:46:33",
            "last_seen_utc": "2026-07-21 17:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834132": [
        {
            "ioc_value": "47.242.0.207:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:46:26",
            "last_seen_utc": "2026-07-21 17:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834133": [
        {
            "ioc_value": "47.242.0.207:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:46:26",
            "last_seen_utc": "2026-07-21 17:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834131": [
        {
            "ioc_value": "114.134.187.38:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:45:55",
            "last_seen_utc": "2026-07-21 17:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834108": [
        {
            "ioc_value": "173.231.188.244:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 13:55:35",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d113f72b9248e3a89d72d1238a8465af7857822b82951681cff22391ffff3039/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834100": [
        {
            "ioc_value": "64.90.3.208:7891",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:53",
            "last_seen_utc": "2026-07-21 17:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834098": [
        {
            "ioc_value": "185.92.190.214:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:35",
            "last_seen_utc": "2026-07-21 17:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834099": [
        {
            "ioc_value": "185.92.190.216:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:35",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834097": [
        {
            "ioc_value": "www.api-aws.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:11",
            "last_seen_utc": "2026-07-20 14:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834066": [
        {
            "ioc_value": "91.92.242.67:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 09:45:54",
            "last_seen_utc": "2026-07-19 18:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834063": [
        {
            "ioc_value": "77.110.119.172:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-19 09:45:43",
            "last_seen_utc": "2026-07-21 17:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834064": [
        {
            "ioc_value": "78.108.56.64:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 09:45:43",
            "last_seen_utc": "2026-07-19 18:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834065": [
        {
            "ioc_value": "78.108.57.24:8912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 09:45:43",
            "last_seen_utc": "2026-07-19 18:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834062": [
        {
            "ioc_value": "167.99.78.100:4437",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-19 09:45:37",
            "last_seen_utc": "2026-07-21 15:13:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/64767a09cce6d538bea2d11e0c59f47abd05f6e57f7a88b2b7a864c782cc1041/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834060": [
        {
            "ioc_value": "45.32.66.51:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 09:45:22",
            "last_seen_utc": "2026-07-19 18:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834059": [
        {
            "ioc_value": "198.23.185.82:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 09:44:13",
            "last_seen_utc": "2026-07-21 17:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834058": [
        {
            "ioc_value": "194.116.236.239:4068",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 09:44:10",
            "last_seen_utc": "2026-07-19 18:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834056": [
        {
            "ioc_value": "185.158.249.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-19 09:43:56",
            "last_seen_utc": "2026-07-20 18:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834054": [
        {
            "ioc_value": "139.180.190.68:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-19 09:43:19",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834053": [
        {
            "ioc_value": "138.2.120.11:61234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-19 09:43:18",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834052": [
        {
            "ioc_value": "128.90.105.170:7203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-19 09:43:15",
            "last_seen_utc": "2026-07-19 18:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834051": [
        {
            "ioc_value": "103.153.254.32:6933",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-19 09:43:05",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834050": [
        {
            "ioc_value": "102.220.160.217:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 09:43:03",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834034": [
        {
            "ioc_value": "198.23.185.136:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 08:00:23",
            "last_seen_utc": "2026-07-21 17:44:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1834029": [
        {
            "ioc_value": "151.239.24.122:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 07:43:54",
            "last_seen_utc": "2026-07-21 17:46:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833837": [
        {
            "ioc_value": "165.227.123.79:6504",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-19 05:57:11",
            "last_seen_utc": "2026-07-21 14:39:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AddType,ClickFix,DigitalOcean,FakeCAPTCHA,mtls,nginx,one-check.lol,PowerShell,TLS1.3",
            "anonymous": 0,
            "reporter": "init_0"
        }
    ],
    "1833917": [
        {
            "ioc_value": "115.190.147.66:63512",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-18 23:45:44",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833874": [
        {
            "ioc_value": "91.92.240.194:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-18 19:45:29",
            "last_seen_utc": "2026-07-21 17:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833870": [
        {
            "ioc_value": "82.146.52.98:8790",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-18 19:45:22",
            "last_seen_utc": "2026-07-21 17:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833868": [
        {
            "ioc_value": "77.237.119.204:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-06-18 19:45:19",
            "last_seen_utc": "2026-07-21 17:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833867": [
        {
            "ioc_value": "64.89.160.127:8086",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:45:16",
            "last_seen_utc": "2026-07-21 08:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833860": [
        {
            "ioc_value": "209.54.102.152:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:44:10",
            "last_seen_utc": "2026-07-20 08:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833861": [
        {
            "ioc_value": "209.54.102.152:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:44:10",
            "last_seen_utc": "2026-07-20 08:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833862": [
        {
            "ioc_value": "209.54.102.152:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:44:10",
            "last_seen_utc": "2026-07-20 08:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833859": [
        {
            "ioc_value": "176.12.64.118:8790",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-18 19:43:39",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833857": [
        {
            "ioc_value": "147.93.191.75:5005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:43:21",
            "last_seen_utc": "2026-07-20 18:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833854": [
        {
            "ioc_value": "141.98.10.150:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:17",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833855": [
        {
            "ioc_value": "141.98.10.150:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:17",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833856": [
        {
            "ioc_value": "141.98.10.150:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:17",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833852": [
        {
            "ioc_value": "115.190.108.6:54233",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-06-18 19:43:11",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833851": [
        {
            "ioc_value": "107.172.238.14:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:09",
            "last_seen_utc": "2026-07-20 08:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833848": [
        {
            "ioc_value": "102.220.160.217:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:43:03",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833752": [
        {
            "ioc_value": "91.223.208.217:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-18 09:46:00",
            "last_seen_utc": "2026-07-19 18:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833750": [
        {
            "ioc_value": "54.38.94.225:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-18 09:45:43",
            "last_seen_utc": "2026-07-21 17:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833749": [
        {
            "ioc_value": "35.254.198.45:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 09:45:15",
            "last_seen_utc": "2026-07-21 17:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833744": [
        {
            "ioc_value": "209.99.191.33:440",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-18 09:44:25",
            "last_seen_utc": "2026-07-21 17:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833742": [
        {
            "ioc_value": "178.16.55.204:5022",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-18 09:43:47",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833741": [
        {
            "ioc_value": "172.245.195.233:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 09:43:41",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833623": [
        {
            "ioc_value": "62.113.59.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 23:46:03",
            "last_seen_utc": "2026-07-21 17:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833622": [
        {
            "ioc_value": "106.13.189.138:56000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 23:45:31",
            "last_seen_utc": "2026-07-21 17:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833602": [
        {
            "ioc_value": "5.101.82.60:27015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 19:45:06",
            "last_seen_utc": "2026-07-21 17:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833600": [
        {
            "ioc_value": "209.54.102.152:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 19:44:09",
            "last_seen_utc": "2026-07-20 08:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833599": [
        {
            "ioc_value": "192.3.136.254:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 19:43:56",
            "last_seen_utc": "2026-07-20 08:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833598": [
        {
            "ioc_value": "185.212.128.176:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-17 19:43:49",
            "last_seen_utc": "2026-07-21 17:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833595": [
        {
            "ioc_value": "147.93.191.75:7000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 19:43:20",
            "last_seen_utc": "2026-07-19 18:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833593": [
        {
            "ioc_value": "103.110.80.154:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-17 19:43:04",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833590": [
        {
            "ioc_value": "1.92.101.103:8006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 19:00:16",
            "last_seen_utc": "2026-07-21 17:46:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1833500": [
        {
            "ioc_value": "20.39.60.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-17 17:00:15",
            "last_seen_utc": "2026-07-21 17:44:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1833497": [
        {
            "ioc_value": "102.220.160.222:5333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 17:00:12",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1833483": [
        {
            "ioc_value": "43.138.165.203:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 15:46:35",
            "last_seen_utc": "2026-07-21 17:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833482": [
        {
            "ioc_value": "42.193.15.237:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 15:46:34",
            "last_seen_utc": "2026-07-21 17:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833471": [
        {
            "ioc_value": "102.220.160.222:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 15:00:14",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1833454": [
        {
            "ioc_value": "147.93.191.75:6006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 13:00:12",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1833440": [
        {
            "ioc_value": "147.93.191.75:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 12:00:22",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1833435": [
        {
            "ioc_value": "185.92.190.217:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 11:46:36",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833434": [
        {
            "ioc_value": "1.13.141.229:8480",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 11:46:12",
            "last_seen_utc": "2026-07-20 14:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833405": [
        {
            "ioc_value": "98.191.176.222:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-06-17 09:48:23",
            "last_seen_utc": "2026-07-21 17:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833403": [
        {
            "ioc_value": "31.77.189.2:6064",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 09:46:53",
            "last_seen_utc": "2026-07-19 18:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833401": [
        {
            "ioc_value": "31.76.87.242:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 09:46:51",
            "last_seen_utc": "2026-07-19 18:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833400": [
        {
            "ioc_value": "2.26.74.90:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 09:45:18",
            "last_seen_utc": "2026-07-19 18:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833397": [
        {
            "ioc_value": "178.128.116.134:3443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-17 09:44:26",
            "last_seen_utc": "2026-07-21 17:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833393": [
        {
            "ioc_value": "138.199.59.5:53522",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-17 09:43:33",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833392": [
        {
            "ioc_value": "103.53.80.201:1235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-17 09:43:10",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833372": [
        {
            "ioc_value": "223.166.31.185:2082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 08:24:49",
            "last_seen_utc": "2026-07-21 17:46:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833010": [
        {
            "ioc_value": "43.138.225.166:6615",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:04",
            "last_seen_utc": "2026-07-21 17:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833008": [
        {
            "ioc_value": "212.14.244.222:807",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:00",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833009": [
        {
            "ioc_value": "212.14.244.222:809",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:00",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833007": [
        {
            "ioc_value": "122.51.50.44:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:45:48",
            "last_seen_utc": "2026-07-21 17:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832783": [
        {
            "ioc_value": "74.208.13.152:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-16 19:45:29",
            "last_seen_utc": "2026-07-21 17:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832780": [
        {
            "ioc_value": "45.198.224.210:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:45:06",
            "last_seen_utc": "2026-07-21 17:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832781": [
        {
            "ioc_value": "45.198.224.211:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:45:06",
            "last_seen_utc": "2026-07-21 17:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832782": [
        {
            "ioc_value": "45.198.224.212:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:45:06",
            "last_seen_utc": "2026-07-21 17:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832778": [
        {
            "ioc_value": "31.76.32.159:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:44:52",
            "last_seen_utc": "2026-07-19 18:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832776": [
        {
            "ioc_value": "2.26.75.102:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:44:06",
            "last_seen_utc": "2026-07-19 18:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832775": [
        {
            "ioc_value": "2.26.74.90:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:44:05",
            "last_seen_utc": "2026-07-19 18:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832771": [
        {
            "ioc_value": "192.3.136.254:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:43:58",
            "last_seen_utc": "2026-07-20 08:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832772": [
        {
            "ioc_value": "192.3.136.254:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-16 19:43:58",
            "last_seen_utc": "2026-07-20 18:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832765": [
        {
            "ioc_value": "156.247.54.11:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-16 19:43:26",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832766": [
        {
            "ioc_value": "156.247.54.12:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-16 19:43:26",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832767": [
        {
            "ioc_value": "156.247.54.13:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-16 19:43:26",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832768": [
        {
            "ioc_value": "156.247.54.14:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-16 19:43:26",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832762": [
        {
            "ioc_value": "119.59.118.75:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:43:12",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832761": [
        {
            "ioc_value": "102.220.160.222:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 19:43:02",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832647": [
        {
            "ioc_value": "39.106.205.6:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 11:00:15",
            "last_seen_utc": "2026-07-21 17:46:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1832633": [
        {
            "ioc_value": "91.132.161.21:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:45:48",
            "last_seen_utc": "2026-07-21 17:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832632": [
        {
            "ioc_value": "5.89.155.59:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-16 09:45:30",
            "last_seen_utc": "2026-07-21 17:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832630": [
        {
            "ioc_value": "45.198.224.214:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:45:16",
            "last_seen_utc": "2026-07-21 17:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832631": [
        {
            "ioc_value": "45.198.224.215:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:45:16",
            "last_seen_utc": "2026-07-21 17:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832629": [
        {
            "ioc_value": "2.26.229.254:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:44:09",
            "last_seen_utc": "2026-07-21 17:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832623": [
        {
            "ioc_value": "172.232.105.92:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-16 09:43:39",
            "last_seen_utc": "2026-07-20 18:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832624": [
        {
            "ioc_value": "172.234.16.151:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:43:39",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832618": [
        {
            "ioc_value": "147.93.191.75:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:21",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832615": [
        {
            "ioc_value": "136.111.38.101:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:15",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832616": [
        {
            "ioc_value": "136.111.38.101:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:15",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832612": [
        {
            "ioc_value": "118.107.5.209:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:43:12",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832611": [
        {
            "ioc_value": "102.220.160.222:2026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:02",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832600": [
        {
            "ioc_value": "151.239.24.160:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 08:39:04",
            "last_seen_utc": "2026-07-21 17:46:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832539": [
        {
            "ioc_value": "45.151.101.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 03:46:04",
            "last_seen_utc": "2026-07-20 14:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832522": [
        {
            "ioc_value": "129.204.14.131:57000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 23:45:48",
            "last_seen_utc": "2026-07-21 17:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832485": [
        {
            "ioc_value": "212.193.5.199:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-15 19:44:11",
            "last_seen_utc": "2026-07-21 17:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832478": [
        {
            "ioc_value": "166.88.159.146:5353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-15 19:43:31",
            "last_seen_utc": "2026-07-19 18:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832474": [
        {
            "ioc_value": "156.247.54.10:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-15 19:43:24",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832471": [
        {
            "ioc_value": "144.31.236.223:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-15 19:43:17",
            "last_seen_utc": "2026-07-19 18:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832470": [
        {
            "ioc_value": "102.46.221.148:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 19:43:02",
            "last_seen_utc": "2026-07-20 08:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832399": [
        {
            "ioc_value": "23.95.170.223:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:46:19",
            "last_seen_utc": "2026-07-21 17:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832398": [
        {
            "ioc_value": "cs.tpedu2metricstw.dpdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:45:49",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832378": [
        {
            "ioc_value": "79.175.189.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 14:00:16",
            "last_seen_utc": "2026-07-21 17:46:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1832323": [
        {
            "ioc_value": "89.42.134.220:1803",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 09:45:54",
            "last_seen_utc": "2026-07-21 17:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832320": [
        {
            "ioc_value": "8.210.84.56:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:45:46",
            "last_seen_utc": "2026-07-21 17:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832319": [
        {
            "ioc_value": "31.76.87.112:7716",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-15 09:45:09",
            "last_seen_utc": "2026-07-19 18:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832317": [
        {
            "ioc_value": "213.193.20.192:9281",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:44:22",
            "last_seen_utc": "2026-07-21 17:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832313": [
        {
            "ioc_value": "131.143.251.246:53921",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:43:17",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832283": [
        {
            "ioc_value": "45.202.1.194:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 06:51:54",
            "last_seen_utc": "2026-07-21 17:46:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832204": [
        {
            "ioc_value": "124.222.218.12:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 23:45:41",
            "last_seen_utc": "2026-07-20 14:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832163": [
        {
            "ioc_value": "89.42.134.220:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 19:45:30",
            "last_seen_utc": "2026-07-21 17:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832161": [
        {
            "ioc_value": "82.47.101.191:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-14 19:45:26",
            "last_seen_utc": "2026-07-19 18:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832158": [
        {
            "ioc_value": "43.133.164.200:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 19:44:54",
            "last_seen_utc": "2026-07-21 17:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832152": [
        {
            "ioc_value": "172.245.195.233:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 19:43:36",
            "last_seen_utc": "2026-07-20 18:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832076": [
        {
            "ioc_value": "217.60.241.14:427",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-14 11:58:37",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832077": [
        {
            "ioc_value": "51.195.111.212:427",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-14 11:58:37",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832078": [
        {
            "ioc_value": "217.60.241.14:424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-14 11:58:37",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832079": [
        {
            "ioc_value": "51.195.111.212:424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-14 11:58:37",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832074": [
        {
            "ioc_value": "23.254.129.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 11:45:50",
            "last_seen_utc": "2026-07-21 17:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832073": [
        {
            "ioc_value": "207.56.229.234:4545",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 11:45:48",
            "last_seen_utc": "2026-07-20 14:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832072": [
        {
            "ioc_value": "sys.systemworld.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 11:45:27",
            "last_seen_utc": "2026-07-21 17:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832021": [
        {
            "ioc_value": "35.243.42.203:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 11:00:16",
            "last_seen_utc": "2026-07-21 17:45:11",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1832010": [
        {
            "ioc_value": "103.47.83.115:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 10:35:04",
            "last_seen_utc": "2026-07-21 17:46:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831995": [
        {
            "ioc_value": "64.225.102.218:31400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-14 09:45:07",
            "last_seen_utc": "2026-07-21 17:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831993": [
        {
            "ioc_value": "45.198.224.213:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 09:44:49",
            "last_seen_utc": "2026-07-21 17:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831992": [
        {
            "ioc_value": "23.235.185.42:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-14 09:44:35",
            "last_seen_utc": "2026-07-21 17:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831990": [
        {
            "ioc_value": "209.99.189.198:7004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 09:44:04",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831991": [
        {
            "ioc_value": "209.99.189.198:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-14 09:44:04",
            "last_seen_utc": "2026-07-21 17:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831987": [
        {
            "ioc_value": "185.207.154.11:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 09:43:43",
            "last_seen_utc": "2026-07-21 17:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831983": [
        {
            "ioc_value": "1.14.234.107:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 09:43:02",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831979": [
        {
            "ioc_value": "49.232.4.71:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 09:00:14",
            "last_seen_utc": "2026-07-21 17:46:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1831974": [
        {
            "ioc_value": "49.232.4.71:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 08:00:20",
            "last_seen_utc": "2026-07-21 17:46:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1831842": [
        {
            "ioc_value": "85.121.176.239:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-13 19:45:34",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831838": [
        {
            "ioc_value": "45.153.127.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-06-13 19:45:04",
            "last_seen_utc": "2026-07-21 17:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831834": [
        {
            "ioc_value": "209.99.189.198:7005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:44:13",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831835": [
        {
            "ioc_value": "209.99.189.198:7006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:44:13",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831828": [
        {
            "ioc_value": "191.107.87.183:5011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 19:43:55",
            "last_seen_utc": "2026-07-21 17:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831825": [
        {
            "ioc_value": "172.245.195.233:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 19:43:37",
            "last_seen_utc": "2026-07-21 08:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831733": [
        {
            "ioc_value": "98.191.176.231:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-06-13 09:46:13",
            "last_seen_utc": "2026-07-21 17:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831732": [
        {
            "ioc_value": "89.42.134.220:1991",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 09:46:08",
            "last_seen_utc": "2026-07-21 17:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831730": [
        {
            "ioc_value": "34.123.214.16:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-06-13 09:45:23",
            "last_seen_utc": "2026-07-21 17:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831728": [
        {
            "ioc_value": "31.76.32.201:1377",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 09:45:22",
            "last_seen_utc": "2026-07-19 18:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831729": [
        {
            "ioc_value": "31.76.32.230:1499",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-13 09:45:22",
            "last_seen_utc": "2026-07-19 18:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831727": [
        {
            "ioc_value": "23.235.185.44:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-13 09:45:15",
            "last_seen_utc": "2026-07-21 17:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831726": [
        {
            "ioc_value": "188.121.162.153:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 09:44:10",
            "last_seen_utc": "2026-07-19 18:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831725": [
        {
            "ioc_value": "185.212.129.185:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-13 09:44:06",
            "last_seen_utc": "2026-07-21 17:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831722": [
        {
            "ioc_value": "130.185.82.117:5641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 09:43:18",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831720": [
        {
            "ioc_value": "108.181.115.254:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-06-13 09:43:12",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831721": [
        {
            "ioc_value": "108.181.115.254:7045",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-06-13 09:43:12",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831717": [
        {
            "ioc_value": "101.33.202.134:9989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 09:43:02",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831611": [
        {
            "ioc_value": "172.94.18.103:72",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 19:43:35",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831610": [
        {
            "ioc_value": "172.245.195.233:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 19:43:34",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831608": [
        {
            "ioc_value": "149.104.28.77:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 19:43:19",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830851": [
        {
            "ioc_value": "78.141.208.70:46337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:45:24",
            "last_seen_utc": "2026-07-21 17:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830849": [
        {
            "ioc_value": "64.89.162.178:5903",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:45:21",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830845": [
        {
            "ioc_value": "45.137.99.3:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:44:55",
            "last_seen_utc": "2026-07-21 17:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830844": [
        {
            "ioc_value": "31.76.32.160:7716",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:44:47",
            "last_seen_utc": "2026-07-20 08:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830843": [
        {
            "ioc_value": "31.57.184.154:7008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 09:44:45",
            "last_seen_utc": "2026-07-21 17:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830842": [
        {
            "ioc_value": "2.26.21.17:4323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:44:00",
            "last_seen_utc": "2026-07-21 17:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830835": [
        {
            "ioc_value": "144.31.236.19:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:43:18",
            "last_seen_utc": "2026-07-20 08:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830834": [
        {
            "ioc_value": "114.132.238.70:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:43:11",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830833": [
        {
            "ioc_value": "110.42.34.220:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:43:10",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830533": [
        {
            "ioc_value": "60.205.126.246:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-12 07:20:03",
            "last_seen_utc": "2026-07-21 17:46:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830531": [
        {
            "ioc_value": "1.13.141.229:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-12 07:19:49",
            "last_seen_utc": "2026-07-20 14:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830416": [
        {
            "ioc_value": "49.233.136.227:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 21:00:15",
            "last_seen_utc": "2026-07-21 17:46:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1830401": [
        {
            "ioc_value": "64.89.162.59:4422",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 19:45:11",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830398": [
        {
            "ioc_value": "46.101.195.123:31400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-11 19:44:52",
            "last_seen_utc": "2026-07-21 17:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830399": [
        {
            "ioc_value": "46.151.182.181:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-11 19:44:52",
            "last_seen_utc": "2026-07-21 17:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830392": [
        {
            "ioc_value": "23.235.185.45:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-11 19:44:35",
            "last_seen_utc": "2026-07-21 17:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830393": [
        {
            "ioc_value": "23.235.185.46:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-11 19:44:35",
            "last_seen_utc": "2026-07-21 17:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830390": [
        {
            "ioc_value": "209.99.188.193:43221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:44:02",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830389": [
        {
            "ioc_value": "2.27.62.228:60204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-11 19:43:57",
            "last_seen_utc": "2026-07-21 17:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830387": [
        {
            "ioc_value": "192.3.139.18:15221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:43:50",
            "last_seen_utc": "2026-07-21 17:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830357": [
        {
            "ioc_value": "139.59.106.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-11 17:00:11",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1830348": [
        {
            "ioc_value": "139.59.106.160:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-11 16:00:23",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1830310": [
        {
            "ioc_value": "122.51.50.44:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 14:00:22",
            "last_seen_utc": "2026-07-21 17:46:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1830307": [
        {
            "ioc_value": "172.94.18.103:79",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 14:00:17",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1830289": [
        {
            "ioc_value": "113.44.64.117:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-11 12:46:30",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/113.44.64.117#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1830291": [
        {
            "ioc_value": "159.89.48.54:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-11 12:46:30",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/159.89.48.54#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1830206": [
        {
            "ioc_value": "117.72.159.215:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 12:42:24",
            "last_seen_utc": "2026-07-21 17:46:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.159.215#8080",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1830053": [
        {
            "ioc_value": "206.81.21.156:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 09:44:07",
            "last_seen_utc": "2026-07-21 17:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830007": [
        {
            "ioc_value": "45.87.53.6:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:43:05",
            "last_seen_utc": "2026-07-21 17:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830006": [
        {
            "ioc_value": "120.55.3.157:10000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:43:04",
            "last_seen_utc": "2026-07-21 17:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830004": [
        {
            "ioc_value": "43.136.180.88:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:48",
            "last_seen_utc": "2026-07-21 17:46:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830002": [
        {
            "ioc_value": "43.136.180.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:47",
            "last_seen_utc": "2026-07-21 17:46:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830003": [
        {
            "ioc_value": "47.121.181.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:47",
            "last_seen_utc": "2026-07-21 17:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830001": [
        {
            "ioc_value": "124.220.41.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:46",
            "last_seen_utc": "2026-07-21 17:46:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829999": [
        {
            "ioc_value": "160.202.230.103:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:44",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829957": [
        {
            "ioc_value": "192.144.213.21:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 05:26:05",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1829946": [
        {
            "ioc_value": "85.137.240.208:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 23:45:53",
            "last_seen_utc": "2026-07-21 17:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829909": [
        {
            "ioc_value": "87.182.39.55:51125",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 19:45:19",
            "last_seen_utc": "2026-07-19 18:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829908": [
        {
            "ioc_value": "82.221.139.243:52281",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-10 19:45:15",
            "last_seen_utc": "2026-07-19 18:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829907": [
        {
            "ioc_value": "64.89.162.178:5902",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 19:45:10",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829903": [
        {
            "ioc_value": "23.235.185.43:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-10 19:44:35",
            "last_seen_utc": "2026-07-21 17:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829902": [
        {
            "ioc_value": "216.158.235.73:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:44:33",
            "last_seen_utc": "2026-07-21 17:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829899": [
        {
            "ioc_value": "193.135.137.240:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 19:43:51",
            "last_seen_utc": "2026-07-21 17:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829896": [
        {
            "ioc_value": "185.33.84.183:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:43:46",
            "last_seen_utc": "2026-07-21 17:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829893": [
        {
            "ioc_value": "172.94.18.103:71",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 19:43:34",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829892": [
        {
            "ioc_value": "170.39.185.141:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:43:32",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829888": [
        {
            "ioc_value": "153.75.249.13:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 19:43:20",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829779": [
        {
            "ioc_value": "185.92.190.214:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-07-21 17:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829780": [
        {
            "ioc_value": "185.92.190.215:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-07-21 17:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829781": [
        {
            "ioc_value": "185.92.190.215:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-07-21 17:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829782": [
        {
            "ioc_value": "185.92.190.216:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-07-21 17:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829783": [
        {
            "ioc_value": "185.92.190.217:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829777": [
        {
            "ioc_value": "185.92.190.213:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:52",
            "last_seen_utc": "2026-07-21 17:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829778": [
        {
            "ioc_value": "185.92.190.213:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:52",
            "last_seen_utc": "2026-07-21 17:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825873": [
        {
            "ioc_value": "38.47.122.34:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 10:00:17",
            "last_seen_utc": "2026-07-21 17:46:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1825867": [
        {
            "ioc_value": "64.89.162.117:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-10 09:45:40",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825865": [
        {
            "ioc_value": "45.81.17.44:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 09:45:19",
            "last_seen_utc": "2026-07-21 17:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825864": [
        {
            "ioc_value": "45.147.28.58:42461",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 09:45:16",
            "last_seen_utc": "2026-07-21 17:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825863": [
        {
            "ioc_value": "31.76.87.188:4034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:45:01",
            "last_seen_utc": "2026-07-20 08:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825862": [
        {
            "ioc_value": "23.95.220.192:43999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 09:44:56",
            "last_seen_utc": "2026-07-21 17:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825858": [
        {
            "ioc_value": "2.27.5.120:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:44:10",
            "last_seen_utc": "2026-07-19 18:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825857": [
        {
            "ioc_value": "2.26.75.249:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 09:44:09",
            "last_seen_utc": "2026-07-19 18:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825853": [
        {
            "ioc_value": "192.208.12.91:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 09:44:00",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825851": [
        {
            "ioc_value": "178.236.46.43:7912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-10 09:43:45",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825850": [
        {
            "ioc_value": "163.245.217.48:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 09:43:35",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825847": [
        {
            "ioc_value": "154.83.186.106:30159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-10 09:43:25",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825788": [
        {
            "ioc_value": "34.92.128.98:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 07:18:53",
            "last_seen_utc": "2026-07-21 17:46:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825685": [
        {
            "ioc_value": "142.93.96.42:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-10 04:00:23",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1825678": [
        {
            "ioc_value": "218.244.142.4:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 03:45:38",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825631": [
        {
            "ioc_value": "198.46.199.110:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 21:45:51",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825614": [
        {
            "ioc_value": "45.87.53.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 20:00:17",
            "last_seen_utc": "2026-07-20 09:14:02",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1825613": [
        {
            "ioc_value": "46.151.182.16:1011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 19:44:51",
            "last_seen_utc": "2026-07-21 17:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825610": [
        {
            "ioc_value": "2.26.75.243:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-09 19:43:55",
            "last_seen_utc": "2026-07-19 18:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825607": [
        {
            "ioc_value": "167.160.186.140:62738",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-09 19:43:30",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825604": [
        {
            "ioc_value": "104.168.0.29:52203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 19:43:06",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825427": [
        {
            "ioc_value": "170.62.130.191:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-09 09:43:35",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825381": [
        {
            "ioc_value": "110.42.219.9:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 07:00:14",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1825373": [
        {
            "ioc_value": "51.195.111.212:416",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-09 06:21:30",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825374": [
        {
            "ioc_value": "217.60.241.14:416",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-09 06:21:30",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825368": [
        {
            "ioc_value": "217.60.241.14:425",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-09 06:21:29",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825369": [
        {
            "ioc_value": "51.195.111.212:425",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-09 06:21:29",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825370": [
        {
            "ioc_value": "217.60.241.14:418",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-09 06:21:29",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825362": [
        {
            "ioc_value": "217.60.241.17:424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-09 06:21:28",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825364": [
        {
            "ioc_value": "51.195.111.212:430",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-09 06:21:28",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825351": [
        {
            "ioc_value": "217.60.241.17:425",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-09 06:21:25",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825226": [
        {
            "ioc_value": "155.103.70.100:13407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-08 19:43:23",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824915": [
        {
            "ioc_value": "94.183.232.247:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-08 09:45:29",
            "last_seen_utc": "2026-07-21 17:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824909": [
        {
            "ioc_value": "155.103.70.100:13408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-08 09:43:22",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824508": [
        {
            "ioc_value": "209.200.246.194:17568",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-07 23:45:14",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824435": [
        {
            "ioc_value": "94.183.232.247:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-06-07 19:45:13",
            "last_seen_utc": "2026-07-21 17:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824433": [
        {
            "ioc_value": "82.156.224.184:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:45:00",
            "last_seen_utc": "2026-07-21 17:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824431": [
        {
            "ioc_value": "46.246.96.214:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:44:43",
            "last_seen_utc": "2026-07-21 17:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824430": [
        {
            "ioc_value": "45.38.20.122:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 19:44:40",
            "last_seen_utc": "2026-07-21 17:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824426": [
        {
            "ioc_value": "172.189.57.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:43:30",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824259": [
        {
            "ioc_value": "60.191.87.107:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-06-07 09:45:24",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824255": [
        {
            "ioc_value": "31.57.184.154:2505",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-07 09:44:50",
            "last_seen_utc": "2026-07-21 17:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824254": [
        {
            "ioc_value": "209.99.188.193:4323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:44:10",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824251": [
        {
            "ioc_value": "154.94.232.165:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:43:26",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824249": [
        {
            "ioc_value": "146.70.41.174:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-07 09:43:23",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824247": [
        {
            "ioc_value": "137.184.163.27:5613",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-07 09:43:16",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824136": [
        {
            "ioc_value": "173.249.41.141:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-06 20:00:20",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1824133": [
        {
            "ioc_value": "91.221.191.167:4323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-06 19:44:51",
            "last_seen_utc": "2026-07-21 17:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824132": [
        {
            "ioc_value": "5.230.201.36:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-06 19:44:38",
            "last_seen_utc": "2026-07-21 17:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824130": [
        {
            "ioc_value": "46.151.182.243:55380",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 19:44:30",
            "last_seen_utc": "2026-07-21 17:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824029": [
        {
            "ioc_value": "154.12.86.154:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824030": [
        {
            "ioc_value": "154.12.86.154:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824031": [
        {
            "ioc_value": "154.12.86.154:9004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824012": [
        {
            "ioc_value": "47.101.51.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:30",
            "last_seen_utc": "2026-07-21 17:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824008": [
        {
            "ioc_value": "167.71.233.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:23",
            "last_seen_utc": "2026-07-20 14:46:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823853": [
        {
            "ioc_value": "https://pas.sm188star.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-07-21 17:24:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823854": [
        {
            "ioc_value": "pas.sm188star.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-07-21 17:24:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823730": [
        {
            "ioc_value": "101.43.103.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 03:44:58",
            "last_seen_utc": "2026-07-21 17:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823644": [
        {
            "ioc_value": "87.107.191.39:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 19:45:55",
            "last_seen_utc": "2026-07-21 17:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823641": [
        {
            "ioc_value": "ns1.newchatsits.ir",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823640": [
        {
            "ioc_value": "62.109.19.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-05 19:44:53",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822764": [
        {
            "ioc_value": "158.247.194.144:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-05 09:43:29",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822643": [
        {
            "ioc_value": "186.169.71.201:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 03:00:15",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1822613": [
        {
            "ioc_value": "5.230.201.36:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-05 01:00:17",
            "last_seen_utc": "2026-07-21 17:45:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1822600": [
        {
            "ioc_value": "34.202.161.96:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:28",
            "last_seen_utc": "2026-07-21 17:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822599": [
        {
            "ioc_value": "updates.fisgloval.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:07",
            "last_seen_utc": "2026-07-21 17:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822526": [
        {
            "ioc_value": "163.172.174.237:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-04 19:43:27",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822527": [
        {
            "ioc_value": "163.172.174.237:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-04 19:43:27",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822488": [
        {
            "ioc_value": "20.64.242.233:1024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 17:00:13",
            "last_seen_utc": "2026-07-21 17:44:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1822415": [
        {
            "ioc_value": "120.26.208.96:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 14:50:35",
            "last_seen_utc": "2026-07-21 17:46:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1822346": [
        {
            "ioc_value": "154.12.86.154:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 11:46:46",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822301": [
        {
            "ioc_value": "82.23.246.160:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:45:35",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822299": [
        {
            "ioc_value": "185.72.9.227:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:43:56",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822296": [
        {
            "ioc_value": "156.247.40.190:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:43:29",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822295": [
        {
            "ioc_value": "155.103.70.198:13408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-04 09:43:28",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822159": [
        {
            "ioc_value": "217.60.241.17:416",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-06-04 05:50:13",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822015": [
        {
            "ioc_value": "20.220.29.224:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-03 19:44:00",
            "last_seen_utc": "2026-07-21 17:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822011": [
        {
            "ioc_value": "168.144.36.228:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 19:43:33",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821983": [
        {
            "ioc_value": "http://178.16.54.109/sodola",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.phorpiex",
            "malware_alias": "Tldr,Trik,TwizT,phorphiex",
            "malware_printable": "Phorpiex",
            "first_seen_utc": "2026-06-03 18:58:52",
            "last_seen_utc": "2026-07-20 16:20:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Download,Phorpiex",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1821798": [
        {
            "ioc_value": "13.236.153.60:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-03 15:24:07",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1821844": [
        {
            "ioc_value": "47.82.234.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 15:23:52",
            "last_seen_utc": "2026-07-21 17:46:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1821877": [
        {
            "ioc_value": "4.240.85.243:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 14:36:55",
            "last_seen_utc": "2026-07-21 17:45:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/4.240.85.243#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1821870": [
        {
            "ioc_value": "62.192.173.249:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-03 14:34:08",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/62.192.173.249#9000",
            "tags": "adaptixc2,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1821807": [
        {
            "ioc_value": "209.200.246.194:11544",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 11:46:25",
            "last_seen_utc": "2026-07-21 17:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821716": [
        {
            "ioc_value": "82.23.246.160:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 09:45:37",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821715": [
        {
            "ioc_value": "204.194.50.173:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 09:44:13",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821713": [
        {
            "ioc_value": "156.247.40.190:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 09:43:30",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821684": [
        {
            "ioc_value": "77.93.155.111:10039",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 08:01:52",
            "last_seen_utc": "2026-07-21 17:45:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1821697": [
        {
            "ioc_value": "118.89.203.103:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 07:57:06",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821695": [
        {
            "ioc_value": "118.89.203.103:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 07:56:52",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821514": [
        {
            "ioc_value": "155.103.70.198:13407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-02 19:43:27",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821233": [
        {
            "ioc_value": "172.236.10.250:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-02 14:06:11",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/172.236.10.250#443",
            "tags": "c2,havoc,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1821227": [
        {
            "ioc_value": "198.13.51.245:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-02 14:05:08",
            "last_seen_utc": "2026-07-21 17:44:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/198.13.51.245#4321",
            "tags": "adaptixc2,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1821219": [
        {
            "ioc_value": "172.237.125.146:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 14:04:11",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/172.237.125.146#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1820866": [
        {
            "ioc_value": "15.204.255.172:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 09:43:26",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820727": [
        {
            "ioc_value": "23.235.185.46:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-01 20:49:16",
            "last_seen_utc": "2026-07-21 17:45:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820729": [
        {
            "ioc_value": "23.235.185.43:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-01 20:49:15",
            "last_seen_utc": "2026-07-21 17:45:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820730": [
        {
            "ioc_value": "23.235.185.42:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-01 20:49:15",
            "last_seen_utc": "2026-07-21 17:45:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820723": [
        {
            "ioc_value": "178.16.54.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-01 19:43:43",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820722": [
        {
            "ioc_value": "178.16.52.47:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-01 19:43:42",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820615": [
        {
            "ioc_value": "82.156.224.184:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-01 15:11:43",
            "last_seen_utc": "2026-07-20 18:45:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820538": [
        {
            "ioc_value": "43.138.165.203:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 08:43:25",
            "last_seen_utc": "2026-07-21 17:46:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820506": [
        {
            "ioc_value": "165.22.225.218:5443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 06:44:52",
            "last_seen_utc": "2026-07-21 17:46:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820414": [
        {
            "ioc_value": "82.157.52.180:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:49",
            "last_seen_utc": "2026-07-21 17:46:40",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820430": [
        {
            "ioc_value": "49.233.215.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:38",
            "last_seen_utc": "2026-07-21 17:46:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820432": [
        {
            "ioc_value": "47.116.211.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 05:44:37",
            "last_seen_utc": "2026-07-21 17:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820398": [
        {
            "ioc_value": "154.38.114.115:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:46:19",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820397": [
        {
            "ioc_value": "ds.metric-take-datadqct.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:45:54",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820327": [
        {
            "ioc_value": "64.89.160.44:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-31 15:04:22",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820291": [
        {
            "ioc_value": "64.176.73.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-31 09:45:39",
            "last_seen_utc": "2026-07-21 17:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820214": [
        {
            "ioc_value": "64.89.160.44:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 06:48:28",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "205759,asyncrat,c2,censys",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1820043": [
        {
            "ioc_value": "38.54.63.135:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:45:23",
            "last_seen_utc": "2026-07-21 17:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820039": [
        {
            "ioc_value": "114.132.190.121:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:43:14",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819982": [
        {
            "ioc_value": "40.85.252.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-30 07:04:38",
            "last_seen_utc": "2026-07-21 17:45:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1819907": [
        {
            "ioc_value": "49.233.81.84:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:45:46",
            "last_seen_utc": "2026-07-21 17:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819906": [
        {
            "ioc_value": "43.140.219.30:7112",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-29 19:45:33",
            "last_seen_utc": "2026-07-21 17:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819904": [
        {
            "ioc_value": "27.102.137.139:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 19:45:20",
            "last_seen_utc": "2026-07-21 17:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819903": [
        {
            "ioc_value": "23.235.185.44:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-29 19:45:19",
            "last_seen_utc": "2026-07-21 17:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819901": [
        {
            "ioc_value": "192.162.199.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:44:12",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819898": [
        {
            "ioc_value": "172.86.109.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-29 19:43:49",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819895": [
        {
            "ioc_value": "162.248.224.236:7492",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819896": [
        {
            "ioc_value": "162.248.225.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819897": [
        {
            "ioc_value": "162.248.225.165:8603",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819894": [
        {
            "ioc_value": "162.248.224.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:41",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819893": [
        {
            "ioc_value": "157.20.182.17:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 19:43:36",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819889": [
        {
            "ioc_value": "111.229.154.250:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:43:14",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819866": [
        {
            "ioc_value": "124.220.235.4:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 15:46:36",
            "last_seen_utc": "2026-07-21 17:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819842": [
        {
            "ioc_value": "mub.depansm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:30:50",
            "last_seen_utc": "2026-07-21 17:23:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1819843": [
        {
            "ioc_value": "https://mub.depansm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:30:50",
            "last_seen_utc": "2026-07-21 17:23:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1819786": [
        {
            "ioc_value": "118.89.79.131:6528",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:33",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819756": [
        {
            "ioc_value": "185.212.129.146:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-29 09:44:05",
            "last_seen_utc": "2026-07-21 17:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819713": [
        {
            "ioc_value": "198.44.177.179:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 06:45:14",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819593": [
        {
            "ioc_value": "31.57.184.154:7005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-28 19:44:44",
            "last_seen_utc": "2026-07-21 17:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819587": [
        {
            "ioc_value": "157.20.182.18:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-28 19:43:28",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819586": [
        {
            "ioc_value": "13.209.95.4:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 19:43:13",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819406": [
        {
            "ioc_value": "91.215.85.212:45423",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:09",
            "last_seen_utc": "2026-07-21 17:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819405": [
        {
            "ioc_value": "85.209.90.132:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:05",
            "last_seen_utc": "2026-07-21 17:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819403": [
        {
            "ioc_value": "81.71.20.107:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:45:58",
            "last_seen_utc": "2026-07-21 17:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819402": [
        {
            "ioc_value": "43.133.165.151:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:45:23",
            "last_seen_utc": "2026-07-21 17:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819401": [
        {
            "ioc_value": "27.102.138.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:45:10",
            "last_seen_utc": "2026-07-21 17:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819396": [
        {
            "ioc_value": "202.95.8.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819397": [
        {
            "ioc_value": "202.95.8.98:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819394": [
        {
            "ioc_value": "193.5.65.169:4348",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-28 09:44:10",
            "last_seen_utc": "2026-07-21 17:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819395": [
        {
            "ioc_value": "193.5.65.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-28 09:44:10",
            "last_seen_utc": "2026-07-21 17:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819387": [
        {
            "ioc_value": "113.31.106.85:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:43:13",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819351": [
        {
            "ioc_value": "120.48.66.205:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-28 06:56:15",
            "last_seen_utc": "2026-07-21 17:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819240": [
        {
            "ioc_value": "46.246.14.2:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-28 05:33:16",
            "last_seen_utc": "2026-07-21 17:45:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1819225": [
        {
            "ioc_value": "91.200.84.198:8515",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:45:55",
            "last_seen_utc": "2026-07-21 17:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819224": [
        {
            "ioc_value": "45.32.236.190:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819222": [
        {
            "ioc_value": "43.106.14.139:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-27 19:45:12",
            "last_seen_utc": "2026-07-21 17:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819220": [
        {
            "ioc_value": "18.162.155.202:3350",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-27 19:43:47",
            "last_seen_utc": "2026-07-21 17:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819218": [
        {
            "ioc_value": "104.243.248.63:1807",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-27 19:43:09",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819146": [
        {
            "ioc_value": "8.134.70.73:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 15:46:43",
            "last_seen_utc": "2026-07-21 17:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819145": [
        {
            "ioc_value": "47.122.47.221:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 15:46:36",
            "last_seen_utc": "2026-07-21 17:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819042": [
        {
            "ioc_value": "164.90.206.5:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-27 09:43:38",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818955": [
        {
            "ioc_value": "117.72.159.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 07:09:22",
            "last_seen_utc": "2026-07-21 17:46:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1818956": [
        {
            "ioc_value": "8.163.49.50:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 07:09:22",
            "last_seen_utc": "2026-07-21 17:46:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1818878": [
        {
            "ioc_value": "190.2.150.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-26 19:43:55",
            "last_seen_utc": "2026-07-20 18:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818872": [
        {
            "ioc_value": "155.102.136.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-26 19:43:28",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818804": [
        {
            "ioc_value": "47.122.47.221:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 14:46:42",
            "last_seen_utc": "2026-07-21 17:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818730": [
        {
            "ioc_value": "45.227.253.121:35120",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-26 10:46:44",
            "last_seen_utc": "2026-07-21 17:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818714": [
        {
            "ioc_value": "198.23.185.82:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-26 10:01:20",
            "last_seen_utc": "2026-07-21 17:44:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1818696": [
        {
            "ioc_value": "193.24.123.160:45631",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-26 09:44:02",
            "last_seen_utc": "2026-07-21 17:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818695": [
        {
            "ioc_value": "191.93.116.106:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-26 09:43:57",
            "last_seen_utc": "2026-07-21 17:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818694": [
        {
            "ioc_value": "153.75.232.207:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-26 09:43:28",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818480": [
        {
            "ioc_value": "47.108.25.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 22:46:18",
            "last_seen_utc": "2026-07-21 17:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818434": [
        {
            "ioc_value": "37.77.150.174:4333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:52",
            "last_seen_utc": "2026-07-21 17:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818433": [
        {
            "ioc_value": "37.77.150.174:4332",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:51",
            "last_seen_utc": "2026-07-21 17:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818432": [
        {
            "ioc_value": "27.102.137.139:1243",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:44:46",
            "last_seen_utc": "2026-07-21 17:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818431": [
        {
            "ioc_value": "202.95.8.92:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-25 19:44:05",
            "last_seen_utc": "2026-07-21 17:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818426": [
        {
            "ioc_value": "157.20.182.17:1998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 19:43:27",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818351": [
        {
            "ioc_value": "157.20.182.17:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 14:01:54",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1818253": [
        {
            "ioc_value": "134.175.78.181:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 06:57:09",
            "last_seen_utc": "2026-07-21 17:46:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818107": [
        {
            "ioc_value": "31.171.131.118:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:45:21",
            "last_seen_utc": "2026-07-21 17:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818104": [
        {
            "ioc_value": "157.20.182.18:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:43:36",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818103": [
        {
            "ioc_value": "157.20.182.17:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:43:35",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818053": [
        {
            "ioc_value": "45.154.12.150:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:49",
            "last_seen_utc": "2026-07-21 17:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818052": [
        {
            "ioc_value": "103.210.236.87:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:17",
            "last_seen_utc": "2026-07-21 17:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818050": [
        {
            "ioc_value": "wsus.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:12",
            "last_seen_utc": "2026-07-21 17:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818051": [
        {
            "ioc_value": "wsus2.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:12",
            "last_seen_utc": "2026-07-21 17:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818032": [
        {
            "ioc_value": "104.168.0.29:52202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 14:10:22",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1818016": [
        {
            "ioc_value": "217.60.241.17:427",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-05-24 13:18:31",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817829": [
        {
            "ioc_value": "172.94.18.103:75",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 11:05:15",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1817873": [
        {
            "ioc_value": "172.94.18.103:73",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 11:04:56",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1817758": [
        {
            "ioc_value": "https://cyy.turbo88ml.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:09",
            "last_seen_utc": "2026-07-21 17:23:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1817757": [
        {
            "ioc_value": "cyy.turbo88ml.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:08",
            "last_seen_utc": "2026-07-21 17:23:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1817704": [
        {
            "ioc_value": "151.236.20.3:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-23 19:43:35",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817663": [
        {
            "ioc_value": "101.126.10.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:56:56",
            "last_seen_utc": "2026-07-21 17:46:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817661": [
        {
            "ioc_value": "8.137.170.3:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:56:55",
            "last_seen_utc": "2026-07-20 09:13:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817658": [
        {
            "ioc_value": "102.204.223.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:56:33",
            "last_seen_utc": "2026-07-21 17:46:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817632": [
        {
            "ioc_value": "203.83.10.114:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:54:01",
            "last_seen_utc": "2026-07-21 17:46:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1817427": [
        {
            "ioc_value": "88.119.167.142:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-22 19:45:35",
            "last_seen_utc": "2026-07-21 17:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817426": [
        {
            "ioc_value": "87.251.76.213:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-22 19:45:34",
            "last_seen_utc": "2026-07-21 17:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817206": [
        {
            "ioc_value": "46.20.109.225:8999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 11:36:04",
            "last_seen_utc": "2026-07-21 17:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1817239": [
        {
            "ioc_value": "88.119.167.143:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-22 09:45:23",
            "last_seen_utc": "2026-07-21 17:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817236": [
        {
            "ioc_value": "45.90.120.36:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 09:44:53",
            "last_seen_utc": "2026-07-21 17:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817235": [
        {
            "ioc_value": "31.57.184.154:7006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:40",
            "last_seen_utc": "2026-07-21 17:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817233": [
        {
            "ioc_value": "31.171.131.118:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:39",
            "last_seen_utc": "2026-07-21 17:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817234": [
        {
            "ioc_value": "31.171.131.118:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:39",
            "last_seen_utc": "2026-07-21 17:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817215": [
        {
            "ioc_value": "154.201.68.191:14125",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:46:18",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817132": [
        {
            "ioc_value": "129.204.14.131:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 08:11:41",
            "last_seen_utc": "2026-07-21 17:46:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1817159": [
        {
            "ioc_value": "143.14.9.56:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 08:11:29",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "adaptix_v1.2,adaptixc2,c2,panel",
            "anonymous": 0,
            "reporter": "Lenny_3BO"
        }
    ],
    "1817184": [
        {
            "ioc_value": "23.236.64.231:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 07:55:19",
            "last_seen_utc": "2026-07-21 17:46:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817055": [
        {
            "ioc_value": "42.121.150.29:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-21 19:45:14",
            "last_seen_utc": "2026-07-21 17:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817054": [
        {
            "ioc_value": "34.61.52.162:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-21 19:45:07",
            "last_seen_utc": "2026-07-21 17:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816738": [
        {
            "ioc_value": "41.216.189.163:43210",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:44:41",
            "last_seen_utc": "2026-07-21 17:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816737": [
        {
            "ioc_value": "221.207.101.175:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-20 19:44:32",
            "last_seen_utc": "2026-07-21 17:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816735": [
        {
            "ioc_value": "167.17.47.118:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:43:30",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816585": [
        {
            "ioc_value": "51.15.8.6:9998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-20 09:45:05",
            "last_seen_utc": "2026-07-21 17:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816583": [
        {
            "ioc_value": "202.1.31.83:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 09:43:56",
            "last_seen_utc": "2026-07-21 17:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816563": [
        {
            "ioc_value": "1.92.101.103:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 08:54:33",
            "last_seen_utc": "2026-07-21 17:46:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1816551": [
        {
            "ioc_value": "45.152.65.240:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 07:37:42",
            "last_seen_utc": "2026-07-21 17:46:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816481": [
        {
            "ioc_value": "114.134.187.38:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 05:25:02",
            "last_seen_utc": "2026-07-21 17:46:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1816445": [
        {
            "ioc_value": "43.142.137.169:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 20:46:09",
            "last_seen_utc": "2026-07-21 17:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816431": [
        {
            "ioc_value": "91.202.233.214:44123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-19 19:45:18",
            "last_seen_utc": "2026-07-21 17:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816427": [
        {
            "ioc_value": "31.57.184.154:2502",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 19:44:36",
            "last_seen_utc": "2026-07-21 17:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816294": [
        {
            "ioc_value": "142.93.165.129:3334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-19 09:43:19",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816252": [
        {
            "ioc_value": "45.152.65.240:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 06:46:32",
            "last_seen_utc": "2026-07-21 17:46:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816173": [
        {
            "ioc_value": "43.143.145.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:16:16",
            "last_seen_utc": "2026-07-21 17:46:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1816172": [
        {
            "ioc_value": "47.82.234.12:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:16:15",
            "last_seen_utc": "2026-07-21 17:46:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1816164": [
        {
            "ioc_value": "119.91.26.245:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:16:06",
            "last_seen_utc": "2026-07-21 17:46:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1816110": [
        {
            "ioc_value": "43.144.19.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:15:34",
            "last_seen_utc": "2026-07-21 17:46:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1816100": [
        {
            "ioc_value": "38.147.189.199:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-18 19:44:31",
            "last_seen_utc": "2026-07-21 17:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816096": [
        {
            "ioc_value": "138.124.90.26:51337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-18 19:43:13",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816036": [
        {
            "ioc_value": "207.180.250.181:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-18 18:05:44",
            "last_seen_utc": "2026-07-21 17:44:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1816037": [
        {
            "ioc_value": "207.180.250.181:10001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-18 18:05:44",
            "last_seen_utc": "2026-07-21 17:44:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1815927": [
        {
            "ioc_value": "163.181.46.56:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-18 09:43:30",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815861": [
        {
            "ioc_value": "217.60.241.17:421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-05-18 08:09:23",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815862": [
        {
            "ioc_value": "217.60.241.17:430",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-05-18 08:09:23",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815818": [
        {
            "ioc_value": "47.236.91.172:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:33:49",
            "last_seen_utc": "2026-07-21 17:46:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1815773": [
        {
            "ioc_value": "194.163.154.86:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-18 07:33:37",
            "last_seen_utc": "2026-07-21 17:44:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1815762": [
        {
            "ioc_value": "119.29.112.239:8005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 22:45:31",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815551": [
        {
            "ioc_value": "207.56.229.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 15:53:07",
            "last_seen_utc": "2026-07-20 14:46:42",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": "cobalt-strike,erebus-wraith,unattributed",
            "anonymous": 0,
            "reporter": "Erebu"
        }
    ],
    "1815461": [
        {
            "ioc_value": "81.71.20.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 06:52:36",
            "last_seen_utc": "2026-07-21 17:46:40",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1815397": [
        {
            "ioc_value": "45.155.69.153:43345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-16 19:45:35",
            "last_seen_utc": "2026-07-21 17:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815392": [
        {
            "ioc_value": "103.219.153.200:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:06",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815393": [
        {
            "ioc_value": "103.219.153.200:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:06",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815391": [
        {
            "ioc_value": "103.219.153.200:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-16 19:43:05",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815137": [
        {
            "ioc_value": "95.231.168.143:4483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-15 19:44:50",
            "last_seen_utc": "2026-07-21 17:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815133": [
        {
            "ioc_value": "34.69.130.10:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-15 19:44:19",
            "last_seen_utc": "2026-07-21 17:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815073": [
        {
            "ioc_value": "pgo.fatherchrismas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-07-21 17:23:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1815074": [
        {
            "ioc_value": "https://pgo.fatherchrismas.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-07-21 17:23:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1814914": [
        {
            "ioc_value": "207.56.229.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-15 13:48:12",
            "last_seen_utc": "2026-07-20 14:46:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1812283": [
        {
            "ioc_value": "95.141.133.7:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-14 19:47:27",
            "last_seen_utc": "2026-07-21 17:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1812280": [
        {
            "ioc_value": "104.243.248.63:1806",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-14 19:43:12",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811874": [
        {
            "ioc_value": "8.218.224.15:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 12:36:52",
            "last_seen_utc": "2026-07-20 14:46:58",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1812073": [
        {
            "ioc_value": "87.120.107.68:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-14 12:34:22",
            "last_seen_utc": "2026-07-21 17:45:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1812137": [
        {
            "ioc_value": "207.56.226.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-14 12:33:41",
            "last_seen_utc": "2026-07-21 17:46:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1812126": [
        {
            "ioc_value": "84.46.251.62:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-14 09:51:34",
            "last_seen_utc": "2026-07-21 17:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811945": [
        {
            "ioc_value": "43.230.162.44:14321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-13 19:44:54",
            "last_seen_utc": "2026-07-21 17:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811775": [
        {
            "ioc_value": "43.139.170.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-13 10:45:56",
            "last_seen_utc": "2026-07-21 17:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811412": [
        {
            "ioc_value": "117.72.168.103:50011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 11:45:38",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811399": [
        {
            "ioc_value": "85.158.57.247:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-12 09:45:14",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811398": [
        {
            "ioc_value": "67.180.188.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-12 09:45:04",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811385": [
        {
            "ioc_value": "104.243.248.63:1803",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-12 09:43:06",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811187": [
        {
            "ioc_value": "mpd.pegasus-77.biz.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-07-21 17:22:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1811188": [
        {
            "ioc_value": "https://mpd.pegasus-77.biz.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-07-21 17:22:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1811186": [
        {
            "ioc_value": "117.50.184.221:10080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 22:45:16",
            "last_seen_utc": "2026-07-21 17:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811129": [
        {
            "ioc_value": "64.199.252.59:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 19:45:07",
            "last_seen_utc": "2026-07-21 17:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811128": [
        {
            "ioc_value": "51.77.54.76:6769",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:45:01",
            "last_seen_utc": "2026-07-21 17:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811126": [
        {
            "ioc_value": "45.77.89.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:44:49",
            "last_seen_utc": "2026-07-21 17:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811123": [
        {
            "ioc_value": "185.190.142.66:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:43:38",
            "last_seen_utc": "2026-07-21 17:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811118": [
        {
            "ioc_value": "109.73.193.242:10140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:43:08",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810965": [
        {
            "ioc_value": "89.42.134.220:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:45:15",
            "last_seen_utc": "2026-07-21 17:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810958": [
        {
            "ioc_value": "20.114.142.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-11 09:43:46",
            "last_seen_utc": "2026-07-21 17:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810956": [
        {
            "ioc_value": "193.169.194.19:8264",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-11 09:43:41",
            "last_seen_utc": "2026-07-21 17:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810955": [
        {
            "ioc_value": "185.242.245.27:44875",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 09:43:35",
            "last_seen_utc": "2026-07-21 17:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810952": [
        {
            "ioc_value": "172.239.57.52:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 09:43:26",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810953": [
        {
            "ioc_value": "172.245.97.237:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 09:43:26",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810950": [
        {
            "ioc_value": "158.94.210.70:22532",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:43:20",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810418": [
        {
            "ioc_value": "64.23.231.32:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-10 19:44:55",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810414": [
        {
            "ioc_value": "31.57.184.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-10 19:44:31",
            "last_seen_utc": "2026-07-21 17:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810410": [
        {
            "ioc_value": "195.123.240.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-10 19:43:45",
            "last_seen_utc": "2026-07-21 17:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810411": [
        {
            "ioc_value": "195.123.240.236:8274",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-10 19:43:45",
            "last_seen_utc": "2026-07-21 17:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810408": [
        {
            "ioc_value": "189.34.188.6:5406",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810409": [
        {
            "ioc_value": "189.34.188.6:5407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-07-21 17:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809984": [
        {
            "ioc_value": "1.92.101.103:8099",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-10 18:42:09",
            "last_seen_utc": "2026-07-21 17:46:04",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "55990,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1810170": [
        {
            "ioc_value": "57.158.27.132:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-10 09:44:56",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809754": [
        {
            "ioc_value": "213.130.25.141:44333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-09 19:43:46",
            "last_seen_utc": "2026-07-21 17:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809750": [
        {
            "ioc_value": "168.144.89.48:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-09 19:43:24",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809219": [
        {
            "ioc_value": "139.196.50.117:9930",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 23:44:52",
            "last_seen_utc": "2026-07-21 17:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809039": [
        {
            "ioc_value": "209.38.100.109:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 19:43:41",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809038": [
        {
            "ioc_value": "193.42.24.165:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 19:43:36",
            "last_seen_utc": "2026-07-21 17:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809035": [
        {
            "ioc_value": "185.212.128.24:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 19:43:29",
            "last_seen_utc": "2026-07-21 17:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809033": [
        {
            "ioc_value": "180.97.214.70:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-08 19:43:28",
            "last_seen_utc": "2026-07-21 17:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809029": [
        {
            "ioc_value": "160.25.82.142:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:19",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808742": [
        {
            "ioc_value": "47.83.254.175:1102",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-08 10:44:29",
            "last_seen_utc": "2026-07-21 17:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808653": [
        {
            "ioc_value": "5.101.81.23:4315",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:47",
            "last_seen_utc": "2026-07-21 17:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808650": [
        {
            "ioc_value": "45.56.91.55:2005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:45",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808648": [
        {
            "ioc_value": "31.57.216.62:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:42",
            "last_seen_utc": "2026-07-21 17:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808643": [
        {
            "ioc_value": "209.38.110.161:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:21",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808639": [
        {
            "ioc_value": "185.212.129.114:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-08 08:43:15",
            "last_seen_utc": "2026-07-20 08:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808637": [
        {
            "ioc_value": "178.104.186.90:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 08:43:13",
            "last_seen_utc": "2026-07-21 17:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808628": [
        {
            "ioc_value": "113.31.118.180:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:05",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808623": [
        {
            "ioc_value": "104.243.248.63:1802",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-08 08:43:04",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808286": [
        {
            "ioc_value": "101.33.225.32:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-07 20:44:32",
            "last_seen_utc": "2026-07-21 17:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808142": [
        {
            "ioc_value": "83.147.38.94:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-07 10:44:18",
            "last_seen_utc": "2026-07-21 17:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807868": [
        {
            "ioc_value": "27.102.137.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 20:53:22",
            "last_seen_utc": "2026-07-21 17:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Remcos,RemcosRAT,Remvio,Socmer",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1807906": [
        {
            "ioc_value": "45.207.192.190:30078",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:39",
            "last_seen_utc": "2026-07-21 17:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807905": [
        {
            "ioc_value": "207.56.226.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:29",
            "last_seen_utc": "2026-07-21 17:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807904": [
        {
            "ioc_value": "117.72.168.103:16337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:09",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807845": [
        {
            "ioc_value": "31.57.216.62:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 18:43:51",
            "last_seen_utc": "2026-07-21 17:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807842": [
        {
            "ioc_value": "154.18.238.18:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-06 18:43:14",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807538": [
        {
            "ioc_value": "31.57.184.154:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-06 08:43:54",
            "last_seen_utc": "2026-07-21 17:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806953": [
        {
            "ioc_value": "5.101.82.99:6031",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-05 10:47:42",
            "last_seen_utc": "2026-07-21 17:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806901": [
        {
            "ioc_value": "172.245.156.179:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-05 08:44:56",
            "last_seen_utc": "2026-07-21 17:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806229": [
        {
            "ioc_value": "8.130.80.145:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:45:07",
            "last_seen_utc": "2026-07-21 17:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806228": [
        {
            "ioc_value": "154.219.115.123:61443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:43",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806227": [
        {
            "ioc_value": "119.29.198.193:8555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:36",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805766": [
        {
            "ioc_value": "82.165.79.60:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:13",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805765": [
        {
            "ioc_value": "82.165.79.60:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:12",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805757": [
        {
            "ioc_value": "163.181.45.55:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-04 08:43:16",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805268": [
        {
            "ioc_value": "151.245.90.45:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:29",
            "last_seen_utc": "2026-07-21 17:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805267": [
        {
            "ioc_value": "ap.johamp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:08",
            "last_seen_utc": "2026-07-21 17:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804968": [
        {
            "ioc_value": "203.160.54.22:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:31",
            "last_seen_utc": "2026-07-21 17:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804965": [
        {
            "ioc_value": "h67as5d5x.m6p3wca1.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:06",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804853": [
        {
            "ioc_value": "47.101.172.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 14:44:30",
            "last_seen_utc": "2026-07-21 17:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804732": [
        {
            "ioc_value": "8.160.216.91:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:53",
            "last_seen_utc": "2026-07-21 17:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804719": [
        {
            "ioc_value": "124.95.172.200:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:06",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804617": [
        {
            "ioc_value": "weddingcarsshropshire.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:31",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804603": [
        {
            "ioc_value": "uwdierenarts.nl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:30",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804604": [
        {
            "ioc_value": "vecte-algerie.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:30",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804547": [
        {
            "ioc_value": "stmichaelslegione.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:24",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804537": [
        {
            "ioc_value": "smartkidsmada.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:23",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804526": [
        {
            "ioc_value": "sergemoulypeintre.fr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:22",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804453": [
        {
            "ioc_value": "omnicoresolutions.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:16",
            "last_seen_utc": "2026-07-19 18:50:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804414": [
        {
            "ioc_value": "mietservice-minibagger.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:12",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804371": [
        {
            "ioc_value": "kairoschristianresourcecenter.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:09",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804346": [
        {
            "ioc_value": "ilisdesigns.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:06",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804332": [
        {
            "ioc_value": "healgram.gr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:05",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804318": [
        {
            "ioc_value": "go.for-it.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:04",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804294": [
        {
            "ioc_value": "evangelhodiario.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:32:00",
            "last_seen_utc": "2026-07-19 18:50:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804281": [
        {
            "ioc_value": "entwined.co.ke",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:59",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804255": [
        {
            "ioc_value": "dawgonllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:57",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804259": [
        {
            "ioc_value": "deltorres.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:57",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804244": [
        {
            "ioc_value": "collectivefab.agency",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:56",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804249": [
        {
            "ioc_value": "costa-blanca-apartment.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:56",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804251": [
        {
            "ioc_value": "cualixrealestate.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:56",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804235": [
        {
            "ioc_value": "clearlinewebdesign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:55",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1804158": [
        {
            "ioc_value": "adriahousedubrovnik.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-05-02 06:31:47",
            "last_seen_utc": "2026-07-19 18:50:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,compromised,etherhiding,Polygon,Vidar",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1803956": [
        {
            "ioc_value": "https://arsimonopa.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-05-02 05:24:17",
            "last_seen_utc": "2026-07-21 17:35:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1803960": [
        {
            "ioc_value": "https://lemonimonakio.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-05-02 05:24:15",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1803896": [
        {
            "ioc_value": "89.114.115.200:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 18:43:58",
            "last_seen_utc": "2026-07-21 17:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803894": [
        {
            "ioc_value": "59.152.212.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 18:43:53",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803887": [
        {
            "ioc_value": "5.101.82.190:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 18:43:50",
            "last_seen_utc": "2026-07-21 17:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803881": [
        {
            "ioc_value": "45.10.164.177:45123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 18:43:45",
            "last_seen_utc": "2026-07-21 17:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803874": [
        {
            "ioc_value": "31.57.184.154:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 18:43:41",
            "last_seen_utc": "2026-07-21 17:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803866": [
        {
            "ioc_value": "195.88.191.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-01 18:43:24",
            "last_seen_utc": "2026-07-21 17:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803867": [
        {
            "ioc_value": "195.88.191.41:7666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-01 18:43:24",
            "last_seen_utc": "2026-07-21 17:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803858": [
        {
            "ioc_value": "185.212.128.80:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 18:43:19",
            "last_seen_utc": "2026-07-21 17:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803859": [
        {
            "ioc_value": "185.212.128.85:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 18:43:19",
            "last_seen_utc": "2026-07-21 17:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803841": [
        {
            "ioc_value": "103.79.79.105:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-01 18:43:03",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803693": [
        {
            "ioc_value": "8.222.192.153:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:50",
            "last_seen_utc": "2026-07-21 17:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803689": [
        {
            "ioc_value": "47.236.91.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:44",
            "last_seen_utc": "2026-07-21 17:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803670": [
        {
            "ioc_value": "frr.ambil-disini.web.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-07-21 17:22:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1803671": [
        {
            "ioc_value": "https://frr.ambil-disini.web.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-07-21 17:22:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1803514": [
        {
            "ioc_value": "72.56.246.58:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 08:43:49",
            "last_seen_utc": "2026-07-21 17:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803512": [
        {
            "ioc_value": "62.60.226.63:6856",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:48",
            "last_seen_utc": "2026-07-21 17:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803513": [
        {
            "ioc_value": "64.89.163.114:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 08:43:48",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803507": [
        {
            "ioc_value": "5.101.86.60:6798",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-01 08:43:46",
            "last_seen_utc": "2026-07-21 17:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803500": [
        {
            "ioc_value": "47.103.106.26:2333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:44",
            "last_seen_utc": "2026-07-21 17:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803493": [
        {
            "ioc_value": "4.236.165.30:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:40",
            "last_seen_utc": "2026-07-21 17:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803473": [
        {
            "ioc_value": "178.128.252.142:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 08:43:16",
            "last_seen_utc": "2026-07-21 17:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803448": [
        {
            "ioc_value": "111.229.144.163:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 08:43:05",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803387": [
        {
            "ioc_value": "203.160.54.22:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 07:08:49",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803286": [
        {
            "ioc_value": "94.176.3.228:48765",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:32",
            "last_seen_utc": "2026-07-21 17:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803291": [
        {
            "ioc_value": "98.97.125.70:8883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:32",
            "last_seen_utc": "2026-07-21 17:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803279": [
        {
            "ioc_value": "91.202.233.153:43555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-07-21 17:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803280": [
        {
            "ioc_value": "91.215.85.151:47653",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-07-21 17:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803275": [
        {
            "ioc_value": "85.121.5.202:5689",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:30",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803276": [
        {
            "ioc_value": "85.155.186.2:3821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:30",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803262": [
        {
            "ioc_value": "79.135.160.20:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:28",
            "last_seen_utc": "2026-07-21 17:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803257": [
        {
            "ioc_value": "66.163.115.78:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803260": [
        {
            "ioc_value": "72.56.246.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-07-21 17:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803261": [
        {
            "ioc_value": "72.56.246.58:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-07-21 17:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803254": [
        {
            "ioc_value": "62.81.188.1:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-07-21 17:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803255": [
        {
            "ioc_value": "66.163.115.78:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803256": [
        {
            "ioc_value": "66.163.115.78:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803246": [
        {
            "ioc_value": "46.101.77.223:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:25",
            "last_seen_utc": "2026-07-21 17:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803239": [
        {
            "ioc_value": "45.155.69.175:42455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-07-21 17:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803240": [
        {
            "ioc_value": "45.56.91.55:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803244": [
        {
            "ioc_value": "45.81.243.52:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-07-21 17:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803235": [
        {
            "ioc_value": "45.125.67.171:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-07-21 17:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803238": [
        {
            "ioc_value": "45.155.69.106:42211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-07-21 17:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803231": [
        {
            "ioc_value": "43.134.133.177:8445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-07-21 17:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803232": [
        {
            "ioc_value": "43.142.77.170:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-07-21 17:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803233": [
        {
            "ioc_value": "43.142.77.170:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-07-21 17:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803234": [
        {
            "ioc_value": "43.160.225.40:39001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-07-21 17:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803218": [
        {
            "ioc_value": "222.255.100.119:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-07-21 17:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803219": [
        {
            "ioc_value": "23.227.203.6:42235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-07-21 17:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803222": [
        {
            "ioc_value": "31.57.184.154:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-07-21 17:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803211": [
        {
            "ioc_value": "216.107.208.250:10444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-07-21 17:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803215": [
        {
            "ioc_value": "219.142.15.101:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-07-21 17:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803216": [
        {
            "ioc_value": "220.231.47.163:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-07-21 17:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803217": [
        {
            "ioc_value": "221.130.42.19:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-07-21 17:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803205": [
        {
            "ioc_value": "208.249.244.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803206": [
        {
            "ioc_value": "209.151.145.164:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803202": [
        {
            "ioc_value": "202.95.17.188:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-07-21 17:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803203": [
        {
            "ioc_value": "206.189.40.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-07-21 17:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803180": [
        {
            "ioc_value": "185.242.3.83:9909",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:14",
            "last_seen_utc": "2026-07-21 17:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803181": [
        {
            "ioc_value": "185.247.224.40:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:14",
            "last_seen_utc": "2026-07-21 17:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803173": [
        {
            "ioc_value": "185.212.128.81:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-07-21 17:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803174": [
        {
            "ioc_value": "185.212.129.23:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-07-21 17:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803176": [
        {
            "ioc_value": "185.212.129.29:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-07-21 17:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803177": [
        {
            "ioc_value": "185.212.129.30:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-07-21 17:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803178": [
        {
            "ioc_value": "185.213.20.250:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-07-21 17:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803179": [
        {
            "ioc_value": "185.242.245.120:42534",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-07-21 17:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803166": [
        {
            "ioc_value": "180.184.29.135:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-07-21 17:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803167": [
        {
            "ioc_value": "182.255.45.114:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-07-21 17:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803172": [
        {
            "ioc_value": "185.212.128.48:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-07-21 17:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803162": [
        {
            "ioc_value": "178.16.52.22:8396",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:11",
            "last_seen_utc": "2026-07-21 17:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803152": [
        {
            "ioc_value": "172.111.162.252:3030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803153": [
        {
            "ioc_value": "172.9.165.216:8096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803141": [
        {
            "ioc_value": "154.219.115.123:60001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803146": [
        {
            "ioc_value": "161.248.179.92:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803147": [
        {
            "ioc_value": "162.14.124.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803134": [
        {
            "ioc_value": "149.104.28.204:3656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:07",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803127": [
        {
            "ioc_value": "142.93.88.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:06",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803124": [
        {
            "ioc_value": "138.124.113.131:4211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:05",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803114": [
        {
            "ioc_value": "115.42.60.122:5440",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803115": [
        {
            "ioc_value": "117.72.101.55:9520",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803119": [
        {
            "ioc_value": "130.94.23.39:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803109": [
        {
            "ioc_value": "103.75.190.47:54630",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803110": [
        {
            "ioc_value": "104.234.174.93:57712",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803111": [
        {
            "ioc_value": "106.55.71.62:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803113": [
        {
            "ioc_value": "115.190.247.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1802897": [
        {
            "ioc_value": "82.156.219.31:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:45",
            "last_seen_utc": "2026-07-21 17:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1802894": [
        {
            "ioc_value": "193.53.127.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:30",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1802892": [
        {
            "ioc_value": "www.microsslcheck.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:10",
            "last_seen_utc": "2026-07-21 17:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800975": [
        {
            "ioc_value": "45.43.59.179:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 11:02:18",
            "last_seen_utc": "2026-07-21 17:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800972": [
        {
            "ioc_value": "ns1.twnic.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 10:46:10",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800970": [
        {
            "ioc_value": "cc.twnic.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-27 10:43:32",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800528": [
        {
            "ioc_value": "http://pillow.riverbridge.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 19:14:08",
            "last_seen_utc": "2026-07-21 17:21:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ipocalur,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800509": [
        {
            "ioc_value": "pillow.riverbridge.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 18:19:19",
            "last_seen_utc": "2026-07-21 17:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2199baf11d50dd10555f8aec122178e03b62570fc0d4614a8e928978dc547154/",
            "tags": "ipocalur,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800411": [
        {
            "ioc_value": "http://91.92.242.236/oPvjr94jfe/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-26 18:11:00",
            "last_seen_utc": "2026-07-21 17:47:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "54e64e,amadey,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1797248": [
        {
            "ioc_value": "psy.flise-mesteren.dk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:06",
            "last_seen_utc": "2026-07-21 17:21:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1797247": [
        {
            "ioc_value": "https://psy.flise-mesteren.dk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:01",
            "last_seen_utc": "2026-07-21 17:21:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796426": [
        {
            "ioc_value": "http://196.251.107.248/kont2rt/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-23 04:45:34",
            "last_seen_utc": "2026-07-21 17:49:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amadey",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796313": [
        {
            "ioc_value": "192.210.174.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 20:53:22",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796097": [
        {
            "ioc_value": "47.94.162.43:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 14:30:19",
            "last_seen_utc": "2026-07-21 17:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1796068": [
        {
            "ioc_value": "wrath.bottlevacuum.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:13",
            "last_seen_utc": "2026-07-21 17:21:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796067": [
        {
            "ioc_value": "http://wrath.bottlevacuum.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:09",
            "last_seen_utc": "2026-07-21 17:21:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1794638": [
        {
            "ioc_value": "http://213.5.130.87",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-19 18:25:29",
            "last_seen_utc": "2026-07-21 06:02:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1793918": [
        {
            "ioc_value": "121.4.92.72:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-18 02:46:54",
            "last_seen_utc": "2026-07-21 17:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1793645": [
        {
            "ioc_value": "http://213.5.130.147",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-17 18:15:06",
            "last_seen_utc": "2026-07-21 06:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1793617": [
        {
            "ioc_value": "ask.shurimaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:27",
            "last_seen_utc": "2026-07-21 17:20:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1793616": [
        {
            "ioc_value": "https://ask.shurimaster.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:25",
            "last_seen_utc": "2026-07-21 17:20:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792850": [
        {
            "ioc_value": "pir.rapidphonebuyer.co.uk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 16:13:58",
            "last_seen_utc": "2026-07-21 17:18:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "d0b0p,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792849": [
        {
            "ioc_value": "https://pir.rapidphonebuyer.co.uk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 16:13:56",
            "last_seen_utc": "2026-07-21 17:18:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "d0b0p,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792719": [
        {
            "ioc_value": "gusto.brothbridge.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:20",
            "last_seen_utc": "2026-07-21 17:21:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792718": [
        {
            "ioc_value": "http://gusto.brothbridge.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:17",
            "last_seen_utc": "2026-07-21 17:21:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792707": [
        {
            "ioc_value": "43.167.177.224:7778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 10:56:58",
            "last_seen_utc": "2026-07-21 17:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792532": [
        {
            "ioc_value": "bxx2rghe05kng.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 02:43:39",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791747": [
        {
            "ioc_value": "http://107.189.24.190:80",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 11:43:19",
            "last_seen_utc": "2026-07-21 17:15:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gr00n1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791738": [
        {
            "ioc_value": "139.224.23.63:8866",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-15 11:39:45",
            "last_seen_utc": "2026-07-21 17:46:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1791688": [
        {
            "ioc_value": "venom.summertunnel.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:17",
            "last_seen_utc": "2026-07-21 17:21:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791687": [
        {
            "ioc_value": "http://venom.summertunnel.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:13",
            "last_seen_utc": "2026-07-21 17:21:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790859": [
        {
            "ioc_value": "lts.cloudvaly.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 16:03:14",
            "last_seen_utc": "2026-07-21 17:13:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ho0r1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790857": [
        {
            "ioc_value": "https://lts.cloudvaly.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 16:03:10",
            "last_seen_utc": "2026-07-21 17:13:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ho0r1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790171": [
        {
            "ioc_value": "dzodu.sparklingideas.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:11:23",
            "last_seen_utc": "2026-07-21 17:20:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odzdkzo,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790170": [
        {
            "ioc_value": "http://dzodu.sparklingideas.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:11:18",
            "last_seen_utc": "2026-07-21 17:20:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odzdkzo,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790169": [
        {
            "ioc_value": "http://kdije.weirdthings.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:10:11",
            "last_seen_utc": "2026-07-21 17:17:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "okfueh,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1787027": [
        {
            "ioc_value": "https://cannabis-dna.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 11:32:51",
            "last_seen_utc": "2026-07-21 17:15:02",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,EtherHiding,Polygon,Vidar,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1785513": [
        {
            "ioc_value": "46.151.182.19:416",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-04-14 05:40:17",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1785064": [
        {
            "ioc_value": "pre.hifive.net.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:47:21",
            "last_seen_utc": "2026-07-21 17:20:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1785049": [
        {
            "ioc_value": "https://pre.hifive.net.au/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:46:34",
            "last_seen_utc": "2026-07-21 17:20:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1784558": [
        {
            "ioc_value": "47.104.248.7:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-12 06:34:43",
            "last_seen_utc": "2026-07-21 17:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1783375": [
        {
            "ioc_value": "39.102.125.11:4435",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-09 14:48:47",
            "last_seen_utc": "2026-07-21 17:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1782524": [
        {
            "ioc_value": "82.165.179.9:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-04-07 23:06:40",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/4c3b97c157d08ee298edb5d30fa86a3b90b04fedfbe517e7e0307b6013eacbf0/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1782522": [
        {
            "ioc_value": "82.165.179.9:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-04-07 23:00:12",
            "last_seen_utc": "2026-07-21 17:45:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1782182": [
        {
            "ioc_value": "dzdi.serendipityhub.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:46:05",
            "last_seen_utc": "2026-07-21 17:19:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1782152": [
        {
            "ioc_value": "http://dzdi.serendipityhub.space/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:43:55",
            "last_seen_utc": "2026-07-21 17:19:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1781907": [
        {
            "ioc_value": "43.139.108.161:8192",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-06 18:49:49",
            "last_seen_utc": "2026-07-21 17:46:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1781225": [
        {
            "ioc_value": "111.230.217.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:05",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1781224": [
        {
            "ioc_value": "109.244.130.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:01",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1781055": [
        {
            "ioc_value": "46.151.182.19:430",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-04-04 12:57:33",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1780720": [
        {
            "ioc_value": "hor.kaitorinihon.jp",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-03 16:13:22",
            "last_seen_utc": "2026-07-21 17:18:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1780716": [
        {
            "ioc_value": "https://hor.kaitorinihon.jp/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-03 16:12:59",
            "last_seen_utc": "2026-07-21 17:18:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1779913": [
        {
            "ioc_value": "31.57.216.28:424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-04-01 05:40:31",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1779916": [
        {
            "ioc_value": "31.57.216.27:424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-04-01 05:40:31",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1779917": [
        {
            "ioc_value": "46.151.182.19:424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-04-01 05:40:31",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1779911": [
        {
            "ioc_value": "130.12.182.175:424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-04-01 05:40:30",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1777986": [
        {
            "ioc_value": "47.122.47.221:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-28 14:56:18",
            "last_seen_utc": "2026-07-21 17:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1777607": [
        {
            "ioc_value": "pn2.skfilmsint.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-07-21 17:17:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777609": [
        {
            "ioc_value": "gre.syslicense.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-07-21 17:17:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777611": [
        {
            "ioc_value": "fefeo.iknowthat.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-07-21 17:18:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777601": [
        {
            "ioc_value": "https://pn2.skfilmsint.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-07-21 17:17:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777603": [
        {
            "ioc_value": "https://gre.syslicense.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-07-21 17:17:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777605": [
        {
            "ioc_value": "http://fefeo.iknowthat.space/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-07-21 17:18:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777296": [
        {
            "ioc_value": "185.242.3.83:2202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-27 12:01:30",
            "last_seen_utc": "2026-07-21 17:44:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.242.3.83",
            "tags": "AS60223,AsyncRAT,C2,censys,NETIFACE-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1777014": [
        {
            "ioc_value": "49.234.199.152:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-27 00:00:31",
            "last_seen_utc": "2026-07-21 17:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/49.234.199.152",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1776672": [
        {
            "ioc_value": "158.94.209.95:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-03-26 14:59:36",
            "last_seen_utc": "2026-07-21 17:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "GCleaner,loader",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1776603": [
        {
            "ioc_value": "130.12.182.175:427",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-26 07:25:17",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1776605": [
        {
            "ioc_value": "31.57.216.27:427",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-26 07:25:17",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1776606": [
        {
            "ioc_value": "31.57.216.28:427",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-26 07:25:17",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1776607": [
        {
            "ioc_value": "46.151.182.19:427",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-26 07:25:17",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1774903": [
        {
            "ioc_value": "37.72.172.58:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-24 12:01:13",
            "last_seen_utc": "2026-07-21 17:45:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1774898": [
        {
            "ioc_value": "47.92.208.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-24 12:00:35",
            "last_seen_utc": "2026-07-21 17:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.92.208.27",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1774595": [
        {
            "ioc_value": "154.83.12.132:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-23 21:06:09",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1774355": [
        {
            "ioc_value": "kdije.weirdthings.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 13:42:00",
            "last_seen_utc": "2026-07-21 17:17:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1774216": [
        {
            "ioc_value": "msi.swadeshcomputer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 08:02:27",
            "last_seen_utc": "2026-07-21 17:16:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1774200": [
        {
            "ioc_value": "https://msi.swadeshcomputer.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 08:01:55",
            "last_seen_utc": "2026-07-21 17:16:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1774131": [
        {
            "ioc_value": "46.151.182.19:421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-23 06:53:11",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1774089": [
        {
            "ioc_value": "195.250.25.176:58101",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-23 04:01:29",
            "last_seen_utc": "2026-07-21 17:44:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.250.25.176",
            "tags": "AdaptixC2,AS36454,C2,censys,WHG-DAL",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1773536": [
        {
            "ioc_value": "156.239.252.191:448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-22 18:02:20",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BEACON,C2,CobaltStrike,Shodan",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1773754": [
        {
            "ioc_value": "138.226.236.52:13212",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-22 12:01:29",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/138.226.236.52",
            "tags": "AdaptixC2,AS205775,C2,censys,NEONCORENETWORKS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1772372": [
        {
            "ioc_value": "pr2.codetohaven.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-20 13:59:59",
            "last_seen_utc": "2026-07-21 17:16:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1772370": [
        {
            "ioc_value": "https://pr2.codetohaven.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-20 13:59:49",
            "last_seen_utc": "2026-07-21 17:16:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1771875": [
        {
            "ioc_value": "182.255.44.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 06:42:00",
            "last_seen_utc": "2026-07-21 17:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771846": [
        {
            "ioc_value": "51.222.87.16:433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 04:19:09",
            "last_seen_utc": "2026-07-21 17:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771843": [
        {
            "ioc_value": "cdn.sys-update.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 04:08:17",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771791": [
        {
            "ioc_value": "8.136.13.87:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-20 00:02:12",
            "last_seen_utc": "2026-07-21 17:45:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.136.13.87",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1771714": [
        {
            "ioc_value": "45.136.13.247:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-19 20:02:51",
            "last_seen_utc": "2026-07-21 17:45:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.136.13.247",
            "tags": "AdaptixC2,AS139659,C2,censys,LUCID-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1771456": [
        {
            "ioc_value": "dhzuadd.hellothere.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-19 13:11:25",
            "last_seen_utc": "2026-07-21 17:17:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drkfiz,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771455": [
        {
            "ioc_value": "https://dhzuadd.hellothere.sbs",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-19 13:11:20",
            "last_seen_utc": "2026-07-21 17:17:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drkfiz,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771235": [
        {
            "ioc_value": "85.206.168.238:888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-19 04:00:37",
            "last_seen_utc": "2026-07-21 17:45:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/85.206.168.238",
            "tags": "AS61272,C2,censys,IST-AS,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1770623": [
        {
            "ioc_value": "46.151.182.19:425",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-18 08:54:43",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1769955": [
        {
            "ioc_value": "43.138.39.212:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-18 04:00:18",
            "last_seen_utc": "2026-07-21 17:46:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.138.39.212",
            "tags": "AS45090,C2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1769297": [
        {
            "ioc_value": "43.155.169.245:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-17 13:16:11",
            "last_seen_utc": "2026-07-21 08:05:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1769012": [
        {
            "ioc_value": "88.218.60.191:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-17 04:01:23",
            "last_seen_utc": "2026-07-21 17:45:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/88.218.60.191",
            "tags": "AdaptixC2,AS48282,C2,censys,VDSINA-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1768984": [
        {
            "ioc_value": "156.245.144.203:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-17 02:48:23",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1768644": [
        {
            "ioc_value": "35.179.229.71:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-03-16 20:01:10",
            "last_seen_utc": "2026-07-21 17:45:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/35.179.229.71",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1767990": [
        {
            "ioc_value": "43.155.169.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-16 12:00:11",
            "last_seen_utc": "2026-07-21 06:05:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.155.169.245",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1767015": [
        {
            "ioc_value": "156.245.144.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-15 14:49:59",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1767016": [
        {
            "ioc_value": "156.245.144.203:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-15 14:49:59",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1766764": [
        {
            "ioc_value": "202.191.67.71:50003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-15 04:01:14",
            "last_seen_utc": "2026-07-21 17:44:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/202.191.67.71",
            "tags": "AdaptixC2,AS131262,C2,censys,KELNET-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1765797": [
        {
            "ioc_value": "31.57.216.28:421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-14 08:24:37",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1765798": [
        {
            "ioc_value": "130.12.182.175:421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-14 08:24:37",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1765803": [
        {
            "ioc_value": "31.57.216.27:421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-14 08:24:37",
            "last_seen_utc": "2026-07-21 05:35:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1765792": [
        {
            "ioc_value": "39.103.91.52:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-14 08:06:08",
            "last_seen_utc": "2026-07-21 17:46:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1765787": [
        {
            "ioc_value": "5.101.82.60:2509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-14 08:00:55",
            "last_seen_utc": "2026-07-21 17:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.60",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1765444": [
        {
            "ioc_value": "pan.paihost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-13 15:06:16",
            "last_seen_utc": "2026-07-21 17:15:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1765442": [
        {
            "ioc_value": "https://pan.paihost.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-13 15:05:58",
            "last_seen_utc": "2026-07-21 17:15:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1764276": [
        {
            "ioc_value": "46.151.182.205:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-13 04:01:11",
            "last_seen_utc": "2026-07-21 17:45:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.151.182.205",
            "tags": "AS205759,AsyncRAT,C2,censys,GHOSTYNETWORKS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1763543": [
        {
            "ioc_value": "159.138.31.252:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-11 16:01:48",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/159.138.31.252",
            "tags": "AS136907,C2,censys,HWCLOUDS-AS-AP,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1763170": [
        {
            "ioc_value": "60.247.206.23:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-11 07:03:38",
            "last_seen_utc": "2026-07-21 17:46:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1762854": [
        {
            "ioc_value": "85.206.168.238:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-10 16:00:58",
            "last_seen_utc": "2026-07-21 17:45:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/85.206.168.238",
            "tags": "AS61272,C2,censys,IST-AS,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1762492": [
        {
            "ioc_value": "107.172.3.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-10 00:01:13",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.3.15",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1762251": [
        {
            "ioc_value": "130.12.182.175:416",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-09 12:52:15",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1762247": [
        {
            "ioc_value": "31.57.216.28:416",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-09 12:52:14",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1762248": [
        {
            "ioc_value": "31.57.216.27:416",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-09 12:52:14",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1762153": [
        {
            "ioc_value": "ooe.myserver.com.bd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-09 09:29:37",
            "last_seen_utc": "2026-07-21 17:15:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1762131": [
        {
            "ioc_value": "https://ooe.myserver.com.bd/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-09 09:29:17",
            "last_seen_utc": "2026-07-21 17:15:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1761283": [
        {
            "ioc_value": "31.57.216.28:430",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-08 06:45:42",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1761285": [
        {
            "ioc_value": "31.57.216.27:430",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-08 06:45:42",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1761286": [
        {
            "ioc_value": "130.12.182.175:430",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-08 06:45:42",
            "last_seen_utc": "2026-07-21 05:35:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1761034": [
        {
            "ioc_value": "130.12.182.175:425",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-07 17:02:14",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1761032": [
        {
            "ioc_value": "31.57.216.28:425",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-07 17:02:13",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1761033": [
        {
            "ioc_value": "31.57.216.27:425",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2026-03-07 17:02:13",
            "last_seen_utc": "2026-07-21 05:35:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Tofsee",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1760216": [
        {
            "ioc_value": "51.222.87.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-06 08:00:30",
            "last_seen_utc": "2026-07-20 09:14:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.222.87.16",
            "tags": "AS16276,C2,censys,CobaltStrike,cs-watermark-426352781,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1758456": [
        {
            "ioc_value": "http://213.5.130.197",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:58",
            "last_seen_utc": "2026-07-21 06:02:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758457": [
        {
            "ioc_value": "http://213.5.130.154",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:57",
            "last_seen_utc": "2026-07-21 06:02:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758458": [
        {
            "ioc_value": "http://213.5.130.200",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:56",
            "last_seen_utc": "2026-07-21 06:02:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758459": [
        {
            "ioc_value": "http://213.5.130.131",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:55",
            "last_seen_utc": "2026-07-21 06:02:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758460": [
        {
            "ioc_value": "http://213.5.130.179",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-07-21 06:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758461": [
        {
            "ioc_value": "http://213.5.130.189",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-07-21 06:02:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758006": [
        {
            "ioc_value": "70.153.18.45:10002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-04 04:01:12",
            "last_seen_utc": "2026-07-21 17:45:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/70.153.18.45",
            "tags": "AS8075,censys,EvilGoPhish,MICROSOFT-CORP-MSN-AS-BLOCK,panel,Phishing",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1757586": [
        {
            "ioc_value": "texashydrowork.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-03 17:25:17",
            "last_seen_utc": "2026-07-20 18:45:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1756955": [
        {
            "ioc_value": "104.243.248.63:1801",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-02 15:30:09",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1756664": [
        {
            "ioc_value": "ctl.it-bd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-02 09:31:49",
            "last_seen_utc": "2026-07-21 17:15:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1756622": [
        {
            "ioc_value": "https://ctl.it-bd.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-02 09:30:33",
            "last_seen_utc": "2026-07-21 17:15:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1754671": [
        {
            "ioc_value": "115.190.250.28:5521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 19:01:08",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.250.28",
            "tags": "AS137718,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1754344": [
        {
            "ioc_value": "23.88.110.42:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-02-24 23:00:43",
            "last_seen_utc": "2026-07-21 17:45:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.88.110.42",
            "tags": "AS24940,C2,censys,HETZNER-AS",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1753925": [
        {
            "ioc_value": "113.45.185.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-24 04:01:15",
            "last_seen_utc": "2026-07-21 17:46:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.45.185.225",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-987654321,HWCSNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1753846": [
        {
            "ioc_value": "64.89.161.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-23 23:00:07",
            "last_seen_utc": "2026-07-21 17:46:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.89.161.183",
            "tags": "AS205759,C2,censys,GHOSTYNETWORKS",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1753479": [
        {
            "ioc_value": "glo.gadgetwalabd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-23 10:07:22",
            "last_seen_utc": "2026-07-21 17:14:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1753432": [
        {
            "ioc_value": "https://glo.gadgetwalabd.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-23 10:06:47",
            "last_seen_utc": "2026-07-21 17:14:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1752688": [
        {
            "ioc_value": "149.28.242.44:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-23 00:02:15",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.242.44",
            "tags": "AdaptixC2,AS-VULTR,AS20473,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1751483": [
        {
            "ioc_value": "45.116.104.104:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-21 08:01:40",
            "last_seen_utc": "2026-07-21 17:45:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.116.104.104",
            "tags": "AS215481,C2,censys,FLEXYNODE-AS,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1751453": [
        {
            "ioc_value": "47.104.159.246:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-21 03:00:07",
            "last_seen_utc": "2026-07-21 17:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.104.159.246",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1751104": [
        {
            "ioc_value": "107.172.217.220:12096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-20 11:00:06",
            "last_seen_utc": "2026-07-21 17:46:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.217.220",
            "tags": "AS36352,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1751083": [
        {
            "ioc_value": "185.180.198.3:2025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-20 08:47:26",
            "last_seen_utc": "2026-07-21 17:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1751084": [
        {
            "ioc_value": "185.180.198.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-20 08:47:26",
            "last_seen_utc": "2026-07-21 17:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1751080": [
        {
            "ioc_value": "163.181.208.79:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-02-20 08:46:17",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1749217": [
        {
            "ioc_value": "111.228.4.54:4455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-16 09:05:30",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/111.228.4.54#4455",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1748314": [
        {
            "ioc_value": "27.221.15.199:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-02-14 18:46:07",
            "last_seen_utc": "2026-07-21 17:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1748256": [
        {
            "ioc_value": "101.200.193.211:8086",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-14 15:11:17",
            "last_seen_utc": "2026-07-20 09:14:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1747540": [
        {
            "ioc_value": "gor.emiraride.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:35",
            "last_seen_utc": "2026-07-21 17:14:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1747538": [
        {
            "ioc_value": "https://gor.emiraride.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:02",
            "last_seen_utc": "2026-07-21 17:14:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1747121": [
        {
            "ioc_value": "117.72.191.140:8028",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-13 06:59:13",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.191.140#8028",
            "tags": "c2,cobaltstrike,cs-watermark-391144938,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1743719": [
        {
            "ioc_value": "opa.dokantrack.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-09 11:14:08",
            "last_seen_utc": "2026-07-21 17:13:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1743622": [
        {
            "ioc_value": "https://opa.dokantrack.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-09 11:13:23",
            "last_seen_utc": "2026-07-21 17:13:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1743594": [
        {
            "ioc_value": "15.204.14.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-09 11:00:33",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.14.143",
            "tags": "AS16276,C2,censys,OVH",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1743398": [
        {
            "ioc_value": "192.3.233.166:59850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 16:00:16",
            "last_seen_utc": "2026-07-21 17:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/192.3.233.166",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1743395": [
        {
            "ioc_value": "1.15.25.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:41",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743391": [
        {
            "ioc_value": "106.52.208.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-07-21 17:42:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743392": [
        {
            "ioc_value": "106.13.137.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-07-21 17:42:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743393": [
        {
            "ioc_value": "101.43.2.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-07-21 17:42:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743394": [
        {
            "ioc_value": "101.133.148.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-07-21 17:42:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743388": [
        {
            "ioc_value": "115.190.178.249:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-07-21 17:42:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743389": [
        {
            "ioc_value": "114.132.150.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-07-21 17:42:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743390": [
        {
            "ioc_value": "110.40.176.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-07-21 17:42:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743386": [
        {
            "ioc_value": "120.48.50.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-07-21 17:42:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743387": [
        {
            "ioc_value": "117.72.214.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-07-21 17:42:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743381": [
        {
            "ioc_value": "124.223.199.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-07-21 17:42:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743382": [
        {
            "ioc_value": "124.221.32.87:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-07-21 17:42:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743383": [
        {
            "ioc_value": "124.220.48.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-07-21 17:42:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743384": [
        {
            "ioc_value": "124.220.164.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-07-21 17:42:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743385": [
        {
            "ioc_value": "121.41.167.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-07-21 17:42:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743378": [
        {
            "ioc_value": "152.136.139.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-07-21 17:42:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743379": [
        {
            "ioc_value": "129.204.103.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-07-21 17:42:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743380": [
        {
            "ioc_value": "124.223.47.219:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-07-21 17:42:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743374": [
        {
            "ioc_value": "172.245.215.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-07-21 17:42:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743375": [
        {
            "ioc_value": "165.154.125.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-07-21 17:42:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743376": [
        {
            "ioc_value": "156.233.233.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-07-21 17:42:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743377": [
        {
            "ioc_value": "154.201.91.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-07-21 17:42:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743370": [
        {
            "ioc_value": "38.190.224.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-07-21 17:42:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743371": [
        {
            "ioc_value": "222.255.214.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-07-21 17:42:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743372": [
        {
            "ioc_value": "192.252.187.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-07-21 17:42:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743373": [
        {
            "ioc_value": "178.16.52.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-07-21 17:42:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743365": [
        {
            "ioc_value": "43.139.146.100:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-07-21 17:42:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743366": [
        {
            "ioc_value": "43.133.41.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-07-21 17:42:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743367": [
        {
            "ioc_value": "42.192.49.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-07-21 17:42:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743368": [
        {
            "ioc_value": "39.107.85.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-07-21 17:42:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743369": [
        {
            "ioc_value": "39.106.144.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-07-21 17:42:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743363": [
        {
            "ioc_value": "47.100.168.4:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-07-21 17:42:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743364": [
        {
            "ioc_value": "43.139.169.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-07-21 17:42:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743362": [
        {
            "ioc_value": "47.111.146.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:30",
            "last_seen_utc": "2026-07-21 17:42:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743358": [
        {
            "ioc_value": "47.243.175.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-07-21 17:42:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743359": [
        {
            "ioc_value": "47.239.188.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-07-21 17:42:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743360": [
        {
            "ioc_value": "47.122.30.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-07-21 17:42:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743361": [
        {
            "ioc_value": "47.122.1.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-07-21 17:42:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743356": [
        {
            "ioc_value": "61.166.154.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-07-21 17:42:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743357": [
        {
            "ioc_value": "49.235.177.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-07-21 17:42:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743353": [
        {
            "ioc_value": "81.70.255.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-07-21 17:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743354": [
        {
            "ioc_value": "81.69.98.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-07-21 17:42:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743355": [
        {
            "ioc_value": "8.210.78.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-07-21 17:42:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743351": [
        {
            "ioc_value": "83.229.126.65:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-07-21 17:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743352": [
        {
            "ioc_value": "81.71.159.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-07-21 17:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743349": [
        {
            "ioc_value": "83.229.123.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-07-21 17:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743350": [
        {
            "ioc_value": "83.229.126.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-07-21 17:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743348": [
        {
            "ioc_value": "8.153.205.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:14",
            "last_seen_utc": "2026-07-21 17:42:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743347": [
        {
            "ioc_value": "8.137.149.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:13",
            "last_seen_utc": "2026-07-21 17:42:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743344": [
        {
            "ioc_value": "47.93.28.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-07-21 17:42:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743345": [
        {
            "ioc_value": "60.205.139.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-07-21 17:42:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743346": [
        {
            "ioc_value": "lcowpowerlite.italynorth.cloudapp.azure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-07-21 17:42:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743340": [
        {
            "ioc_value": "47.109.198.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-07-21 17:42:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743341": [
        {
            "ioc_value": "47.120.70.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-07-21 17:42:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743342": [
        {
            "ioc_value": "47.121.137.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-07-21 17:42:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743343": [
        {
            "ioc_value": "47.121.29.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-07-21 17:42:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743336": [
        {
            "ioc_value": "45.115.236.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-07-21 17:42:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743338": [
        {
            "ioc_value": "47.107.136.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-07-21 17:42:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743339": [
        {
            "ioc_value": "47.109.145.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-07-21 17:42:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743333": [
        {
            "ioc_value": "192.140.176.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-07-21 17:42:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743334": [
        {
            "ioc_value": "36.140.162.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-07-21 17:42:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743335": [
        {
            "ioc_value": "39.105.165.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-07-21 17:42:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743330": [
        {
            "ioc_value": "152.32.251.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-07-21 17:42:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743331": [
        {
            "ioc_value": "154.201.74.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-07-21 17:42:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743332": [
        {
            "ioc_value": "179.43.186.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-07-21 17:42:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743326": [
        {
            "ioc_value": "139.196.41.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-07-21 17:42:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743327": [
        {
            "ioc_value": "139.224.16.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-07-21 17:42:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743328": [
        {
            "ioc_value": "14.103.175.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-07-21 17:42:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743329": [
        {
            "ioc_value": "150.187.25.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-07-21 17:42:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743322": [
        {
            "ioc_value": "120.48.168.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-07-21 17:42:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743323": [
        {
            "ioc_value": "121.40.18.128:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-07-21 17:42:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743324": [
        {
            "ioc_value": "122.51.93.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-07-21 17:42:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743325": [
        {
            "ioc_value": "134.122.140.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-07-21 17:42:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743320": [
        {
            "ioc_value": "117.72.102.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-07-21 17:42:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743321": [
        {
            "ioc_value": "117.72.242.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-07-21 17:42:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743318": [
        {
            "ioc_value": "113.44.67.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-07-21 17:42:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743319": [
        {
            "ioc_value": "115.190.161.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-07-21 17:42:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743314": [
        {
            "ioc_value": "106.38.201.95:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-07-21 17:42:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743315": [
        {
            "ioc_value": "106.75.162.108:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-07-21 17:42:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743316": [
        {
            "ioc_value": "106.75.215.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-07-21 17:42:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743317": [
        {
            "ioc_value": "106.75.224.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-07-21 17:42:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743312": [
        {
            "ioc_value": "106.12.219.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-07-21 17:42:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743313": [
        {
            "ioc_value": "106.13.29.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-07-21 17:42:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743267": [
        {
            "ioc_value": "15.204.14.143:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-08 11:00:25",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.14.143",
            "tags": "AS16276,C2,censys,OVH",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1743209": [
        {
            "ioc_value": "15.204.95.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-08 04:00:55",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.95.228",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1742595": [
        {
            "ioc_value": "174.138.86.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-07 03:00:18",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/174.138.86.141",
            "tags": "AS14061,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1741587": [
        {
            "ioc_value": "57.158.27.132:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-02-05 13:01:59",
            "last_seen_utc": "2026-07-21 17:45:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/57.158.27.132#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1741476": [
        {
            "ioc_value": "94.74.0.253:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-05 11:00:23",
            "last_seen_utc": "2026-07-21 17:45:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/94.74.0.253",
            "tags": "AS39636,ASN-AEMNET,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1741375": [
        {
            "ioc_value": "37.72.172.58:6066",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-02-05 06:34:37",
            "last_seen_utc": "2026-07-21 17:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AS29802,asyncrat,c2,fofa,RAT",
            "anonymous": 0,
            "reporter": "oxygen28"
        }
    ],
    "1741132": [
        {
            "ioc_value": "172.174.234.34:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-04 11:00:54",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.174.234.34",
            "tags": "AS8075,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1740953": [
        {
            "ioc_value": "188.166.244.201:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-04 00:02:27",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/188.166.244.201",
            "tags": "AdaptixC2,AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739255": [
        {
            "ioc_value": "98.85.71.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-31 00:05:33",
            "last_seen_utc": "2026-07-21 17:45:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/98.85.71.175",
            "tags": "AMAZON-AES,AS14618,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739209": [
        {
            "ioc_value": "47.115.193.52:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-01-30 18:54:11",
            "last_seen_utc": "2026-07-21 17:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1739169": [
        {
            "ioc_value": "167.99.208.145:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-30 16:05:29",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.99.208.145",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739163": [
        {
            "ioc_value": "107.150.105.91:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 16:04:48",
            "last_seen_utc": "2026-07-21 17:42:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.150.105.91",
            "tags": "AS135377,C2,censys,CobaltStrike,cs-watermark-666666666,UCLOUD-HK-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739009": [
        {
            "ioc_value": "111.92.243.40:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 08:04:49",
            "last_seen_utc": "2026-07-21 17:42:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.92.243.40",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1738921": [
        {
            "ioc_value": "45.82.85.50:13063",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-01-30 02:55:25",
            "last_seen_utc": "2026-07-21 17:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1738909": [
        {
            "ioc_value": "68.64.178.201:54321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-01-30 00:06:02",
            "last_seen_utc": "2026-07-21 17:45:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.64.178.201",
            "tags": "AdaptixC2,AS139659,C2,censys,LUCID-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1737790": [
        {
            "ioc_value": "47.120.46.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-26 23:00:09",
            "last_seen_utc": "2026-07-21 17:42:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.46.230",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1737664": [
        {
            "ioc_value": "https://fluraresto.me/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-01-26 13:57:13",
            "last_seen_utc": "2026-07-21 17:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1737665": [
        {
            "ioc_value": "https://mastralakkot.live/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-01-26 13:57:13",
            "last_seen_utc": "2026-07-21 17:33:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1737569": [
        {
            "ioc_value": "27.223.85.234:58001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-01-26 08:05:39",
            "last_seen_utc": "2026-07-21 17:45:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/27.223.85.234",
            "tags": "AdaptixC2,AS4837,C2,censys,CHINA169-BACKBONE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1737455": [
        {
            "ioc_value": "167.179.76.179:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-25 22:49:35",
            "last_seen_utc": "2026-07-21 17:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1737454": [
        {
            "ioc_value": "ns1.ns-apache.jo3.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-25 22:48:35",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1736696": [
        {
            "ioc_value": "80.87.206.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.rhysida",
            "malware_alias": null,
            "malware_printable": "Rhysida",
            "first_seen_utc": "2026-01-24 18:47:55",
            "last_seen_utc": "2026-07-21 17:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Rhysida",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1736697": [
        {
            "ioc_value": "80.87.206.64:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.rhysida",
            "malware_alias": null,
            "malware_printable": "Rhysida",
            "first_seen_utc": "2026-01-24 18:47:55",
            "last_seen_utc": "2026-07-21 17:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Rhysida",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1736189": [
        {
            "ioc_value": "https://cpajoliette.com/q",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-01-23 17:27:00",
            "last_seen_utc": "2026-07-20 13:09:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/115945269899095691",
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1736055": [
        {
            "ioc_value": "lat.sodstreams.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-23 09:14:44",
            "last_seen_utc": "2026-07-21 17:13:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1736049": [
        {
            "ioc_value": "https://lat.sodstreams.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-23 09:14:26",
            "last_seen_utc": "2026-07-21 17:13:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1736014": [
        {
            "ioc_value": "47.120.32.72:8075",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-23 08:04:06",
            "last_seen_utc": "2026-07-21 17:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.32.72",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735522": [
        {
            "ioc_value": "176.31.71.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 12:04:28",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/176.31.71.168",
            "tags": "AS16276,C2,censys,OVH,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735337": [
        {
            "ioc_value": "121.4.92.72:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-21 20:03:53",
            "last_seen_utc": "2026-07-21 17:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/121.4.92.72",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734893": [
        {
            "ioc_value": "136.24.173.249:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-20 16:04:24",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/136.24.173.249",
            "tags": "AS19165,C2,censys,Mythic,WEBPASS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734081": [
        {
            "ioc_value": "103.79.79.105:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-18 00:03:59",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.79.79.105",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734053": [
        {
            "ioc_value": "43.139.50.42:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-17 20:52:32",
            "last_seen_utc": "2026-07-21 17:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1733763": [
        {
            "ioc_value": "113.250.188.15:8078",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-17 11:00:10",
            "last_seen_utc": "2026-07-20 14:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.250.188.15",
            "tags": "AS134420,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1732736": [
        {
            "ioc_value": "64.23.231.32:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-01-16 11:05:53",
            "last_seen_utc": "2026-07-21 17:45:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/64.23.231.32#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1732709": [
        {
            "ioc_value": "117.72.178.246:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-16 11:03:46",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.178.246#4848",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1732012": [
        {
            "ioc_value": "212.103.26.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-01-13 20:03:58",
            "last_seen_utc": "2026-07-21 17:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/212.103.26.10",
            "tags": "AS15557,C2,censys,Havoc,LDCOMNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1732009": [
        {
            "ioc_value": "47.84.83.56:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-01-13 20:03:34",
            "last_seen_utc": "2026-07-21 17:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.84.83.56",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1731532": [
        {
            "ioc_value": "54.38.94.225:8881",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-01-13 08:52:00",
            "last_seen_utc": "2026-07-21 17:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1700191": [
        {
            "ioc_value": "115.190.237.175:35555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-09 20:02:46",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.237.175",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-666666666,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1693493": [
        {
            "ioc_value": "137.184.93.131:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-09 11:01:05",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/137.184.93.131",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1693365": [
        {
            "ioc_value": "117.72.178.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-08 23:00:12",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.178.246",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1693357": [
        {
            "ioc_value": "172.94.18.103:191",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-08 22:50:04",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1693090": [
        {
            "ioc_value": "123.249.100.226:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-08 08:51:57",
            "last_seen_utc": "2026-07-21 17:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1692743": [
        {
            "ioc_value": "38.49.57.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-07 20:02:36",
            "last_seen_utc": "2026-07-21 17:42:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.49.57.15",
            "tags": "AS8796,C2,censys,CobaltStrike,cs-watermark-666666666,FD-298-8796",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1691952": [
        {
            "ioc_value": "115.190.233.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-06 08:02:23",
            "last_seen_utc": "2026-07-21 17:42:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.233.79",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1691605": [
        {
            "ioc_value": "http://213.5.130.122",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:42",
            "last_seen_utc": "2026-07-21 06:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691603": [
        {
            "ioc_value": "http://213.5.130.151",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:41",
            "last_seen_utc": "2026-07-21 06:02:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691604": [
        {
            "ioc_value": "http://213.5.130.124",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-07-21 06:02:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691606": [
        {
            "ioc_value": "http://213.5.130.187",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-07-21 06:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691547": [
        {
            "ioc_value": "ptn.passadisco.com.br",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-05 10:07:28",
            "last_seen_utc": "2026-07-21 17:12:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1691488": [
        {
            "ioc_value": "https://ptn.passadisco.com.br/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-01-05 10:06:50",
            "last_seen_utc": "2026-07-21 17:12:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1689798": [
        {
            "ioc_value": "157.245.54.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-02 04:03:37",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/157.245.54.75",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1689290": [
        {
            "ioc_value": "182.92.117.223:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-01 07:01:03",
            "last_seen_utc": "2026-07-20 09:14:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688739": [
        {
            "ioc_value": "101.34.205.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:16",
            "last_seen_utc": "2026-07-21 17:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688738": [
        {
            "ioc_value": "103.171.35.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:15",
            "last_seen_utc": "2026-07-21 17:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688737": [
        {
            "ioc_value": "107.149.192.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:14",
            "last_seen_utc": "2026-07-21 17:42:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688734": [
        {
            "ioc_value": "124.222.218.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-07-21 17:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688735": [
        {
            "ioc_value": "124.221.255.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-07-21 17:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688736": [
        {
            "ioc_value": "123.56.78.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-07-21 17:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688732": [
        {
            "ioc_value": "152.32.202.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-07-21 17:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688733": [
        {
            "ioc_value": "150.158.119.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-07-21 17:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688730": [
        {
            "ioc_value": "165.154.244.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-07-21 17:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688731": [
        {
            "ioc_value": "156.225.20.77:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-07-21 17:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688729": [
        {
            "ioc_value": "182.92.239.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:10",
            "last_seen_utc": "2026-07-21 17:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688726": [
        {
            "ioc_value": "39.105.160.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-07-21 17:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688727": [
        {
            "ioc_value": "38.38.250.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-07-21 17:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688728": [
        {
            "ioc_value": "211.184.175.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-07-21 17:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688725": [
        {
            "ioc_value": "45.58.56.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:07",
            "last_seen_utc": "2026-07-21 17:42:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688723": [
        {
            "ioc_value": "8.130.80.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-07-21 17:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688724": [
        {
            "ioc_value": "8.130.26.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-07-21 17:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688721": [
        {
            "ioc_value": "94.74.164.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-07-21 17:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688722": [
        {
            "ioc_value": "87.251.67.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-07-21 17:42:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688694": [
        {
            "ioc_value": "16.171.13.191:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-30 16:04:05",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/16.171.13.191",
            "tags": "AMAZON-02,AS16509,C2,censys,Covenant",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1687948": [
        {
            "ioc_value": "222.186.17.103:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-29 08:46:57",
            "last_seen_utc": "2026-07-21 17:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1687817": [
        {
            "ioc_value": "118.89.88.183:56781",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-28 20:01:34",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.89.88.183",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1687807": [
        {
            "ioc_value": "163.181.213.114:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-28 18:44:20",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1687327": [
        {
            "ioc_value": "37.72.172.58:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-28 07:41:32",
            "last_seen_utc": "2026-07-21 17:45:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1687170": [
        {
            "ioc_value": "37.72.172.58:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-27 16:02:33",
            "last_seen_utc": "2026-07-21 17:45:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1686405": [
        {
            "ioc_value": "155.102.62.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-25 18:44:15",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1686010": [
        {
            "ioc_value": "139.196.223.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-25 07:52:31",
            "last_seen_utc": "2026-07-21 17:42:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.196.223.82",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1685856": [
        {
            "ioc_value": "helpremote.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-24 12:48:51",
            "last_seen_utc": "2026-07-21 17:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1685596": [
        {
            "ioc_value": "172.94.18.103:190",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-23 22:45:05",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1685256": [
        {
            "ioc_value": "115.190.160.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 20:01:06",
            "last_seen_utc": "2026-07-21 17:42:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.160.206",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1684938": [
        {
            "ioc_value": "8.159.146.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 03:00:34",
            "last_seen_utc": "2026-07-21 17:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1684936": [
        {
            "ioc_value": "missmovie.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 02:54:49",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1684826": [
        {
            "ioc_value": "179.43.186.214:7889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-22 20:01:00",
            "last_seen_utc": "2026-07-21 17:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/179.43.186.214",
            "tags": "AS51852,C2,censys,CobaltStrike,cs-watermark-987654321,PLI-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1684543": [
        {
            "ioc_value": "64.190.113.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-12-22 00:01:20",
            "last_seen_utc": "2026-07-21 17:45:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.190.113.161",
            "tags": "AS399629,BLNWX,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1682522": [
        {
            "ioc_value": "155.102.133.61:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-18 18:44:36",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1681218": [
        {
            "ioc_value": "36.140.162.173:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-17 04:00:34",
            "last_seen_utc": "2026-07-21 17:46:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/36.140.162.173",
            "tags": "AS9808,C2,censys,CHINAMOBILE-CN,CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1680395": [
        {
            "ioc_value": "119.45.160.160:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-16 06:49:03",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.45.160.160#8889",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1680306": [
        {
            "ioc_value": "43.161.245.186:79",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-16 02:49:55",
            "last_seen_utc": "2026-07-21 17:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1680210": [
        {
            "ioc_value": "39.105.200.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-15 20:00:23",
            "last_seen_utc": "2026-07-21 17:46:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.105.200.188",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1676363": [
        {
            "ioc_value": "67.219.102.244:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-12 02:50:28",
            "last_seen_utc": "2026-07-21 17:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1675463": [
        {
            "ioc_value": "101.42.255.92:6379",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-11 12:04:11",
            "last_seen_utc": "2026-07-21 04:05:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.42.255.92",
            "tags": "AdaptixC2,AS45090,C2,censys,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1674643": [
        {
            "ioc_value": "159.75.75.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-11 02:49:26",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1670887": [
        {
            "ioc_value": "20.157.116.151:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-08 14:58:40",
            "last_seen_utc": "2026-07-21 17:44:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.157.116.151",
            "tags": "AdaptixC2,AS8069,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1668967": [
        {
            "ioc_value": "180.76.141.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-07 16:01:37",
            "last_seen_utc": "2026-07-21 17:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/180.76.141.175",
            "tags": "AS38365,BAIDU,C2,censys,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1667182": [
        {
            "ioc_value": "216.238.89.173:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-04 00:03:19",
            "last_seen_utc": "2026-07-21 17:44:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/216.238.89.173",
            "tags": "AdaptixC2,AS-VULTR,AS20473,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1667122": [
        {
            "ioc_value": "149.28.138.70:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-12-03 20:02:26",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.138.70",
            "tags": "AS-VULTR,AS20473,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1667105": [
        {
            "ioc_value": "115.190.161.178:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-03 20:01:15",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.161.178",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1666902": [
        {
            "ioc_value": "122.114.10.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-03 12:31:15",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.114.10.199",
            "tags": "AS4837,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1666137": [
        {
            "ioc_value": "8.137.149.67:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-02 12:51:03",
            "last_seen_utc": "2026-07-21 17:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1665523": [
        {
            "ioc_value": "http://213.5.130.104",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-07-21 06:02:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665524": [
        {
            "ioc_value": "http://213.5.130.180",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-07-21 06:02:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665525": [
        {
            "ioc_value": "http://213.5.130.106",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:50",
            "last_seen_utc": "2026-07-21 06:02:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665526": [
        {
            "ioc_value": "http://213.5.130.102",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-07-21 06:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665527": [
        {
            "ioc_value": "http://213.5.130.152",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-07-21 06:02:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665528": [
        {
            "ioc_value": "http://213.5.130.107",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-07-21 06:02:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665529": [
        {
            "ioc_value": "http://213.5.130.153",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-07-21 06:02:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665530": [
        {
            "ioc_value": "http://213.5.130.100",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-07-21 06:02:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665531": [
        {
            "ioc_value": "http://213.5.130.182",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-07-21 06:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665532": [
        {
            "ioc_value": "http://213.5.130.181",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:47",
            "last_seen_utc": "2026-07-21 06:02:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665454": [
        {
            "ioc_value": "122.114.10.199:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-01 12:36:20",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.114.10.199",
            "tags": "AS4837,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1665331": [
        {
            "ioc_value": "47.84.83.56:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-01 06:57:39",
            "last_seen_utc": "2026-07-21 17:45:28",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.84.83.56#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1663012": [
        {
            "ioc_value": "47.236.56.15:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-29 12:00:52",
            "last_seen_utc": "2026-07-21 17:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.56.15",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,CobaltStrike,cs-watermark-0",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1660878": [
        {
            "ioc_value": "43.162.121.116:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-29 04:01:42",
            "last_seen_utc": "2026-07-21 17:45:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.121.116",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1651951": [
        {
            "ioc_value": "5.101.82.51:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-11-28 04:01:01",
            "last_seen_utc": "2026-07-19 18:45:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.51",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1650889": [
        {
            "ioc_value": "job.itechno.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-26 12:50:54",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1650040": [
        {
            "ioc_value": "156.245.248.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-25 10:49:55",
            "last_seen_utc": "2026-07-21 17:42:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1649977": [
        {
            "ioc_value": "88.192.127.87:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2025-11-25 08:01:18",
            "last_seen_utc": "2026-07-21 17:45:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/88.192.127.87",
            "tags": "AS1759,C2,censys,Quasar,RAT,TSF-IP-CORE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1649775": [
        {
            "ioc_value": "http://213.5.130.84",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:37",
            "last_seen_utc": "2026-07-21 06:02:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649776": [
        {
            "ioc_value": "http://213.5.130.96",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-07-21 06:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649777": [
        {
            "ioc_value": "http://213.5.130.98",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-07-21 06:02:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649778": [
        {
            "ioc_value": "http://213.5.130.160",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:35",
            "last_seen_utc": "2026-07-21 06:02:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649164": [
        {
            "ioc_value": "5.101.86.44:61288",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-11-23 08:00:29",
            "last_seen_utc": "2026-07-21 17:45:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.86.44",
            "tags": "AS-GLOBALTELEHOST,AS62563,C2,censys,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1647575": [
        {
            "ioc_value": "123.58.64.57:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-21 00:02:05",
            "last_seen_utc": "2026-07-21 17:46:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/123.58.64.57",
            "tags": "AS17623,C2,censys,CNCGROUP-SZ,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1645785": [
        {
            "ioc_value": "47.236.149.142:46832",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-17 23:00:18",
            "last_seen_utc": "2026-07-21 17:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.149.142",
            "tags": "AS45102,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1645520": [
        {
            "ioc_value": "http://185.132.133.140",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-17 13:58:09",
            "last_seen_utc": "2026-07-21 06:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1645505": [
        {
            "ioc_value": "194.233.73.173:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-11-17 12:04:03",
            "last_seen_utc": "2026-07-21 17:44:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/194.233.73.173",
            "tags": "AdaptixC2,AS141995,C2,CAPL-AS-AP,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1641582": [
        {
            "ioc_value": "62.4.0.66:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-15 08:48:18",
            "last_seen_utc": "2026-07-21 17:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1639703": [
        {
            "ioc_value": "62.60.226.183:483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2025-11-13 04:54:17",
            "last_seen_utc": "2026-07-21 15:46:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Tofsee",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1639434": [
        {
            "ioc_value": "62.4.0.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-12 16:02:00",
            "last_seen_utc": "2026-07-21 17:45:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.4.0.66",
            "tags": "AS12876,C2,censys,Mythic,Online",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638854": [
        {
            "ioc_value": "54.165.230.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-12 04:02:31",
            "last_seen_utc": "2026-07-21 17:45:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.165.230.182",
            "tags": "AMAZON-AES,AS14618,C2,censys,Covenant",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638274": [
        {
            "ioc_value": "38.242.212.5:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-11-10 18:47:41",
            "last_seen_utc": "2026-07-21 17:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1638236": [
        {
            "ioc_value": "154.205.145.109:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-11-10 16:02:55",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/154.205.145.109",
            "tags": "AS138915,C2,censys,Havoc,KAOPU-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1637255": [
        {
            "ioc_value": "62.60.226.65:43155",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-11-09 08:02:17",
            "last_seen_utc": "2026-07-21 17:45:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.60.226.65",
            "tags": "AS214351,C2,censys,FEMOIT,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1636099": [
        {
            "ioc_value": "111.228.55.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 23:00:12",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.228.55.96",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1634744": [
        {
            "ioc_value": "165.154.225.239:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 02:49:37",
            "last_seen_utc": "2026-07-21 17:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1634389": [
        {
            "ioc_value": "139.196.111.118:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-06 07:26:25",
            "last_seen_utc": "2026-07-21 17:46:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1633501": [
        {
            "ioc_value": "59.110.28.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 20:01:04",
            "last_seen_utc": "2026-07-21 17:42:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/59.110.28.230",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1633194": [
        {
            "ioc_value": "51.15.8.6:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-11-04 08:00:54",
            "last_seen_utc": "2026-07-21 17:45:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.8.6",
            "tags": "AS12876,C2,censys,Online,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1633063": [
        {
            "ioc_value": "192.253.227.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:22",
            "last_seen_utc": "2026-07-21 17:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1633061": [
        {
            "ioc_value": "167.88.168.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:14",
            "last_seen_utc": "2026-07-21 17:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1632776": [
        {
            "ioc_value": "83.229.126.183:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 20:00:26",
            "last_seen_utc": "2026-07-21 17:46:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.126.183",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-987654321,LUCID-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1631753": [
        {
            "ioc_value": "117.72.175.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2025-11-03 12:08:57",
            "last_seen_utc": "2026-07-21 17:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.nviso.eu/blog",
            "tags": "C2,NVISO,VShell",
            "anonymous": 0,
            "reporter": "0xThiebaut"
        }
    ],
    "1631367": [
        {
            "ioc_value": "117.72.242.9:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 09:03:04",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.242.9",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1631471": [
        {
            "ioc_value": "119.42.148.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 07:01:12",
            "last_seen_utc": "2026-07-21 17:42:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.42.148.186#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1630832": [
        {
            "ioc_value": "157.20.182.18:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-11-01 12:36:10",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/157.20.182.18#1337",
            "tags": "asyncrat,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1630704": [
        {
            "ioc_value": "117.72.175.125:8087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-01 12:31:38",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.175.125#8087",
            "tags": "c2,cobaltstrike,cs-watermark-391144938,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1630391": [
        {
            "ioc_value": "85.215.57.133:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-10-31 16:01:24",
            "last_seen_utc": "2026-07-21 17:45:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/85.215.57.133",
            "tags": "AdaptixC2,AS8560,C2,censys,IONOS-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1629384": [
        {
            "ioc_value": "103.149.93.146:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-30 04:00:42",
            "last_seen_utc": "2026-07-21 17:42:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.149.93.146",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1628814": [
        {
            "ioc_value": "179.43.186.214:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 09:23:45",
            "last_seen_utc": "2026-07-21 17:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1628691": [
        {
            "ioc_value": "8.17.56.128:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 02:49:59",
            "last_seen_utc": "2026-07-21 17:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1628076": [
        {
            "ioc_value": "8.137.149.67:8060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 12:28:01",
            "last_seen_utc": "2026-07-21 17:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1627925": [
        {
            "ioc_value": "182.254.155.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 04:00:27",
            "last_seen_utc": "2026-07-21 17:42:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/182.254.155.23",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1627719": [
        {
            "ioc_value": "182.16.98.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 02:49:21",
            "last_seen_utc": "2026-07-21 17:42:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1627659": [
        {
            "ioc_value": "182.16.98.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-27 20:50:01",
            "last_seen_utc": "2026-07-21 17:42:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1626705": [
        {
            "ioc_value": "196.251.83.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-26 07:39:14",
            "last_seen_utc": "2026-07-21 17:42:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/196.251.83.89",
            "tags": "AS401120,C2,censys,CHEAPY-HOST",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1626312": [
        {
            "ioc_value": "173.212.216.226:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-10-25 04:02:07",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/173.212.216.226",
            "tags": "AS51167,censys,Chaos,CONTABO,panel",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1626300": [
        {
            "ioc_value": "47.121.135.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-25 04:00:11",
            "last_seen_utc": "2026-07-21 17:42:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.121.135.201",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1626112": [
        {
            "ioc_value": "140.143.194.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-24 16:00:08",
            "last_seen_utc": "2026-07-21 17:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/140.143.194.253",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1625642": [
        {
            "ioc_value": "maelootp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 16:48:58",
            "last_seen_utc": "2026-07-21 17:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1625564": [
        {
            "ioc_value": "evil.ritademo.io.vn",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 12:50:22",
            "last_seen_utc": "2026-07-21 17:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1625107": [
        {
            "ioc_value": "185.72.8.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-10-22 18:45:52",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1625108": [
        {
            "ioc_value": "185.72.8.137:7882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-10-22 18:45:52",
            "last_seen_utc": "2026-07-21 17:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1624905": [
        {
            "ioc_value": "116.62.226.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-22 15:43:44",
            "last_seen_utc": "2026-07-21 17:42:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1624664": [
        {
            "ioc_value": "115.190.140.220:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-22 08:02:02",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.140.220",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1624300": [
        {
            "ioc_value": "47.110.67.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 20:01:59",
            "last_seen_utc": "2026-07-21 17:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.110.67.64",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1624166": [
        {
            "ioc_value": "http://213.5.130.75",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:24",
            "last_seen_utc": "2026-07-21 06:02:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624167": [
        {
            "ioc_value": "http://213.5.130.10",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:23",
            "last_seen_utc": "2026-07-21 06:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624170": [
        {
            "ioc_value": "http://213.5.130.89",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:22",
            "last_seen_utc": "2026-07-21 06:02:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1618876": [
        {
            "ioc_value": "www.salesf0rce.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 02:49:37",
            "last_seen_utc": "2026-07-21 17:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1617732": [
        {
            "ioc_value": "157.20.182.18:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-10-19 06:39:17",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/157.20.182.18",
            "tags": "AS152485,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1617577": [
        {
            "ioc_value": "143.92.43.246:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-18 12:49:25",
            "last_seen_utc": "2026-07-21 17:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1617285": [
        {
            "ioc_value": "5.152.16.189:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-10-17 12:02:17",
            "last_seen_utc": "2026-07-21 17:45:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.152.16.189",
            "tags": "AS35805,C2,censys,Netsupport,RAT,SILKNET-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1617002": [
        {
            "ioc_value": "3.143.55.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-17 08:02:43",
            "last_seen_utc": "2026-07-21 17:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.143.55.137",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1616729": [
        {
            "ioc_value": "47.129.2.130:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:50:54",
            "last_seen_utc": "2026-07-21 17:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1616728": [
        {
            "ioc_value": "ns1.gygiuh.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:49:04",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1615761": [
        {
            "ioc_value": "89.58.30.49:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-14 20:02:48",
            "last_seen_utc": "2026-07-21 17:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.58.30.49",
            "tags": "AS197540,C2,censys,Covenant,NETCUP-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1614712": [
        {
            "ioc_value": "5.101.82.60:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-10-14 08:01:33",
            "last_seen_utc": "2026-07-21 17:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.60",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1608986": [
        {
            "ioc_value": "45.138.16.162:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-10-07 20:02:30",
            "last_seen_utc": "2026-07-21 17:45:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.138.16.162",
            "tags": "AdaptixC2,AS210558,C2,censys,SERVICES-1337-GMBH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1608605": [
        {
            "ioc_value": "143.92.43.153:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-07 02:49:11",
            "last_seen_utc": "2026-07-21 17:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1608606": [
        {
            "ioc_value": "143.92.43.231:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-07 02:49:11",
            "last_seen_utc": "2026-07-21 17:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1604523": [
        {
            "ioc_value": "18.219.51.236:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-30 04:00:23",
            "last_seen_utc": "2026-07-21 17:43:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.219.51.236",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1604499": [
        {
            "ioc_value": "149.50.135.215:49152",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-30 00:02:15",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.50.135.215",
            "tags": "AdaptixC2,AS27823,C2,censys,Dattatec.com",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1603281": [
        {
            "ioc_value": "154.92.15.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-28 15:48:32",
            "last_seen_utc": "2026-07-21 17:42:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1602818": [
        {
            "ioc_value": "84.27.86.226:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-09-27 16:02:13",
            "last_seen_utc": "2026-07-20 18:45:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/84.27.86.226",
            "tags": "AS33915,C2,censys,Netsupport,RAT,TNF-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1601556": [
        {
            "ioc_value": "115.120.245.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 20:00:39",
            "last_seen_utc": "2026-07-21 17:42:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.120.245.134",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-987654321,HWCSNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1601359": [
        {
            "ioc_value": "196.251.69.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 12:51:01",
            "last_seen_utc": "2026-07-21 17:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1599651": [
        {
            "ioc_value": "47.113.186.138:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-24 20:00:10",
            "last_seen_utc": "2026-07-21 17:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.113.186.138",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599442": [
        {
            "ioc_value": "43.162.114.240:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-24 08:02:13",
            "last_seen_utc": "2026-07-21 17:45:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.240",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1598336": [
        {
            "ioc_value": "43.139.170.200:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-23 06:06:58",
            "last_seen_utc": "2026-07-21 17:46:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1598300": [
        {
            "ioc_value": "43.162.114.107:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-23 04:00:59",
            "last_seen_utc": "2026-07-21 17:45:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.107",
            "tags": "AS132203,censys,EvilGinx,Phishing",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1598102": [
        {
            "ioc_value": "159.75.211.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:51:05",
            "last_seen_utc": "2026-07-21 17:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1598100": [
        {
            "ioc_value": "cstest.mucfc.store",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:49:30",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1597898": [
        {
            "ioc_value": "ns2.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:38",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1597894": [
        {
            "ioc_value": "ns1.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:35",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1596535": [
        {
            "ioc_value": "43.162.108.133:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-21 16:01:22",
            "last_seen_utc": "2026-07-21 17:45:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.108.133",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1590702": [
        {
            "ioc_value": "61.155.145.182:8090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-15 20:01:53",
            "last_seen_utc": "2026-07-21 17:46:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/61.155.145.182",
            "tags": "AS140292,C2,censys,CHINATELECOM-JIANGSU-SUZHOU-5G-NETWORK,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1589068": [
        {
            "ioc_value": "18.167.174.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-09-13 04:01:58",
            "last_seen_utc": "2026-07-21 17:43:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.167.174.198",
            "tags": "AMAZON-02,AS16509,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1588789": [
        {
            "ioc_value": "144.208.127.243:50375",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-09-13 00:02:05",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/144.208.127.243",
            "tags": "AS395092,C2,censys,SHOCK-1,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1588133": [
        {
            "ioc_value": "195.178.110.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:36",
            "last_seen_utc": "2026-07-21 17:42:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.178.110.135",
            "tags": "AS48090,C2,censys,CobaltStrike,cs-watermark-426352781,DMZHOST",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1588128": [
        {
            "ioc_value": "150.158.170.241:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:30",
            "last_seen_utc": "2026-07-21 17:42:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.158.170.241",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1587773": [
        {
            "ioc_value": "106.12.111.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 06:43:14",
            "last_seen_utc": "2026-07-21 17:42:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1587441": [
        {
            "ioc_value": "101.32.109.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-10 20:01:24",
            "last_seen_utc": "2026-07-21 17:42:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.32.109.112",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1587229": [
        {
            "ioc_value": "142.93.86.246:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-10 16:02:07",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/142.93.86.246",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1582910": [
        {
            "ioc_value": "8.138.222.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-06 20:01:18",
            "last_seen_utc": "2026-07-21 17:42:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.138.222.215",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1582784": [
        {
            "ioc_value": "103.236.70.158:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-09-06 12:01:48",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.236.70.158",
            "tags": "AS134768,C2,censys,CHINANET-SHAANXI-CLOUD-BASE,DcRAT,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1581557": [
        {
            "ioc_value": "8.148.194.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-04 07:40:17",
            "last_seen_utc": "2026-07-21 17:42:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.148.194.157#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1580723": [
        {
            "ioc_value": "47.236.159.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:52:55",
            "last_seen_utc": "2026-07-21 17:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580721": [
        {
            "ioc_value": "ns2.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:45",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580720": [
        {
            "ioc_value": "ns1.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:42",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580257": [
        {
            "ioc_value": "47.121.137.8:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 05:43:42",
            "last_seen_utc": "2026-07-21 17:46:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.121.137.8#80",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1580237": [
        {
            "ioc_value": "47.99.196.178:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-02 04:01:38",
            "last_seen_utc": "2026-07-21 17:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.99.196.178",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1579038": [
        {
            "ioc_value": "180.76.244.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-01 12:00:33",
            "last_seen_utc": "2026-07-21 17:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/180.76.244.55",
            "tags": "AS38365,BAIDU,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1578921": [
        {
            "ioc_value": "109.205.181.248:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-01 00:01:11",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/109.205.181.248",
            "tags": "AS51167,C2,censys,CONTABO,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1578899": [
        {
            "ioc_value": "103.73.66.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-31 20:50:07",
            "last_seen_utc": "2026-07-21 17:42:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577783": [
        {
            "ioc_value": "43.199.78.142:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:50:45",
            "last_seen_utc": "2026-07-21 17:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577775": [
        {
            "ioc_value": "n1.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577776": [
        {
            "ioc_value": "n2.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577777": [
        {
            "ioc_value": "n3.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577774": [
        {
            "ioc_value": "lab.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:01",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1574099": [
        {
            "ioc_value": "89.216.98.17:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-08-25 08:14:17",
            "last_seen_utc": "2026-07-21 17:45:50",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/89.216.98.17#3085",
            "tags": "c2,netsupport,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1573705": [
        {
            "ioc_value": "43.163.112.217:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-25 00:00:27",
            "last_seen_utc": "2026-07-21 17:42:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.163.112.217",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1573112": [
        {
            "ioc_value": "3.24.114.211:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-23 16:00:59",
            "last_seen_utc": "2026-07-21 17:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.24.114.211",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1571607": [
        {
            "ioc_value": "178.16.55.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-20 08:02:12",
            "last_seen_utc": "2026-07-21 17:42:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/178.16.55.53",
            "tags": "C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1570775": [
        {
            "ioc_value": "116.203.31.207:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-18 20:01:59",
            "last_seen_utc": "2026-07-21 17:46:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.203.31.207",
            "tags": "AS24940,C2,censys,CobaltStrike,cs-watermark-987654321,HETZNER-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1570558": [
        {
            "ioc_value": "150.187.25.242:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-17 20:01:54",
            "last_seen_utc": "2026-07-21 17:46:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.187.25.242",
            "tags": "AS20312,C2,censys,CobaltStrike,cs-watermark-987654321,Fundacion",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1569825": [
        {
            "ioc_value": "8.138.167.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 15:22:26",
            "last_seen_utc": "2026-07-21 17:42:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.138.167.123#443",
            "tags": "c2,cobaltstrike,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1569780": [
        {
            "ioc_value": "119.29.231.118:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 08:01:47",
            "last_seen_utc": "2026-07-21 17:42:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.29.231.118",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1569167": [
        {
            "ioc_value": "116.198.233.179:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 21:57:45",
            "last_seen_utc": "2026-07-21 17:46:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/116.198.233.179#6666",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1569004": [
        {
            "ioc_value": "8ve3qsgxk7rs6.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 12:49:06",
            "last_seen_utc": "2026-07-21 17:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1568713": [
        {
            "ioc_value": "117.72.184.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 06:21:34",
            "last_seen_utc": "2026-07-21 17:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.184.172",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1568192": [
        {
            "ioc_value": "115.190.138.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-13 16:01:30",
            "last_seen_utc": "2026-07-21 17:46:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.138.41",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-391144938,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567756": [
        {
            "ioc_value": "116.198.233.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 20:01:25",
            "last_seen_utc": "2026-07-21 17:42:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.198.233.179",
            "tags": "AS137699,C2,censys,CHINATELECOM-JIANGSU-SUQIAN-IDC,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567668": [
        {
            "ioc_value": "62.117.98.115:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-12 12:01:59",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.117.98.115",
            "tags": "AS8732,C2,censys,COMCOR-AS,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567648": [
        {
            "ioc_value": "107.174.115.43:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 10:50:19",
            "last_seen_utc": "2026-07-21 17:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1567604": [
        {
            "ioc_value": "68.64.176.172:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 06:35:23",
            "last_seen_utc": "2026-07-21 17:46:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1567316": [
        {
            "ioc_value": "209.250.227.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-08-11 20:01:43",
            "last_seen_utc": "2026-07-21 17:44:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/209.250.227.127",
            "tags": "AS-VULTR,AS20473,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567234": [
        {
            "ioc_value": "45.204.216.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-11 08:01:15",
            "last_seen_utc": "2026-07-21 17:42:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.204.216.24",
            "tags": "AS62468,C2,censys,CobaltStrike,cs-watermark-987654321,HKCLOUDX",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1565164": [
        {
            "ioc_value": "8.219.76.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-06 12:54:26",
            "last_seen_utc": "2026-07-21 17:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564496": [
        {
            "ioc_value": "47.105.36.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-05 08:53:36",
            "last_seen_utc": "2026-07-21 17:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564345": [
        {
            "ioc_value": "185.233.166.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-08-04 20:45:44",
            "last_seen_utc": "2026-07-21 17:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564346": [
        {
            "ioc_value": "185.233.166.124:9702",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-08-04 20:45:44",
            "last_seen_utc": "2026-07-21 17:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1563211": [
        {
            "ioc_value": "89.197.168.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-01 20:01:06",
            "last_seen_utc": "2026-07-21 17:45:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.197.168.150",
            "tags": "AS47474,C2,censys,Mythic,VIRTUAL1",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1562698": [
        {
            "ioc_value": "68.133.1.34:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xenorat",
            "malware_alias": null,
            "malware_printable": "XenoRAT",
            "first_seen_utc": "2025-07-31 01:20:10",
            "last_seen_utc": "2026-07-21 17:45:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "XenoRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1561533": [
        {
            "ioc_value": "217.154.212.25:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-28 05:29:47",
            "last_seen_utc": "2026-07-21 17:44:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1561181": [
        {
            "ioc_value": "117.72.181.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-27 16:00:55",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.181.104",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1560912": [
        {
            "ioc_value": "47.236.130.154:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-26 12:51:52",
            "last_seen_utc": "2026-07-21 00:05:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1560617": [
        {
            "ioc_value": "47.236.130.154:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-25 10:51:18",
            "last_seen_utc": "2026-07-21 17:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1559822": [
        {
            "ioc_value": "47.122.152.65:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-23 16:00:37",
            "last_seen_utc": "2026-07-21 17:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.122.152.65",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1559594": [
        {
            "ioc_value": "158.255.213.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-07-22 20:44:22",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1559595": [
        {
            "ioc_value": "158.255.213.22:63421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-07-22 20:44:22",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1558329": [
        {
            "ioc_value": "103.125.248.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-19 12:49:30",
            "last_seen_utc": "2026-07-21 17:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1558066": [
        {
            "ioc_value": "193.112.84.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-18 12:51:20",
            "last_seen_utc": "2026-07-21 17:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1558027": [
        {
            "ioc_value": "206.189.227.148:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-07-18 08:01:12",
            "last_seen_utc": "2026-07-21 17:44:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.189.227.148",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1557619": [
        {
            "ioc_value": "ns3.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:04",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1557618": [
        {
            "ioc_value": "ns2.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:03",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1557617": [
        {
            "ioc_value": "ns1.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:02",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1556099": [
        {
            "ioc_value": "51.81.171.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-07-12 00:01:36",
            "last_seen_utc": "2026-07-21 17:45:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.81.171.234",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1554642": [
        {
            "ioc_value": "88.129.151.109:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-07-08 20:56:28",
            "last_seen_utc": "2026-07-21 17:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1554340": [
        {
            "ioc_value": "88.129.147.201:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-07-07 20:54:20",
            "last_seen_utc": "2026-07-21 17:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1554064": [
        {
            "ioc_value": "8.152.99.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-06 20:00:32",
            "last_seen_utc": "2026-07-21 17:42:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.152.99.85",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1551457": [
        {
            "ioc_value": "217.154.212.25:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-30 05:36:40",
            "last_seen_utc": "2026-07-21 17:46:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/217.154.212.25#8000",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1550784": [
        {
            "ioc_value": "116.205.143.204:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-28 10:54:22",
            "last_seen_utc": "2026-07-21 17:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1550783": [
        {
            "ioc_value": "dns1.globalcdn.autos",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-28 10:53:12",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1550284": [
        {
            "ioc_value": "54.38.94.225:8886",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-28 08:51:18",
            "last_seen_utc": "2026-07-20 18:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1549925": [
        {
            "ioc_value": "67.205.141.81:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-27 07:00:53",
            "last_seen_utc": "2026-07-21 17:45:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/67.205.141.81#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1549030": [
        {
            "ioc_value": "156.227.233.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-25 04:00:19",
            "last_seen_utc": "2026-07-21 17:42:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/156.227.233.153",
            "tags": "AS138152,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1548335": [
        {
            "ioc_value": "107.173.122.193:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-21 18:56:08",
            "last_seen_utc": "2026-07-21 17:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1548333": [
        {
            "ioc_value": "ns3.admlistdel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-21 18:55:13",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1548330": [
        {
            "ioc_value": "ns2.admlistdel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-21 18:55:10",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1547925": [
        {
            "ioc_value": "82.156.156.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-20 06:01:32",
            "last_seen_utc": "2026-07-21 17:42:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1546420": [
        {
            "ioc_value": "158.158.0.196:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-19 00:02:44",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/158.158.0.196",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1546246": [
        {
            "ioc_value": "191.93.118.254:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-06-18 08:02:37",
            "last_seen_utc": "2026-07-21 17:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9265a6e0b26a240f1f8bffddf3b36d0e533919d0c894bd66839a90e351961464/",
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1545615": [
        {
            "ioc_value": "8.147.128.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-17 03:12:25",
            "last_seen_utc": "2026-07-21 17:42:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1545348": [
        {
            "ioc_value": "8.137.149.67:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-16 12:01:46",
            "last_seen_utc": "2026-07-21 17:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.137.149.67",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1545221": [
        {
            "ioc_value": "107.173.122.193:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-16 08:01:46",
            "last_seen_utc": "2026-07-21 17:46:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.173.122.193",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1544612": [
        {
            "ioc_value": "47.109.48.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-13 20:01:30",
            "last_seen_utc": "2026-07-21 17:42:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.48.57",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1544039": [
        {
            "ioc_value": "39.104.78.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-12 08:56:19",
            "last_seen_utc": "2026-07-21 17:42:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.104.78.25",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1543390": [
        {
            "ioc_value": "8.155.0.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-10 16:01:13",
            "last_seen_utc": "2026-07-21 17:42:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.155.0.238",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1542759": [
        {
            "ioc_value": "119.45.29.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-08 20:01:01",
            "last_seen_utc": "2026-07-21 17:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.45.29.172",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1541652": [
        {
            "ioc_value": "68.64.176.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-06 16:00:50",
            "last_seen_utc": "2026-07-21 17:42:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.64.176.42",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-391144938,LUCID-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1541446": [
        {
            "ioc_value": "ns1.admlistdel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-06 02:53:59",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1538881": [
        {
            "ioc_value": "193.239.85.15:2083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-06-02 12:01:04",
            "last_seen_utc": "2026-07-21 17:44:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.239.85.15",
            "tags": "AS9009,C2,censys,Havoc,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1538799": [
        {
            "ioc_value": "47.109.198.8:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-02 05:47:28",
            "last_seen_utc": "2026-07-21 17:46:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.109.198.8#6000",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1538358": [
        {
            "ioc_value": "54.38.94.225:8885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-01 08:52:56",
            "last_seen_utc": "2026-07-21 17:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1537676": [
        {
            "ioc_value": "101.43.91.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:39",
            "last_seen_utc": "2026-07-21 17:42:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1537678": [
        {
            "ioc_value": "59.110.7.32:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:38",
            "last_seen_utc": "2026-07-21 17:42:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1536850": [
        {
            "ioc_value": "99.112.198.249:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-05-30 08:53:21",
            "last_seen_utc": "2026-07-21 17:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1536831": [
        {
            "ioc_value": "129.28.85.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 08:00:11",
            "last_seen_utc": "2026-07-21 17:42:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/129.28.85.210",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1536730": [
        {
            "ioc_value": "111.229.4.108:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 02:55:17",
            "last_seen_utc": "2026-07-21 17:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1536683": [
        {
            "ioc_value": "161.35.176.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-05-29 22:26:34",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.176.231",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1533613": [
        {
            "ioc_value": "221.132.29.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-24 20:01:31",
            "last_seen_utc": "2026-07-21 17:45:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/221.132.29.137",
            "tags": "AS45899,C2,censys,Mythic,VNPT-AS-VN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1533071": [
        {
            "ioc_value": "1.15.174.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-24 11:13:44",
            "last_seen_utc": "2026-07-21 17:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1532332": [
        {
            "ioc_value": "8.140.239.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-23 05:34:51",
            "last_seen_utc": "2026-07-21 17:42:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1532306": [
        {
            "ioc_value": "178.217.98.23:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-05-22 20:01:48",
            "last_seen_utc": "2026-07-21 17:43:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/178.217.98.23",
            "tags": "AS48282,censys,Chaos,panel,VDSINA-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1531654": [
        {
            "ioc_value": "122.10.49.137:808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 16:00:35",
            "last_seen_utc": "2026-07-21 17:46:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.10.49.137",
            "tags": "AS134548,C2,censys,CobaltStrike,cs-watermark-1234567890,DXTL-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1527752": [
        {
            "ioc_value": "117.72.206.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 08:00:35",
            "last_seen_utc": "2026-07-21 17:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.206.39",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1527457": [
        {
            "ioc_value": "122.10.25.26:808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 00:00:32",
            "last_seen_utc": "2026-07-21 17:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.10.25.26",
            "tags": "AS134548,C2,censys,CobaltStrike,cs-watermark-1234567890,DXTL-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1526357": [
        {
            "ioc_value": "106.54.61.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-20 06:37:42",
            "last_seen_utc": "2026-07-21 17:42:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1525250": [
        {
            "ioc_value": "124.223.114.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-18 15:34:22",
            "last_seen_utc": "2026-07-21 17:42:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://intelinsights.substack.com/p/from-939-to-85-hunting-cobalt-strike",
            "tags": "censys,cobaltstrike",
            "anonymous": 0,
            "reporter": "orlof_v"
        }
    ],
    "1524773": [
        {
            "ioc_value": "167.99.51.2:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 14:42:08",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.99.51.2#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1524641": [
        {
            "ioc_value": "167.99.51.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 08:00:32",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.99.51.2",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1524319": [
        {
            "ioc_value": "101.35.109.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-17 06:26:23",
            "last_seen_utc": "2026-07-21 17:42:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/101.35.109.246#443",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1523466": [
        {
            "ioc_value": "103.171.35.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:57",
            "last_seen_utc": "2026-07-21 17:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523462": [
        {
            "ioc_value": "60.204.169.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:47",
            "last_seen_utc": "2026-07-21 17:42:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523434": [
        {
            "ioc_value": "179.43.186.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:13:56",
            "last_seen_utc": "2026-07-21 17:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523280": [
        {
            "ioc_value": "45.133.180.138:6432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-05-15 06:10:52",
            "last_seen_utc": "2026-07-21 17:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b6185d4054c5a08141db4c3fb5e43369ea21af5892d8ba47628e23f37f79250d/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1523246": [
        {
            "ioc_value": "8.134.70.73:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 05:25:01",
            "last_seen_utc": "2026-07-20 09:14:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1521639": [
        {
            "ioc_value": "8.134.70.73:88",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-13 14:08:42",
            "last_seen_utc": "2026-07-21 17:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "beacon,c2,Cobalt Strike,CobaltStrike",
            "anonymous": 0,
            "reporter": "pancak3lullz"
        }
    ],
    "1520343": [
        {
            "ioc_value": "38.54.112.234:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:58:42",
            "last_seen_utc": "2026-07-21 17:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1520342": [
        {
            "ioc_value": "asusupdateserver.asuscomm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:55:40",
            "last_seen_utc": "2026-07-21 17:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1519438": [
        {
            "ioc_value": "47.109.190.151:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-11 06:11:06",
            "last_seen_utc": "2026-07-21 17:45:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.190.151",
            "tags": "AS37963,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1519451": [
        {
            "ioc_value": "https://lofiramegi.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-05-11 05:00:18",
            "last_seen_utc": "2026-07-21 17:33:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1519450": [
        {
            "ioc_value": "https://topguningit.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-05-11 05:00:17",
            "last_seen_utc": "2026-07-21 17:41:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1518529": [
        {
            "ioc_value": "47.108.140.10:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-09 05:36:03",
            "last_seen_utc": "2026-07-21 17:45:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.108.140.10",
            "tags": "AS37963,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1518023": [
        {
            "ioc_value": "106.52.207.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-07 13:00:19",
            "last_seen_utc": "2026-07-21 17:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1513590": [
        {
            "ioc_value": "54.38.94.225:8882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-04-29 08:53:29",
            "last_seen_utc": "2026-07-21 17:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1513585": [
        {
            "ioc_value": "107.143.144.154:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-04-29 08:43:42",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1513057": [
        {
            "ioc_value": "103.68.251.236:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-04-27 20:01:49",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.68.251.236",
            "tags": "AS150861,C2,censys,Mythic,POWERNET-VN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1511917": [
        {
            "ioc_value": "181.206.158.190:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-04-26 20:01:51",
            "last_seen_utc": "2026-07-21 17:43:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/181.206.158.190",
            "tags": "AS27831,C2,censys,Colombia,DcRAT,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1509966": [
        {
            "ioc_value": "167.71.13.103:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-22 12:21:47",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.71.13.103#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1493521": [
        {
            "ioc_value": "77.73.129.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-04-18 08:02:32",
            "last_seen_utc": "2026-07-21 17:45:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/77.73.129.82",
            "tags": "AS201814,C2,censys,MEVSPACE,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1492480": [
        {
            "ioc_value": "113.45.253.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-16 16:01:35",
            "last_seen_utc": "2026-07-21 17:46:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.45.253.80",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-666666666,HWCSNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1492012": [
        {
            "ioc_value": "47.83.134.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-04-15 16:02:30",
            "last_seen_utc": "2026-07-21 17:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.83.134.97",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1491748": [
        {
            "ioc_value": "193.142.146.70:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-04-15 04:01:37",
            "last_seen_utc": "2026-07-21 17:44:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.142.146.70",
            "tags": "AS213438,C2,censys,COLOCATEL-INC,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1486437": [
        {
            "ioc_value": "167.71.13.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-10 05:55:49",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.71.13.103",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1463173": [
        {
            "ioc_value": "38.46.218.36:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:14",
            "last_seen_utc": "2026-07-21 15:06:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463174": [
        {
            "ioc_value": "38.46.218.38:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:13",
            "last_seen_utc": "2026-07-21 17:12:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463176": [
        {
            "ioc_value": "38.46.218.39:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:12",
            "last_seen_utc": "2026-07-21 17:44:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463152": [
        {
            "ioc_value": "200.107.126.227:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-04-02 08:01:26",
            "last_seen_utc": "2026-07-21 17:44:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/200.107.126.227",
            "tags": "AS14754,C2,censys,Netsupport,RAT,TELECOMUNICACIONES",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1462468": [
        {
            "ioc_value": "43.143.229.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-01 10:24:30",
            "last_seen_utc": "2026-07-21 17:42:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1461919": [
        {
            "ioc_value": "8.140.239.162:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-31 06:14:47",
            "last_seen_utc": "2026-07-21 17:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.140.239.162",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1459722": [
        {
            "ioc_value": "193.142.146.70:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-03-28 04:00:35",
            "last_seen_utc": "2026-07-21 17:44:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.142.146.70",
            "tags": "AS213438,C2,censys,COLOCATEL-INC,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1458716": [
        {
            "ioc_value": "ehchq7m7rpvdr.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-25 22:53:24",
            "last_seen_utc": "2026-07-21 17:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1457513": [
        {
            "ioc_value": "103.142.147.17:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-24 06:29:33",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.142.147.17",
            "tags": "AS135581,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1454148": [
        {
            "ioc_value": "103.142.147.18:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-22 20:43:16",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1454149": [
        {
            "ioc_value": "103.142.147.19:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-22 20:43:16",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1452404": [
        {
            "ioc_value": "47.116.208.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-20 12:01:27",
            "last_seen_utc": "2026-07-21 17:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.116.208.81",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1446559": [
        {
            "ioc_value": "www.dyshop.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-12 02:47:28",
            "last_seen_utc": "2026-07-21 17:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1441769": [
        {
            "ioc_value": "51.81.171.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-06 04:01:35",
            "last_seen_utc": "2026-07-21 17:45:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.81.171.234",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1440611": [
        {
            "ioc_value": "43.153.2.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-04 00:00:37",
            "last_seen_utc": "2026-07-21 17:46:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.153.2.113",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-100000,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1440087": [
        {
            "ioc_value": "15.204.95.228:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-03 12:01:16",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.95.228",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1439776": [
        {
            "ioc_value": "150.5.174.231:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-02 20:01:03",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.5.174.231",
            "tags": "AS150436,BYTEPLUS-AS-AP,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1439368": [
        {
            "ioc_value": "54.38.94.225:8887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-03-02 08:46:23",
            "last_seen_utc": "2026-07-21 17:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439168": [
        {
            "ioc_value": "47.129.171.26:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:47:46",
            "last_seen_utc": "2026-07-21 17:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439166": [
        {
            "ioc_value": "ns.1.3.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439167": [
        {
            "ioc_value": "ns.1.4.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1424136": [
        {
            "ioc_value": "118.24.121.59:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-02-20 06:12:03",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.24.121.59",
            "tags": "AS45090,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1411885": [
        {
            "ioc_value": "192.52.167.140:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-02-14 00:01:07",
            "last_seen_utc": "2026-07-21 17:44:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/192.52.167.140",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Netsupport,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1409420": [
        {
            "ioc_value": "103.215.81.156:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-02-10 20:43:10",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1405307": [
        {
            "ioc_value": "https://apworsindos.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-06 13:54:51",
            "last_seen_utc": "2026-07-21 17:33:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1405308": [
        {
            "ioc_value": "https://reminasolirol.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-06 13:54:51",
            "last_seen_utc": "2026-07-21 17:41:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1404178": [
        {
            "ioc_value": "20.74.209.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-05 22:51:06",
            "last_seen_utc": "2026-07-21 17:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1402495": [
        {
            "ioc_value": "62.60.226.42:43155",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-02-02 16:00:48",
            "last_seen_utc": "2026-07-21 17:45:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.60.226.42",
            "tags": "AS214351,C2,censys,FEMOIT,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1402480": [
        {
            "ioc_value": "service-rchqbzvz-1301033415.sh.tencentapigw.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-02 12:49:35",
            "last_seen_utc": "2026-07-21 17:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1402273": [
        {
            "ioc_value": "https://vivaforevew.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-01 20:47:38",
            "last_seen_utc": "2026-07-21 17:44:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1402274": [
        {
            "ioc_value": "https://wersogkiwgow.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-01 20:47:38",
            "last_seen_utc": "2026-07-21 17:34:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1398921": [
        {
            "ioc_value": "62.60.226.6:43155",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-02-01 04:00:38",
            "last_seen_utc": "2026-07-21 17:45:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.60.226.6",
            "tags": "AS214351,C2,censys,FEMOIT,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1398820": [
        {
            "ioc_value": "162.252.173.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 13:44:30",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1398810": [
        {
            "ioc_value": "162.252.173.12:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 12:01:38",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/162.252.173.12",
            "tags": "AS9009,backdoor,C2,censys,M247,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1398657": [
        {
            "ioc_value": "8.134.108.73:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-31 07:01:30",
            "last_seen_utc": "2026-07-21 17:45:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.134.108.73",
            "tags": "AS37963,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1396136": [
        {
            "ioc_value": "38.146.28.93:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:47:19",
            "last_seen_utc": "2026-07-21 17:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1396135": [
        {
            "ioc_value": "185.33.86.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:45:48",
            "last_seen_utc": "2026-07-21 17:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1396130": [
        {
            "ioc_value": "38.146.28.93:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:01:38",
            "last_seen_utc": "2026-07-21 17:45:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.146.28.93",
            "tags": "AS174,backdoor,C2,censys,COGENT-174,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1396102": [
        {
            "ioc_value": "185.33.86.15:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 04:01:31",
            "last_seen_utc": "2026-07-21 17:44:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.33.86.15",
            "tags": "AS202015,backdoor,C2,censys,HZ-US-AS,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1394408": [
        {
            "ioc_value": "54.38.94.225:8883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-26 08:46:00",
            "last_seen_utc": "2026-07-21 17:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1394158": [
        {
            "ioc_value": "54.38.94.225:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-25 20:47:04",
            "last_seen_utc": "2026-07-21 17:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1391610": [
        {
            "ioc_value": "45.82.85.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-22 17:46:05",
            "last_seen_utc": "2026-07-21 17:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1386236": [
        {
            "ioc_value": "https://135.181.31.18",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-01-18 16:10:00",
            "last_seen_utc": "2026-07-21 17:10:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1384933": [
        {
            "ioc_value": "38.180.81.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:15:21",
            "last_seen_utc": "2026-07-21 17:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384934": [
        {
            "ioc_value": "38.180.81.153:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:15:21",
            "last_seen_utc": "2026-07-21 17:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384921": [
        {
            "ioc_value": "167.99.139.231:8004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-17 09:14:13",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384912": [
        {
            "ioc_value": "185.174.101.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-07-21 17:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384913": [
        {
            "ioc_value": "185.174.101.240:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-07-21 17:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384914": [
        {
            "ioc_value": "185.174.101.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-07-21 17:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384915": [
        {
            "ioc_value": "185.174.101.69:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-07-21 17:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384908": [
        {
            "ioc_value": "108.181.115.171:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384909": [
        {
            "ioc_value": "108.181.115.171:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384910": [
        {
            "ioc_value": "108.181.182.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384911": [
        {
            "ioc_value": "108.181.182.143:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384790": [
        {
            "ioc_value": "at1.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-07-21 17:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384791": [
        {
            "ioc_value": "at2.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-07-21 17:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384792": [
        {
            "ioc_value": "at3.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-07-21 17:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384380": [
        {
            "ioc_value": "103.43.18.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.meterpreter",
            "malware_alias": null,
            "malware_printable": "Meterpreter",
            "first_seen_utc": "2025-01-16 13:16:26",
            "last_seen_utc": "2026-07-21 05:05:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Metasploit,Meterpreter",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1381067": [
        {
            "ioc_value": "112.5.58.181:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:43:51",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380875": [
        {
            "ioc_value": "update.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-07-21 17:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380878": [
        {
            "ioc_value": "upgrade.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-07-21 17:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380837": [
        {
            "ioc_value": "ns3.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:30",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380841": [
        {
            "ioc_value": "ns3.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:30",
            "last_seen_utc": "2026-07-21 17:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380833": [
        {
            "ioc_value": "ns2.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:29",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380818": [
        {
            "ioc_value": "ns2.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:27",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380815": [
        {
            "ioc_value": "ns2.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:26",
            "last_seen_utc": "2026-07-21 17:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380811": [
        {
            "ioc_value": "ns1.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:25",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380783": [
        {
            "ioc_value": "ns1.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380787": [
        {
            "ioc_value": "ns1.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380635": [
        {
            "ioc_value": "8.219.78.159:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:57",
            "last_seen_utc": "2026-07-21 17:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380629": [
        {
            "ioc_value": "70.34.196.238:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:43",
            "last_seen_utc": "2026-07-21 17:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380607": [
        {
            "ioc_value": "47.98.134.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:28",
            "last_seen_utc": "2026-07-21 17:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380569": [
        {
            "ioc_value": "38.54.115.233:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:17:37",
            "last_seen_utc": "2026-07-21 17:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380533": [
        {
            "ioc_value": "207.148.68.118:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:17:20",
            "last_seen_utc": "2026-07-21 17:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380446": [
        {
            "ioc_value": "139.180.189.95:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:16:21",
            "last_seen_utc": "2026-07-21 17:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380421": [
        {
            "ioc_value": "118.25.91.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:44",
            "last_seen_utc": "2026-07-21 17:42:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380420": [
        {
            "ioc_value": "117.72.39.83:43872",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:43",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380232": [
        {
            "ioc_value": "38.207.179.146:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-10 04:04:28",
            "last_seen_utc": "2026-07-21 17:45:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.207.179.146",
            "tags": "AS139659,C2,censys,LUCID-AS-AP,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1377524": [
        {
            "ioc_value": "8.140.239.162:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-03 08:01:15",
            "last_seen_utc": "2026-07-21 17:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1376919": [
        {
            "ioc_value": "86.124.168.255:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2025-01-01 04:03:19",
            "last_seen_utc": "2026-07-21 17:45:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/86.124.168.255",
            "tags": "AS8708,c2,censys,RCS-RDS,SocGholish",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1359401": [
        {
            "ioc_value": "8.153.97.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-24 08:00:43",
            "last_seen_utc": "2026-07-21 17:42:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.153.97.202",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1359309": [
        {
            "ioc_value": "91.199.154.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-12-24 04:01:34",
            "last_seen_utc": "2026-07-21 17:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "AS62212,C2,censys,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1358842": [
        {
            "ioc_value": "149.28.61.158:8773",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-20 16:01:53",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.61.158",
            "tags": "AS-VULTR,AS20473,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1357389": [
        {
            "ioc_value": "45.56.69.210:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-16 16:01:41",
            "last_seen_utc": "2026-07-21 17:45:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.56.69.210",
            "tags": "AKAMAI-LINODE-AP,AS63949,censys,EvilGoPhish,panel,Phishing",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1356002": [
        {
            "ioc_value": "113.44.90.0:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-12 06:21:40",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.44.90.0",
            "tags": "AS55990,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1352876": [
        {
            "ioc_value": "139.196.126.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-06 07:36:52",
            "last_seen_utc": "2026-07-21 17:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1350210": [
        {
            "ioc_value": "117.72.39.83:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-02 21:01:15",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1349957": [
        {
            "ioc_value": "117.72.39.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-01 07:43:42",
            "last_seen_utc": "2026-07-21 17:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1349567": [
        {
            "ioc_value": "216.118.101.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:19",
            "last_seen_utc": "2026-07-21 17:44:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349531": [
        {
            "ioc_value": "216.118.101.132:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:11",
            "last_seen_utc": "2026-07-21 17:44:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349510": [
        {
            "ioc_value": "216.118.101.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:08",
            "last_seen_utc": "2026-07-21 17:44:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349492": [
        {
            "ioc_value": "216.118.101.216:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:04",
            "last_seen_utc": "2026-07-21 17:44:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349438": [
        {
            "ioc_value": "216.118.101.54:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:05:51",
            "last_seen_utc": "2026-07-21 17:44:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1348902": [
        {
            "ioc_value": "216.118.101.108:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-29 13:56:30",
            "last_seen_utc": "2026-07-21 17:44:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1348295": [
        {
            "ioc_value": "47.90.142.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:54",
            "last_seen_utc": "2026-07-21 17:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1348026": [
        {
            "ioc_value": "8.137.114.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:07",
            "last_seen_utc": "2026-07-21 17:42:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1347669": [
        {
            "ioc_value": "1.92.135.168:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:45:53",
            "last_seen_utc": "2026-07-19 20:05:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1346058": [
        {
            "ioc_value": "servicioremotoempresas.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-19 18:00:05",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1340201": [
        {
            "ioc_value": "146.70.158.198:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-10-30 17:53:55",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Sliver%20C2",
            "tags": "c2,sliver,sliverc2",
            "anonymous": 0,
            "reporter": "TheRavenFile"
        }
    ],
    "1338675": [
        {
            "ioc_value": "https://stripplasst.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:41",
            "last_seen_utc": "2026-07-21 17:44:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1338673": [
        {
            "ioc_value": "https://skinnyjeanso.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:39",
            "last_seen_utc": "2026-07-21 17:41:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1338670": [
        {
            "ioc_value": "https://coolarition.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:34",
            "last_seen_utc": "2026-07-21 17:35:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1332624": [
        {
            "ioc_value": "154.221.17.44:2888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-10-02 06:31:45",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1332328": [
        {
            "ioc_value": "195.100.198.220:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-10-01 16:02:09",
            "last_seen_utc": "2026-07-21 17:44:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.100.198.220",
            "tags": "AS5400,BT,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1329042": [
        {
            "ioc_value": "118.25.148.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-09-25 08:00:47",
            "last_seen_utc": "2026-07-21 17:42:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.148.25",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1326604": [
        {
            "ioc_value": "206.210.123.104:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-09-20 08:01:06",
            "last_seen_utc": "2026-07-21 17:44:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.210.123.104",
            "tags": "AS33130,C2,censys,IASL,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1326051": [
        {
            "ioc_value": "https://isomicrotich.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:51",
            "last_seen_utc": "2026-07-21 17:44:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.7,Alpha",
            "anonymous": 0,
            "reporter": "spamhaus"
        }
    ],
    "1326052": [
        {
            "ioc_value": "https://rilomenifis.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:50",
            "last_seen_utc": "2026-07-21 17:34:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.7,Alpha",
            "anonymous": 0,
            "reporter": "spamhaus"
        }
    ],
    "1321901": [
        {
            "ioc_value": "64.23.213.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-09-07 16:01:45",
            "last_seen_utc": "2026-07-21 17:45:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.23.213.61",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1317376": [
        {
            "ioc_value": "https://pikchestop.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-07-21 17:44:25",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": 0,
            "reporter": "johannes"
        }
    ],
    "1317377": [
        {
            "ioc_value": "https://indepahote.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-07-21 17:35:24",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": 0,
            "reporter": "johannes"
        }
    ],
    "1317070": [
        {
            "ioc_value": "86.53.241.21:447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-29 00:01:11",
            "last_seen_utc": "2026-07-21 17:45:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/86.53.241.21",
            "tags": "AS3257,C2,censys,GTT-BACKBONE,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1314694": [
        {
            "ioc_value": "83.229.120.73:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-08-22 10:04:33",
            "last_seen_utc": "2026-07-21 17:45:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.120.73",
            "tags": "AS139659,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1313657": [
        {
            "ioc_value": "193.19.242.55:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-19 19:55:59",
            "last_seen_utc": "2026-07-21 17:44:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.19.242.55",
            "tags": "AS35319,AS48964,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1313194": [
        {
            "ioc_value": "110.13.35.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-18 14:04:40",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/110.13.35.37",
            "tags": "AS9318,C2,censys,RAT,SKB-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1312402": [
        {
            "ioc_value": "20.188.119.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-08-17 14:04:20",
            "last_seen_utc": "2026-07-21 17:44:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.188.119.195",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1312338": [
        {
            "ioc_value": "210.249.114.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-17 02:04:24",
            "last_seen_utc": "2026-07-21 17:44:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.154",
            "tags": "AS2516,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1312117": [
        {
            "ioc_value": "20.188.119.195:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-08-16 14:02:33",
            "last_seen_utc": "2026-07-21 17:44:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.188.119.195",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1311619": [
        {
            "ioc_value": "23.24.178.35:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-15 22:40:43",
            "last_seen_utc": "2026-07-21 17:45:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.24.178.35",
            "tags": "AS20214,C2,censys,COMCAST-20214,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1309755": [
        {
            "ioc_value": "146.70.158.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-08-11 21:50:57",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.158.198",
            "tags": "AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1296480": [
        {
            "ioc_value": "43.138.0.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-07-09 19:05:36",
            "last_seen_utc": "2026-07-21 17:42:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1296006": [
        {
            "ioc_value": "213.149.181.121:469",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-09 06:51:58",
            "last_seen_utc": "2026-07-21 17:44:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/213.149.181.121",
            "tags": "CYTA-NETWORK Internet Services,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1296003": [
        {
            "ioc_value": "20.105.139.205:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-09 06:51:48",
            "last_seen_utc": "2026-07-21 17:44:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.105.139.205",
            "tags": "MICROSOFT-CORP-MSN-AS-BLOCK,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1295752": [
        {
            "ioc_value": "210.249.114.153:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-08 06:51:14",
            "last_seen_utc": "2026-07-21 17:44:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.153",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1295405": [
        {
            "ioc_value": "23.24.178.33:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-07 03:48:38",
            "last_seen_utc": "2026-07-21 17:45:05",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.24.178.33",
            "tags": "COMCAST-7922,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1292877": [
        {
            "ioc_value": "210.249.114.154:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-03 06:52:14",
            "last_seen_utc": "2026-07-21 17:44:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.154",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291417": [
        {
            "ioc_value": "198.244.197.118:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:40",
            "last_seen_utc": "2026-07-21 17:44:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/198.244.197.118",
            "tags": "NetSupportRAT,OVH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291414": [
        {
            "ioc_value": "206.210.123.104:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:30",
            "last_seen_utc": "2026-07-21 17:44:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.210.123.104",
            "tags": "IASL,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291411": [
        {
            "ioc_value": "61.96.204.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:19",
            "last_seen_utc": "2026-07-21 17:45:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/61.96.204.117",
            "tags": "DREAMX-AS DREAMLINE CO.,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291410": [
        {
            "ioc_value": "185.23.192.33:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:15",
            "last_seen_utc": "2026-07-21 17:44:06",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.23.192.33",
            "tags": "NetSupportRAT,WINET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291409": [
        {
            "ioc_value": "2.136.235.200:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:10",
            "last_seen_utc": "2026-07-21 17:44:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/2.136.235.200",
            "tags": "NetSupportRAT,TELEFONICA_DE_ESPANA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291397": [
        {
            "ioc_value": "210.249.114.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:04:31",
            "last_seen_utc": "2026-07-21 17:44:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.153",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291297": [
        {
            "ioc_value": "londopas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:04",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1291296": [
        {
            "ioc_value": "berjimek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:03",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1291010": [
        {
            "ioc_value": "www.qianxinnbplus.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 10:13:19",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HKLNIL Landui Cloud ComputingHK Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1289423": [
        {
            "ioc_value": "152.32.202.240:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-26 17:07:43",
            "last_seen_utc": "2026-07-21 17:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1287670": [
        {
            "ioc_value": "91.199.154.103:34211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-06-22 06:45:48",
            "last_seen_utc": "2026-07-21 17:45:51",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "Sliver",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1285430": [
        {
            "ioc_value": "ieee-ecce.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285431": [
        {
            "ioc_value": "kauzalvip.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285432": [
        {
            "ioc_value": "nakit-yok.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285433": [
        {
            "ioc_value": "nathanhr.services",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1283657": [
        {
            "ioc_value": "support.whatsappsignup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-10 09:26:05",
            "last_seen_utc": "2026-07-21 17:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,PEG TECH INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1278385": [
        {
            "ioc_value": "static.nvidiadrives.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 19:42:15",
            "last_seen_utc": "2026-07-21 17:42:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1278172": [
        {
            "ioc_value": "119.91.208.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 08:38:33",
            "last_seen_utc": "2026-07-21 17:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1277937": [
        {
            "ioc_value": "47.109.69.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-01 13:08:25",
            "last_seen_utc": "2026-07-21 17:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1277588": [
        {
            "ioc_value": "101.43.32.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-31 12:57:33",
            "last_seen_utc": "2026-07-21 17:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276810": [
        {
            "ioc_value": "asterchildrenshoes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:53:46",
            "last_seen_utc": "2026-07-21 17:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BL Networks,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276802": [
        {
            "ioc_value": "124.223.41.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:52:55",
            "last_seen_utc": "2026-07-21 17:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276786": [
        {
            "ioc_value": "8.210.9.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 10:17:04",
            "last_seen_utc": "2026-07-21 17:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,CobaltStrike,cs-watermark-0",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276244": [
        {
            "ioc_value": "https://65.108.55.55:9000/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-05-27 16:13:21",
            "last_seen_utc": "2026-07-21 17:10:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1275630": [
        {
            "ioc_value": "pt-security.ru",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-25 22:18:29",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MTW-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1274726": [
        {
            "ioc_value": "47.92.127.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-24 13:15:35",
            "last_seen_utc": "2026-07-21 17:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273973": [
        {
            "ioc_value": "119.28.83.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-22 11:06:58",
            "last_seen_utc": "2026-07-21 17:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273882": [
        {
            "ioc_value": "51.15.16.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2024-05-21 18:51:48",
            "last_seen_utc": "2026-07-21 17:45:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.16.116",
            "tags": "Online SAS,SocGholish",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273456": [
        {
            "ioc_value": "139.159.203.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-21 12:53:29",
            "last_seen_utc": "2026-07-21 17:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,HWCSNET Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1272788": [
        {
            "ioc_value": "123.58.198.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-19 07:56:13",
            "last_seen_utc": "2026-07-21 17:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271699": [
        {
            "ioc_value": "vip8806.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-16 07:53:43",
            "last_seen_utc": "2026-07-21 17:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS LLC,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271605": [
        {
            "ioc_value": "blmdiscount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-07-21 17:42:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271606": [
        {
            "ioc_value": "91.238.181.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-07-21 17:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271347": [
        {
            "ioc_value": "118.25.85.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 15:33:07",
            "last_seen_utc": "2026-07-21 17:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.85.198",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-305419896,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1270684": [
        {
            "ioc_value": "64.7.198.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-14 10:14:21",
            "last_seen_utc": "2026-07-21 17:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BLNWX,CobaltStrike,cs-watermark-426352781",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269727": [
        {
            "ioc_value": "113.31.105.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:31",
            "last_seen_utc": "2026-07-21 17:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "China Telecom (Group),CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269724": [
        {
            "ioc_value": "185.196.8.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:10",
            "last_seen_utc": "2026-07-21 17:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269723": [
        {
            "ioc_value": "action-winds.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:09",
            "last_seen_utc": "2026-07-21 17:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269721": [
        {
            "ioc_value": "microstar.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:08",
            "last_seen_utc": "2026-07-21 17:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1267565": [
        {
            "ioc_value": "113.31.106.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 10:14:57",
            "last_seen_utc": "2026-07-21 17:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHINANET-SHANGHAI-MAN China Telecom Group,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1267486": [
        {
            "ioc_value": "111.230.12.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 07:48:08",
            "last_seen_utc": "2026-07-21 17:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.230.12.238",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1266959": [
        {
            "ioc_value": "134.122.130.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-06 12:49:25",
            "last_seen_utc": "2026-07-21 17:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1263972": [
        {
            "ioc_value": "134.122.130.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-29 12:51:26",
            "last_seen_utc": "2026-07-21 17:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1263319": [
        {
            "ioc_value": "124.71.106.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-28 17:59:06",
            "last_seen_utc": "2026-07-21 17:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1262666": [
        {
            "ioc_value": "118.31.116.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-26 12:59:31",
            "last_seen_utc": "2026-07-21 17:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1262568": [
        {
            "ioc_value": "8.134.11.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-25 22:12:56",
            "last_seen_utc": "2026-07-21 17:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1261845": [
        {
            "ioc_value": "165.227.108.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-24 13:08:20",
            "last_seen_utc": "2026-07-21 17:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-970865301,DigitalOcean LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1260893": [
        {
            "ioc_value": "80.66.75.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:49",
            "last_seen_utc": "2026-07-21 17:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GRIZ-INET-SERVICE",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1260890": [
        {
            "ioc_value": "101.201.54.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:43",
            "last_seen_utc": "2026-07-21 17:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1259796": [
        {
            "ioc_value": "62.204.41.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-21 15:09:17",
            "last_seen_utc": "2026-07-21 17:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.204.41.11",
            "tags": "AS59425,c2,censys,CobaltStrike,cs-watermark-1580103824,HORIZONMSK-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1255726": [
        {
            "ioc_value": "124.220.6.158:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-11 10:15:16",
            "last_seen_utc": "2026-07-21 17:46:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&virtual_hosts=EXCLUDE&q=%28services.software.uniform_resource_identifier%3A+%60cpe%3A2.3%3Aa%3Afortra%3Acobalt_strike%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%60%29+and+autonomous_system.name%3D%60TENCENT-NET-AP+Shenzhen+Tencent+Computer+Systems+Company+Limited%60",
            "tags": "AS45090,c2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1255727": [
        {
            "ioc_value": "124.220.6.158:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-11 10:15:15",
            "last_seen_utc": "2026-07-21 17:46:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&virtual_hosts=EXCLUDE&q=%28services.software.uniform_resource_identifier%3A+%60cpe%3A2.3%3Aa%3Afortra%3Acobalt_strike%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%60%29+and+autonomous_system.name%3D%60TENCENT-NET-AP+Shenzhen+Tencent+Computer+Systems+Company+Limited%60",
            "tags": "AS45090,c2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1252542": [
        {
            "ioc_value": "185.196.10.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-02 10:17:26",
            "last_seen_utc": "2026-07-21 17:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,SIMPLECARRIER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1250157": [
        {
            "ioc_value": "soneypaly.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 14:42:02",
            "last_seen_utc": "2026-07-21 17:42:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1249815": [
        {
            "ioc_value": "47.105.69.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 07:57:29",
            "last_seen_utc": "2026-07-21 17:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1248363": [
        {
            "ioc_value": "https://titnovacrion.top/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.unidentified_111",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Unidentified 111 (Latrodectus)",
            "first_seen_utc": "2024-03-22 19:47:18",
            "last_seen_utc": "2026-07-21 17:47:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "1245476": [
        {
            "ioc_value": "47.100.87.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-09 20:54:40",
            "last_seen_utc": "2026-07-21 17:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1244781": [
        {
            "ioc_value": "194.165.16.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 20:55:37",
            "last_seen_utc": "2026-07-21 17:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1244726": [
        {
            "ioc_value": "googlesupportacc.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 10:12:56",
            "last_seen_utc": "2026-07-21 17:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASSEFLOW,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1241656": [
        {
            "ioc_value": "121.43.55.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-21 22:13:19",
            "last_seen_utc": "2026-07-21 17:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1240949": [
        {
            "ioc_value": "95.179.137.233:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-19 15:29:52",
            "last_seen_utc": "2026-07-21 17:46:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890,The Constant Company LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1237621": [
        {
            "ioc_value": "qw.regcssv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-07 10:12:21",
            "last_seen_utc": "2026-07-21 17:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,FLYSERVERS-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1236577": [
        {
            "ioc_value": "ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-03 19:38:15",
            "last_seen_utc": "2026-07-21 17:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.22.66.152+ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "tags": "AMAZON-02,AS16509,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1236276": [
        {
            "ioc_value": "20.56.70.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-02 06:00:13",
            "last_seen_utc": "2026-07-21 17:42:38",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1235332": [
        {
            "ioc_value": "www.louangelwolf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-30 06:20:34",
            "last_seen_utc": "2026-07-21 17:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1551089073",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234854": [
        {
            "ioc_value": "kkudndkwatnfevcaqeefytqnh.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:18",
            "last_seen_utc": "2026-07-21 17:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234859": [
        {
            "ioc_value": "whxzqkbbtzvdyxdeseoiyujzs.co",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-07-21 17:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234860": [
        {
            "ioc_value": "uohhunkmnfhbimtagizqgwpmv.to",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-07-21 17:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234928": [
        {
            "ioc_value": "114.55.133.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:40",
            "last_seen_utc": "2026-07-21 17:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/114.55.133.151",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1234909": [
        {
            "ioc_value": "117.72.39.83:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:20",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1234304": [
        {
            "ioc_value": "38.147.189.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2024-01-24 18:49:24",
            "last_seen_utc": "2026-07-21 17:45:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.147.189.199",
            "tags": "Pupy RAT,XNNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1233919": [
        {
            "ioc_value": "www.idn15r69vh3fwhzclfoeuaoy.today",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-23 13:53:21",
            "last_seen_utc": "2026-07-21 17:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.219.229.99+www.idn15r69vh3fwhzclfoeuaoy.today",
            "tags": "AS45102,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1231802": [
        {
            "ioc_value": "164-90-169-184.cprapid.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-18 13:44:13",
            "last_seen_utc": "2026-07-21 17:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.169.184+164-90-169-184.cprapid.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1230963": [
        {
            "ioc_value": "https://65.21.187.53/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-01-16 08:13:32",
            "last_seen_utc": "2026-07-21 17:10:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1230909": [
        {
            "ioc_value": "lz4.tiktok123.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-15 16:27:00",
            "last_seen_utc": "2026-07-21 17:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230478": [
        {
            "ioc_value": "164.92.79.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-13 06:47:25",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.79.49",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1230429": [
        {
            "ioc_value": "site.dev.hutechweb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-12 18:36:24",
            "last_seen_utc": "2026-07-21 17:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230076": [
        {
            "ioc_value": "ns1.fiducaire.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-07-21 17:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230077": [
        {
            "ioc_value": "ns1.asurances.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-07-21 17:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230078": [
        {
            "ioc_value": "sagsblog.telinduslab.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-07-21 17:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230079": [
        {
            "ioc_value": "ns1.jocelynhealth.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-07-21 17:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1590258876",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229840": [
        {
            "ioc_value": "ns.emaratalyoum.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-10 10:50:13",
            "last_seen_utc": "2026-07-21 17:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1727139162",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229817": [
        {
            "ioc_value": "161.35.239.147:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-10 06:48:20",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.239.147",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1229694": [
        {
            "ioc_value": "emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:19",
            "last_seen_utc": "2026-07-21 17:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229695": [
        {
            "ioc_value": "ns1.emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:17",
            "last_seen_utc": "2026-07-21 17:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229661": [
        {
            "ioc_value": "111.92.243.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 08:45:29",
            "last_seen_utc": "2026-07-21 17:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HFTCL-AS-AP High Family Technology Co. Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1229599": [
        {
            "ioc_value": "82.65.19.134:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2024-01-09 05:30:32",
            "last_seen_utc": "2026-07-21 17:45:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/82.65.19.134",
            "tags": "C2,censys,PROXAD,RAT",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1228458": [
        {
            "ioc_value": "139.9.62.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-05 21:31:13",
            "last_seen_utc": "2026-07-21 17:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.9.62.19",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1228181": [
        {
            "ioc_value": "101.133.225.51:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-05 14:48:41",
            "last_seen_utc": "2026-07-21 17:46:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.133.225.51",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1228033": [
        {
            "ioc_value": "143.110.151.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-01-05 06:45:36",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/143.110.151.209",
            "tags": "DIGITALOCEAN-ASN,Sliver",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1227297": [
        {
            "ioc_value": "106.54.209.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-02 14:31:12",
            "last_seen_utc": "2026-07-21 17:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/106.54.209.36",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1226488": [
        {
            "ioc_value": "astra4512.startdedicated.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-30 11:33:25",
            "last_seen_utc": "2026-07-21 17:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GD-EMEA-DC-SXB1",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1224105": [
        {
            "ioc_value": "cs.xcb.one",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-27 22:15:29",
            "last_seen_utc": "2026-07-21 17:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1223678": [
        {
            "ioc_value": "8.140.203.92:7817",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-12-26 06:46:27",
            "last_seen_utc": "2026-07-21 17:45:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.140.203.92",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1221451": [
        {
            "ioc_value": "62.234.27.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-18 05:00:11",
            "last_seen_utc": "2026-07-21 17:42:39",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1213636": [
        {
            "ioc_value": "MicrosoftSyst3m.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-16 22:12:14",
            "last_seen_utc": "2026-07-21 17:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1213211": [
        {
            "ioc_value": "117.72.39.83:33333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-15 18:59:31",
            "last_seen_utc": "2026-07-21 17:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1209246": [
        {
            "ioc_value": "unzip2.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-04 08:45:50",
            "last_seen_utc": "2026-07-21 17:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1205166": [
        {
            "ioc_value": "techsyscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-07-21 17:42:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1205167": [
        {
            "ioc_value": "yify88.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-07-21 17:42:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1205164": [
        {
            "ioc_value": "americcorp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:02",
            "last_seen_utc": "2026-07-21 17:42:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1204685": [
        {
            "ioc_value": "tech-guard.vguard.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-22 20:04:09",
            "last_seen_utc": "2026-07-21 17:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/44.204.120.159+tech-guard.vguard.tech",
            "tags": "AMAZON-AES,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1202628": [
        {
            "ioc_value": "ns.manager.moonlighter.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-15 20:24:37",
            "last_seen_utc": "2026-07-21 17:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1893164628,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1201144": [
        {
            "ioc_value": "101.34.222.38:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.viper_rat",
            "malware_alias": null,
            "malware_printable": "Viper RAT",
            "first_seen_utc": "2023-11-09 17:50:07",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.34.222.38",
            "tags": "C2,censys,RAT",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1200343": [
        {
            "ioc_value": "dev.theokanegroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-09 04:06:44",
            "last_seen_utc": "2026-07-21 17:42:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/134.209.164.110+dev.theokanegroup.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1199545": [
        {
            "ioc_value": "38.54.115.233:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-06 21:04:29",
            "last_seen_utc": "2026-07-21 17:46:27",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1199506": [
        {
            "ioc_value": "bwyb.love",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-06 18:07:30",
            "last_seen_utc": "2026-07-21 17:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.242.158.114+bwyb.love",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1199160": [
        {
            "ioc_value": "www.sunwu.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-05 15:00:42",
            "last_seen_utc": "2026-07-21 17:42:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/82.157.149.194+www.sunwu.world",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1192255": [
        {
            "ioc_value": "139.155.148.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-24 10:39:59",
            "last_seen_utc": "2026-07-21 17:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.155.148.131",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1191379": [
        {
            "ioc_value": "www.goocoinorg.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-20 21:57:56",
            "last_seen_utc": "2026-07-21 17:42:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+www.goocoinorg.com&ref=threatfox",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1189545": [
        {
            "ioc_value": "airlinesapp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-16 08:49:32",
            "last_seen_utc": "2026-07-21 17:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,DigitalOcean LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1188605": [
        {
            "ioc_value": "lectricelfuel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-13 19:49:34",
            "last_seen_utc": "2026-07-21 17:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+lectricelfuel.com&ref=threatfox",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1187879": [
        {
            "ioc_value": "143.110.151.209:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2023-10-12 01:35:38",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/143.110.151.209",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1187462": [
        {
            "ioc_value": "117.72.8.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-11 12:59:56",
            "last_seen_utc": "2026-07-21 17:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.8.192",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1180378": [
        {
            "ioc_value": "111.229.187.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-30 16:12:13",
            "last_seen_utc": "2026-07-21 17:42:35",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1165497": [
        {
            "ioc_value": "igo0gle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-21 09:29:08",
            "last_seen_utc": "2026-07-21 17:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-ALVIVA,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1165172": [
        {
            "ioc_value": "8.217.217.243:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-09-20 18:47:20",
            "last_seen_utc": "2026-07-21 17:45:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.217.217.243",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1155921": [
        {
            "ioc_value": "csxv.sec.cm",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-09 20:06:55",
            "last_seen_utc": "2026-07-21 17:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHANGWAY-AS,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1155319": [
        {
            "ioc_value": "43.136.38.59:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-05 21:52:59",
            "last_seen_utc": "2026-07-21 17:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1152278": [
        {
            "ioc_value": "withoutedge.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:05",
            "last_seen_utc": "2026-07-21 17:42:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152277": [
        {
            "ioc_value": "thconnewfoot.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:04",
            "last_seen_utc": "2026-07-21 17:42:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152274": [
        {
            "ioc_value": "caixas.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-07-21 17:42:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152275": [
        {
            "ioc_value": "ddllsearch.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-07-21 17:42:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152276": [
        {
            "ioc_value": "gepcash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-07-21 17:42:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152272": [
        {
            "ioc_value": "amazonclouds.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-07-21 17:42:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152273": [
        {
            "ioc_value": "amur-city.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-07-21 17:42:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1151932": [
        {
            "ioc_value": "77.74.208.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2023-08-25 06:48:54",
            "last_seen_utc": "2026-07-21 17:45:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/77.74.208.123",
            "tags": "BRETAGNETELECOM,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1151693": [
        {
            "ioc_value": "43.153.222.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-23 11:56:21",
            "last_seen_utc": "2026-07-21 17:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1149951": [
        {
            "ioc_value": "164.92.145.128:7810",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2023-08-14 18:46:43",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.145.128",
            "tags": "Brute Ratel C4,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1149946": [
        {
            "ioc_value": "pctor.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:05",
            "last_seen_utc": "2026-07-21 17:42:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1149945": [
        {
            "ioc_value": "tehomics.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:04",
            "last_seen_utc": "2026-07-21 17:42:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1149944": [
        {
            "ioc_value": "instant-healthonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:03",
            "last_seen_utc": "2026-07-21 17:42:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1148731": [
        {
            "ioc_value": "stratpringl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-05 14:38:23",
            "last_seen_utc": "2026-07-21 17:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,PINDC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1148487": [
        {
            "ioc_value": "onlinetechdesk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-04 11:01:52",
            "last_seen_utc": "2026-07-21 17:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike,cs-watermark-587247372",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146843": [
        {
            "ioc_value": "harmonyshoused.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:25:44",
            "last_seen_utc": "2026-07-21 17:42:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146834": [
        {
            "ioc_value": "api.office-updates.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:24:41",
            "last_seen_utc": "2026-07-21 17:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-494165167,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146619": [
        {
            "ioc_value": "mkbkygbgwcdc.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-02 10:24:58",
            "last_seen_utc": "2026-07-21 17:42:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,KAOPU-HK Kaopu Cloud HK Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1140114": [
        {
            "ioc_value": "tcessolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-25 10:17:22",
            "last_seen_utc": "2026-07-21 17:42:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS202973,CobaltStrike,cs-watermark-587247372",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1138196": [
        {
            "ioc_value": "rw1.sentrysource.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-15 12:48:31",
            "last_seen_utc": "2026-07-21 17:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-93937751,ROGERS-COMMUNICATIONS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1135804": [
        {
            "ioc_value": "pedagogists.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:02",
            "last_seen_utc": "2026-07-21 17:42:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1135803": [
        {
            "ioc_value": "cdnsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:01",
            "last_seen_utc": "2026-07-21 17:42:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1134787": [
        {
            "ioc_value": "1.15.248.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-28 22:51:22",
            "last_seen_utc": "2026-07-21 17:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1134128": [
        {
            "ioc_value": "check1.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:12:17",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1134127": [
        {
            "ioc_value": "check.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:11:33",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1133505": [
        {
            "ioc_value": "usadevgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-22 17:12:29",
            "last_seen_utc": "2026-07-21 17:42:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,WAICORE-TRANSIT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1132563": [
        {
            "ioc_value": "103.27.186.185:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-06-20 18:49:40",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.27.186.185",
            "tags": "Pupy RAT,SNL-HK Starry Network Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1128165": [
        {
            "ioc_value": "heastings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-11 22:26:06",
            "last_seen_utc": "2026-07-21 17:42:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,M247",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1127715": [
        {
            "ioc_value": "unitechdb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:05",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127713": [
        {
            "ioc_value": "cornptia.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127714": [
        {
            "ioc_value": "eyefinancemonitor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127447": [
        {
            "ioc_value": "surplusofer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-08 16:27:41",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122048": [
        {
            "ioc_value": "dianqi2.dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:42:02",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122047": [
        {
            "ioc_value": "dianqi1.dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:46",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122046": [
        {
            "ioc_value": "dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:31",
            "last_seen_utc": "2026-07-21 17:45:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122045": [
        {
            "ioc_value": "dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:10",
            "last_seen_utc": "2026-07-21 17:45:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122043": [
        {
            "ioc_value": "ns1.bewiser.at",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:39:57",
            "last_seen_utc": "2026-07-21 17:45:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890,The Constant Company LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1121460": [
        {
            "ioc_value": "update.microsoftapply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:35:48",
            "last_seen_utc": "2026-07-21 17:46:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-Not Found,DediPath",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1120772": [
        {
            "ioc_value": "australiansuper.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-23 12:37:36",
            "last_seen_utc": "2026-07-21 17:42:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike,cs-watermark-348901740",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1116637": [
        {
            "ioc_value": "sheersdesigns.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:03",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1116636": [
        {
            "ioc_value": "artmicrodesign.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:02",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1114522": [
        {
            "ioc_value": "103.27.186.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-05-10 18:49:37",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.27.186.185",
            "tags": "Pupy RAT,SNL-HK Starry Network Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1112839": [
        {
            "ioc_value": "situotech.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-06 16:13:31",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,HARMONYHOSTING-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110863": [
        {
            "ioc_value": "39.106.36.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:43",
            "last_seen_utc": "2026-07-21 17:45:14",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.106.36.96",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110862": [
        {
            "ioc_value": "36.95.131.171:9091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:41",
            "last_seen_utc": "2026-07-21 17:45:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/36.95.131.171",
            "tags": "Deimos,TELKOMNET-AS-AP PT Telekomunikasi Indonesia",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110860": [
        {
            "ioc_value": "18.162.155.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:35",
            "last_seen_utc": "2026-07-21 17:43:57",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.162.155.202",
            "tags": "AMAZON-02,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110859": [
        {
            "ioc_value": "8.218.26.114:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:33",
            "last_seen_utc": "2026-07-21 17:45:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.218.26.114",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1106335": [
        {
            "ioc_value": "maboloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1106336": [
        {
            "ioc_value": "matong.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1105988": [
        {
            "ioc_value": "qw.sveexec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-21 10:20:17",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1103771": [
        {
            "ioc_value": "77.242.250.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-15 12:28:52",
            "last_seen_utc": "2026-07-21 17:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1416875320",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1102558": [
        {
            "ioc_value": "lls-rs.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-12 09:02:56",
            "last_seen_utc": "2026-07-21 17:42:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,PROSPERO-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1096685": [
        {
            "ioc_value": "iony.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096686": [
        {
            "ioc_value": "office36o.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096683": [
        {
            "ioc_value": "feyrijavac.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096684": [
        {
            "ioc_value": "fidelyus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1095276": [
        {
            "ioc_value": "jacketsupport.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 22:27:30",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1095042": [
        {
            "ioc_value": "duckducklive.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 04:51:21",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/b5da1db6d69f2f872e603beb0f121c68f3320ed33a0c9835bfc1a931d177c947",
            "tags": "391144938,Beacon,Cobalt Strike,CobaltStrike",
            "anonymous": 0,
            "reporter": "AndreGironda"
        }
    ],
    "1094484": [
        {
            "ioc_value": "louvree.abudhabe.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-28 15:52:23",
            "last_seen_utc": "2026-07-21 17:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1826426664,EMIRATES-INTERNET Emirates Internet",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1092077": [
        {
            "ioc_value": "jquerymaingame.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092078": [
        {
            "ioc_value": "mail-my-account.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092079": [
        {
            "ioc_value": "my-accounts-gooogle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092080": [
        {
            "ioc_value": "pegistrationads.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092075": [
        {
            "ioc_value": "eaglehardwares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092076": [
        {
            "ioc_value": "information.baby",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092009": [
        {
            "ioc_value": "moviegallerys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 13:36:29",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091575": [
        {
            "ioc_value": "acroserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 22:40:17",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091535": [
        {
            "ioc_value": "atechniques.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 19:45:49",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091454": [
        {
            "ioc_value": "winsatoom.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 13:33:15",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-668694132",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1087542": [
        {
            "ioc_value": "devoinnanote.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-13 04:47:12",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-2130772225,SHARKTECH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082976": [
        {
            "ioc_value": "ponzinivek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-07-21 17:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082977": [
        {
            "ioc_value": "ruplearben.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-07-21 17:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082978": [
        {
            "ioc_value": "talonbilling.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-07-21 17:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082979": [
        {
            "ioc_value": "gorillagaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-07-21 17:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082980": [
        {
            "ioc_value": "chanimoblie.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-07-21 17:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082871": [
        {
            "ioc_value": "kbnexc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:02",
            "last_seen_utc": "2026-07-21 17:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082870": [
        {
            "ioc_value": "jquerysslx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:01",
            "last_seen_utc": "2026-07-21 17:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082838": [
        {
            "ioc_value": "e-servicesolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 13:15:07",
            "last_seen_utc": "2026-07-21 17:42:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA GROUP Ltd,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082591": [
        {
            "ioc_value": "devsecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-24 02:30:56",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082417": [
        {
            "ioc_value": "www.vmware.rest",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-23 13:06:07",
            "last_seen_utc": "2026-07-21 17:42:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1081018": [
        {
            "ioc_value": "galspost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-17 18:25:01",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1101991775,Microsoft Corporation",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1080735": [
        {
            "ioc_value": "imvcatool.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-16 14:54:22",
            "last_seen_utc": "2026-07-21 17:42:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1078198": [
        {
            "ioc_value": "aspnetcenter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 19:39:46",
            "last_seen_utc": "2026-07-21 17:42:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Web Gostaran Bandar Company PJS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1078172": [
        {
            "ioc_value": "audelr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078173": [
        {
            "ioc_value": "csou.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078174": [
        {
            "ioc_value": "integrated-security.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078175": [
        {
            "ioc_value": "uranustechsolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078062": [
        {
            "ioc_value": "getsafeblog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-03 17:24:39",
            "last_seen_utc": "2026-07-21 17:42:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1076907": [
        {
            "ioc_value": "qw.svcshosvt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:40:26",
            "last_seen_utc": "2026-07-21 17:42:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1076896": [
        {
            "ioc_value": "nxsimdevelop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:39:18",
            "last_seen_utc": "2026-07-21 17:42:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075651": [
        {
            "ioc_value": "appdevtechnology.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-01 02:21:19",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075540": [
        {
            "ioc_value": "dbx.formsift.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-31 15:09:13",
            "last_seen_utc": "2026-07-21 17:42:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075020": [
        {
            "ioc_value": "devcloudpro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-29 11:29:55",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1074894": [
        {
            "ioc_value": "164.90.158.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:40:24",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.158.199",
            "tags": "DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1074890": [
        {
            "ioc_value": "145.131.8.169:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:40:10",
            "last_seen_utc": "2026-07-20 18:43:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/145.131.8.169",
            "tags": "Mythic,SENTIA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1074144": [
        {
            "ioc_value": "support-wellsfargovis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:03",
            "last_seen_utc": "2026-07-21 17:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074141": [
        {
            "ioc_value": "recoverporta1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074142": [
        {
            "ioc_value": "recoverportal2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074143": [
        {
            "ioc_value": "recoveryweb2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1073670": [
        {
            "ioc_value": "vd-ntds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-23 20:33:42",
            "last_seen_utc": "2026-07-21 17:42:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PROSPERO-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1070164": [
        {
            "ioc_value": "hnsxpharm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-07-21 17:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070165": [
        {
            "ioc_value": "myjqueryss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-07-21 17:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070167": [
        {
            "ioc_value": "telusmobility-billed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-07-21 17:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070168": [
        {
            "ioc_value": "thenbkgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-07-21 17:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070137": [
        {
            "ioc_value": "avdev.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 11:23:14",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069980": [
        {
            "ioc_value": "qw.execsvct.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 19:53:20",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069895": [
        {
            "ioc_value": "azurecloudfire.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 14:15:53",
            "last_seen_utc": "2026-07-21 17:42:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ITRESHENIYA-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069868": [
        {
            "ioc_value": "goupdatemic.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 11:23:42",
            "last_seen_utc": "2026-07-21 17:42:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GOOGLE",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069579": [
        {
            "ioc_value": "mwg-update.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-18 02:29:29",
            "last_seen_utc": "2026-07-21 17:42:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068206": [
        {
            "ioc_value": "goodsport2023.win",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-13 17:37:32",
            "last_seen_utc": "2026-07-21 17:42:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,VOM",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068079": [
        {
            "ioc_value": "blackandwhiteshoose.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 21:56:23",
            "last_seen_utc": "2026-07-21 17:42:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068045": [
        {
            "ioc_value": "qw.svcrencst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 20:55:06",
            "last_seen_utc": "2026-07-21 17:42:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067954": [
        {
            "ioc_value": "realsecuritystore.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 14:45:18",
            "last_seen_utc": "2026-07-21 17:42:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067924": [
        {
            "ioc_value": "fixx.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 13:04:56",
            "last_seen_utc": "2026-07-21 17:42:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SNEL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067646": [
        {
            "ioc_value": "allowedcloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-11 10:59:45",
            "last_seen_utc": "2026-07-21 17:42:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HIVELOCITY Inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064196": [
        {
            "ioc_value": "freegaysnews.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 19:48:39",
            "last_seen_utc": "2026-07-21 17:42:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064176": [
        {
            "ioc_value": "topgamenetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 18:58:09",
            "last_seen_utc": "2026-07-21 17:42:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064173": [
        {
            "ioc_value": "zfuxwvouqvnttpsrxe.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 16:21:02",
            "last_seen_utc": "2026-07-21 17:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064075": [
        {
            "ioc_value": "cloudyspaces.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064076": [
        {
            "ioc_value": "666621.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064069": [
        {
            "ioc_value": "144.217.207.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064070": [
        {
            "ioc_value": "allsdone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064071": [
        {
            "ioc_value": "ipsandwich.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064072": [
        {
            "ioc_value": "cookieholder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064073": [
        {
            "ioc_value": "pingcheker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064074": [
        {
            "ioc_value": "wagonovk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064062": [
        {
            "ioc_value": "microsoftupdateassist.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064063": [
        {
            "ioc_value": "qvibova.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064064": [
        {
            "ioc_value": "cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064065": [
        {
            "ioc_value": "metalkost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064066": [
        {
            "ioc_value": "m7r4r2i2.stackpathcdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064067": [
        {
            "ioc_value": "online.cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064057": [
        {
            "ioc_value": "bartiba.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064058": [
        {
            "ioc_value": "varnart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064059": [
        {
            "ioc_value": "nsfdfdfdf.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064060": [
        {
            "ioc_value": "micorsoft.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064061": [
        {
            "ioc_value": "aigouing.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064046": [
        {
            "ioc_value": "ksplsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064047": [
        {
            "ioc_value": "lastinsuranceteam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064048": [
        {
            "ioc_value": "msdnsservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064049": [
        {
            "ioc_value": "securequoteme.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064050": [
        {
            "ioc_value": "techdevcorp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064051": [
        {
            "ioc_value": "syncorporation.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064052": [
        {
            "ioc_value": "visualstudioapp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064053": [
        {
            "ioc_value": "altreeservicellc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064054": [
        {
            "ioc_value": "discountshadesdirect.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064055": [
        {
            "ioc_value": "setechnowork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064056": [
        {
            "ioc_value": "technicollit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064038": [
        {
            "ioc_value": "shiyicaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064039": [
        {
            "ioc_value": "cdn-top.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064040": [
        {
            "ioc_value": "onesecondservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064041": [
        {
            "ioc_value": "vpnupdaters.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064042": [
        {
            "ioc_value": "rodinscoldly.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064043": [
        {
            "ioc_value": "antariscapital.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064044": [
        {
            "ioc_value": "ftwealthmgt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064045": [
        {
            "ioc_value": "iconiq-capitel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064031": [
        {
            "ioc_value": "asset-trades.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064032": [
        {
            "ioc_value": "telemetrin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064033": [
        {
            "ioc_value": "secupdate4win.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064034": [
        {
            "ioc_value": "cdn-start.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064035": [
        {
            "ioc_value": "capitalmanagementdata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064036": [
        {
            "ioc_value": "lawsolutions.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064024": [
        {
            "ioc_value": "diegomaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064025": [
        {
            "ioc_value": "dp-test1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064026": [
        {
            "ioc_value": "cloudkey.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064027": [
        {
            "ioc_value": "updatevpncitrix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064028": [
        {
            "ioc_value": "classgum.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064029": [
        {
            "ioc_value": "edgeupdater.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064030": [
        {
            "ioc_value": "gfcbm.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064016": [
        {
            "ioc_value": "barmnava.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064017": [
        {
            "ioc_value": "firewallwithadvancedserurity.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064018": [
        {
            "ioc_value": "lgbtqplusfriendlydomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064019": [
        {
            "ioc_value": "market-stats.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064020": [
        {
            "ioc_value": "apabfs.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064021": [
        {
            "ioc_value": "fziomerof.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064022": [
        {
            "ioc_value": "fserd.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064023": [
        {
            "ioc_value": "verofes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064015": [
        {
            "ioc_value": "postofficeltdc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:43",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064006": [
        {
            "ioc_value": "jarvcza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064007": [
        {
            "ioc_value": "teystyjeem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064008": [
        {
            "ioc_value": "faceupfinder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064009": [
        {
            "ioc_value": "costacancordia.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064010": [
        {
            "ioc_value": "lapsusareskids.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064011": [
        {
            "ioc_value": "msupdater.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064012": [
        {
            "ioc_value": "dwordname.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064013": [
        {
            "ioc_value": "trademot.finance",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064014": [
        {
            "ioc_value": "agreminj.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063998": [
        {
            "ioc_value": "exchangeallltd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063999": [
        {
            "ioc_value": "guggenheimpartners-survey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064000": [
        {
            "ioc_value": "caresalonservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064001": [
        {
            "ioc_value": "just-findncall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064002": [
        {
            "ioc_value": "fluoxi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064003": [
        {
            "ioc_value": "buynet.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064004": [
        {
            "ioc_value": "everythingchecker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064005": [
        {
            "ioc_value": "dezword.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063995": [
        {
            "ioc_value": "goksearch.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063996": [
        {
            "ioc_value": "polyhaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063997": [
        {
            "ioc_value": "data-protection-test.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063992": [
        {
            "ioc_value": "update04.microsoft-essentials.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:39",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063991": [
        {
            "ioc_value": "akaluij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:38",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063989": [
        {
            "ioc_value": "43.129.7.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063990": [
        {
            "ioc_value": "82.156.241.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063985": [
        {
            "ioc_value": "donormix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063986": [
        {
            "ioc_value": "hardicki.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063987": [
        {
            "ioc_value": "stfconnect.onthewifi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063988": [
        {
            "ioc_value": "agsdef.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063978": [
        {
            "ioc_value": "observerinfo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063979": [
        {
            "ioc_value": "dehikz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063980": [
        {
            "ioc_value": "cocanewline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063981": [
        {
            "ioc_value": "rainqor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063982": [
        {
            "ioc_value": "axelkim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063983": [
        {
            "ioc_value": "azimurs.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063984": [
        {
            "ioc_value": "innovativesitecreations.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063972": [
        {
            "ioc_value": "creditscore.usbankcreditcards.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063975": [
        {
            "ioc_value": "megumin.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063976": [
        {
            "ioc_value": "loanhelp.support",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063977": [
        {
            "ioc_value": "volsecure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063966": [
        {
            "ioc_value": "domtern.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063968": [
        {
            "ioc_value": "drakr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063969": [
        {
            "ioc_value": "devcisco.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063971": [
        {
            "ioc_value": "web-news-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063963": [
        {
            "ioc_value": "bankafrika.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063964": [
        {
            "ioc_value": "mssfr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063965": [
        {
            "ioc_value": "edgekey.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063955": [
        {
            "ioc_value": "webyoutubeshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063956": [
        {
            "ioc_value": "extic.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063957": [
        {
            "ioc_value": "reykh.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063959": [
        {
            "ioc_value": "propertynewsclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063960": [
        {
            "ioc_value": "afindisc.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063961": [
        {
            "ioc_value": "propertyinfogroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063962": [
        {
            "ioc_value": "topnewscompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063950": [
        {
            "ioc_value": "baidenfree.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063951": [
        {
            "ioc_value": "directoryupdate.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063952": [
        {
            "ioc_value": "azmnetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063953": [
        {
            "ioc_value": "onevisioncommunications.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063954": [
        {
            "ioc_value": "campioni-imam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063943": [
        {
            "ioc_value": "serviceapp1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063944": [
        {
            "ioc_value": "softcloud.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063945": [
        {
            "ioc_value": "appmind.center",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063946": [
        {
            "ioc_value": "ms-data.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063947": [
        {
            "ioc_value": "oracleup.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063948": [
        {
            "ioc_value": "topinfocompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063949": [
        {
            "ioc_value": "blockchainstartups-crypto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063934": [
        {
            "ioc_value": "expresssmash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063935": [
        {
            "ioc_value": "vgroz.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063936": [
        {
            "ioc_value": "baidengop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063937": [
        {
            "ioc_value": "ofilopex.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063938": [
        {
            "ioc_value": "aabancaa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063939": [
        {
            "ioc_value": "shermango.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063940": [
        {
            "ioc_value": "nongxinyin.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063941": [
        {
            "ioc_value": "a6m1n.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063942": [
        {
            "ioc_value": "emailbox.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063926": [
        {
            "ioc_value": "wxtencent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063927": [
        {
            "ioc_value": "emergeno.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063928": [
        {
            "ioc_value": "browngreeer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063929": [
        {
            "ioc_value": "processdec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063931": [
        {
            "ioc_value": "sndm-sndm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063932": [
        {
            "ioc_value": "sinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063933": [
        {
            "ioc_value": "vinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063918": [
        {
            "ioc_value": "westtherr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063919": [
        {
            "ioc_value": "quickaccestwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063920": [
        {
            "ioc_value": "usgrim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063921": [
        {
            "ioc_value": "onelivemusicshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063922": [
        {
            "ioc_value": "zomerax.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063923": [
        {
            "ioc_value": "fsamon.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063924": [
        {
            "ioc_value": "sscimails.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063925": [
        {
            "ioc_value": "agentrecovery.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063909": [
        {
            "ioc_value": "entertainok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063910": [
        {
            "ioc_value": "jatafatuna.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063911": [
        {
            "ioc_value": "pluyk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063912": [
        {
            "ioc_value": "affinm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063913": [
        {
            "ioc_value": "gijoxupe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063914": [
        {
            "ioc_value": "vangshares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063915": [
        {
            "ioc_value": "fudupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063917": [
        {
            "ioc_value": "contemporaryto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063902": [
        {
            "ioc_value": "ziono.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063903": [
        {
            "ioc_value": "lolutow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063904": [
        {
            "ioc_value": "niht12.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063905": [
        {
            "ioc_value": "slfcorporate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063906": [
        {
            "ioc_value": "baidu-cdn-10.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063907": [
        {
            "ioc_value": "jandoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063908": [
        {
            "ioc_value": "casevor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063897": [
        {
            "ioc_value": "gotroops.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063898": [
        {
            "ioc_value": "wtxservice.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063899": [
        {
            "ioc_value": "xevayuhace.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063900": [
        {
            "ioc_value": "suppcat.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063901": [
        {
            "ioc_value": "softloadup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063889": [
        {
            "ioc_value": "asbetysh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063890": [
        {
            "ioc_value": "ascagliarinish.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063891": [
        {
            "ioc_value": "ascasdsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063892": [
        {
            "ioc_value": "aschamp79sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063893": [
        {
            "ioc_value": "aschnurmansh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063894": [
        {
            "ioc_value": "aseleeeksh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063895": [
        {
            "ioc_value": "asensvsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063880": [
        {
            "ioc_value": "artist2actresssh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063881": [
        {
            "ioc_value": "arturprikhodkosh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063882": [
        {
            "ioc_value": "arvin78sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063883": [
        {
            "ioc_value": "arvind567shahsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063884": [
        {
            "ioc_value": "arvindkkumsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063885": [
        {
            "ioc_value": "arvosash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063886": [
        {
            "ioc_value": "arwalsersh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063887": [
        {
            "ioc_value": "aryaarieash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063888": [
        {
            "ioc_value": "aryalalexsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063870": [
        {
            "ioc_value": "dovaxanil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063871": [
        {
            "ioc_value": "hehegahu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063872": [
        {
            "ioc_value": "agriculturemachineries.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063873": [
        {
            "ioc_value": "arhipenkolenagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063874": [
        {
            "ioc_value": "aritmiagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063875": [
        {
            "ioc_value": "artes911sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063876": [
        {
            "ioc_value": "arthas89sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063877": [
        {
            "ioc_value": "arthurstevens62sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063878": [
        {
            "ioc_value": "arthurtaylor13sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063879": [
        {
            "ioc_value": "artis214sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-07-21 17:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063864": [
        {
            "ioc_value": "zipo-cons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063865": [
        {
            "ioc_value": "fazehotafa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063866": [
        {
            "ioc_value": "zendriol.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063867": [
        {
            "ioc_value": "sezezapa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063868": [
        {
            "ioc_value": "sorekipe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063869": [
        {
            "ioc_value": "zezinuwe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063858": [
        {
            "ioc_value": "shrekf.art",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063859": [
        {
            "ioc_value": "amaniza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063860": [
        {
            "ioc_value": "microcloud.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063861": [
        {
            "ioc_value": "anexuss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063862": [
        {
            "ioc_value": "edictsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063863": [
        {
            "ioc_value": "out1etshops.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063851": [
        {
            "ioc_value": "stepnbayac.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063852": [
        {
            "ioc_value": "chickenpoken.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063853": [
        {
            "ioc_value": "hockeysmall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063854": [
        {
            "ioc_value": "orthodoxok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063855": [
        {
            "ioc_value": "cocesovo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063856": [
        {
            "ioc_value": "familyinsurancepartner.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063857": [
        {
            "ioc_value": "senebuvuyi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063848": [
        {
            "ioc_value": "fincheck.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063849": [
        {
            "ioc_value": "svchosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063850": [
        {
            "ioc_value": "conhosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063843": [
        {
            "ioc_value": "maximumservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063844": [
        {
            "ioc_value": "conferencedesk.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063845": [
        {
            "ioc_value": "bluetechsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063846": [
        {
            "ioc_value": "allgroupservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063847": [
        {
            "ioc_value": "acitopram.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063838": [
        {
            "ioc_value": "businessservicesolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063839": [
        {
            "ioc_value": "gravyblicus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063840": [
        {
            "ioc_value": "firmwarekey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063841": [
        {
            "ioc_value": "updateraccount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063842": [
        {
            "ioc_value": "mvnetworking.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-07-21 17:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063832": [
        {
            "ioc_value": "avasecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063833": [
        {
            "ioc_value": "extranetserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063834": [
        {
            "ioc_value": "clacem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063835": [
        {
            "ioc_value": "eonline-cdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063836": [
        {
            "ioc_value": "cagohufe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063837": [
        {
            "ioc_value": "vezawahoy.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063826": [
        {
            "ioc_value": "tetafup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063827": [
        {
            "ioc_value": "api-trend-micro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063828": [
        {
            "ioc_value": "digital-hardware.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063829": [
        {
            "ioc_value": "aboutdatabasesoftware.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063830": [
        {
            "ioc_value": "high-control.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063831": [
        {
            "ioc_value": "soft-base.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063821": [
        {
            "ioc_value": "iptvr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063823": [
        {
            "ioc_value": "mingw.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063824": [
        {
            "ioc_value": "transfercloud.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063825": [
        {
            "ioc_value": "flashcom.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063818": [
        {
            "ioc_value": "sciencelifedata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063819": [
        {
            "ioc_value": "bookingsupport.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063820": [
        {
            "ioc_value": "ateyakima.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063813": [
        {
            "ioc_value": "buy1walmart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063816": [
        {
            "ioc_value": "drbeat.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063817": [
        {
            "ioc_value": "aialadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063810": [
        {
            "ioc_value": "hhkj222.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063811": [
        {
            "ioc_value": "yw2204.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063812": [
        {
            "ioc_value": "nordicqlobal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063806": [
        {
            "ioc_value": "favls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-07-21 17:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063807": [
        {
            "ioc_value": "linkkedin.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-07-21 17:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063808": [
        {
            "ioc_value": "magellanfit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-07-21 17:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063805": [
        {
            "ioc_value": "afspd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:03",
            "last_seen_utc": "2026-07-21 17:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063804": [
        {
            "ioc_value": "164.92.70.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:46:51",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063802": [
        {
            "ioc_value": "abritrum-bridges.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:44:07",
            "last_seen_utc": "2026-07-21 17:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063208": [
        {
            "ioc_value": "a.wv2022.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 19:56:09",
            "last_seen_utc": "2026-07-21 17:42:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1063123": [
        {
            "ioc_value": "apacheorg.wiki",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 02:22:09",
            "last_seen_utc": "2026-07-21 17:42:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDIE-AS-AP Cloudie Limited,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1062406": [
        {
            "ioc_value": "updatemicrotok.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-24 19:00:50",
            "last_seen_utc": "2026-07-21 17:42:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-SERVERION,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1053949": [
        {
            "ioc_value": "eserverx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 21:43:42",
            "last_seen_utc": "2026-07-21 17:43:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1050306": [
        {
            "ioc_value": "cmdatabase.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 11:41:44",
            "last_seen_utc": "2026-07-21 17:42:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ADM Service Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1050198": [
        {
            "ioc_value": "cloudmane.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-17 12:12:59",
            "last_seen_utc": "2026-07-21 17:43:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1036758": [
        {
            "ioc_value": "8.212.49.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-13 11:43:38",
            "last_seen_utc": "2026-07-21 17:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Alibaba (US) Technology Co. Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1036111": [
        {
            "ioc_value": "qw.conhoosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-12 01:38:31",
            "last_seen_utc": "2026-07-21 17:43:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1035723": [
        {
            "ioc_value": "expoglobalservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-08 20:45:56",
            "last_seen_utc": "2026-07-21 17:43:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TIER-NET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1035558": [
        {
            "ioc_value": "www.microsofer.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-07 20:05:59",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1031731": [
        {
            "ioc_value": "googlecontentuser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 20:03:53",
            "last_seen_utc": "2026-07-21 17:43:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/TheDFIRReport/status/1599780643222654976",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1031726": [
        {
            "ioc_value": "test.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 19:27:32",
            "last_seen_utc": "2026-07-21 17:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YISUCLOUDLTD-HK YISU CLOUD LTD",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1029025": [
        {
            "ioc_value": "palalto.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 11:42:38",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028963": [
        {
            "ioc_value": "esoftwareupdates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-04 20:18:27",
            "last_seen_utc": "2026-07-21 17:43:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASGHOSTNET,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028767": [
        {
            "ioc_value": "globalplayservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 21:28:11",
            "last_seen_utc": "2026-07-21 17:43:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028737": [
        {
            "ioc_value": "rapidfinact.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:50:52",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SHINJIRU-MY-AS-AP Shinjiru Technology Sdn Bhd",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028720": [
        {
            "ioc_value": "globalsteamclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:38:18",
            "last_seen_utc": "2026-07-21 17:43:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028501": [
        {
            "ioc_value": "get-music-online.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-01 20:32:20",
            "last_seen_utc": "2026-07-21 17:43:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1024554": [
        {
            "ioc_value": "msndla.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-27 16:10:54",
            "last_seen_utc": "2026-07-21 17:43:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1023854": [
        {
            "ioc_value": "childhealthresources.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:54:46",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1023821": [
        {
            "ioc_value": "360safeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:50:52",
            "last_seen_utc": "2026-07-21 17:43:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1021044": [
        {
            "ioc_value": "aksaholdings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-20 10:32:06",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1012628": [
        {
            "ioc_value": "msisfx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-15 06:56:25",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/malware_traffic/status/1592262598195646464",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1009773": [
        {
            "ioc_value": "get-smartbuyer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-12 17:46:46",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1000509": [
        {
            "ioc_value": "qw.stakcl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-10 11:51:33",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "991420": [
        {
            "ioc_value": "sogouupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-08 20:20:30",
            "last_seen_utc": "2026-07-21 17:43:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "985010": [
        {
            "ioc_value": "dnsupdatecheck.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-07 20:10:29",
            "last_seen_utc": "2026-07-21 17:43:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "973832": [
        {
            "ioc_value": "ipulsecloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-04 11:23:08",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "964538": [
        {
            "ioc_value": "zadiguser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964540": [
        {
            "ioc_value": "wasazokiwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964541": [
        {
            "ioc_value": "yuwajeni.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964542": [
        {
            "ioc_value": "yavahiyil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964543": [
        {
            "ioc_value": "rabihino.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964545": [
        {
            "ioc_value": "nokevohoh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964546": [
        {
            "ioc_value": "rawocav.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964548": [
        {
            "ioc_value": "deyikurihe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "952862": [
        {
            "ioc_value": "freshuper.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-30 19:51:44",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,tzulo inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952596": [
        {
            "ioc_value": "reebons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:32:13",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952587": [
        {
            "ioc_value": "gaswert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:23:49",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952582": [
        {
            "ioc_value": "sajij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 11:54:42",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952555": [
        {
            "ioc_value": "asasyz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:14:36",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952552": [
        {
            "ioc_value": "agazud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:12:26",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LLC Baxet",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952534": [
        {
            "ioc_value": "tuuik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:57:36",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952528": [
        {
            "ioc_value": "alfuhin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:56:46",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "950974": [
        {
            "ioc_value": "amaladin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-27 23:43:27",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "949937": [
        {
            "ioc_value": "aualadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-26 10:09:11",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916136": [
        {
            "ioc_value": "bthserv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:42:10",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Internet Solutions & Innovations LTD.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916115": [
        {
            "ioc_value": "nuesro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:37:35",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916100": [
        {
            "ioc_value": "pasadonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:36:50",
            "last_seen_utc": "2026-07-21 17:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915911": [
        {
            "ioc_value": "worldsgates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:40:40",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LUCIDACLOUD LIMITED",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915908": [
        {
            "ioc_value": "protramal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:39:30",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915846": [
        {
            "ioc_value": "spltst.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 01:11:02",
            "last_seen_utc": "2026-07-21 17:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,combahton GmbH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "891477": [
        {
            "ioc_value": "cehocihit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 13:10:54",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "891461": [
        {
            "ioc_value": "cloudmicro.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 12:38:04",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "887212": [
        {
            "ioc_value": "keycloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:41:28",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PARTNER-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886703": [
        {
            "ioc_value": "activeservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:13:41",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amati Foundation,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886693": [
        {
            "ioc_value": "newyearbalance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:12:51",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886516": [
        {
            "ioc_value": "xamayojir.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:02:36",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886499": [
        {
            "ioc_value": "xicefoga.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 20:58:25",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-WDC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "884091": [
        {
            "ioc_value": "ams-prd-cob.nl",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:51:56",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883488": [
        {
            "ioc_value": "tagujog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:35:22",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883412": [
        {
            "ioc_value": "mysqlserver.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:32:23",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ICME",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883142": [
        {
            "ioc_value": "xuluxetas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:23:44",
            "last_seen_utc": "2026-07-21 17:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-NYC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "880419": [
        {
            "ioc_value": "hadujaza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-12 17:16:11",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.trendmicro.com/en_us/research/22/j/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "871733": [
        {
            "ioc_value": "softsupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-07-21 17:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "871734": [
        {
            "ioc_value": "anushl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858399": [
        {
            "ioc_value": "anbush.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858402": [
        {
            "ioc_value": "get-topservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858403": [
        {
            "ioc_value": "msoftupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858404": [
        {
            "ioc_value": "pregabas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-07-21 17:43:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "851096": [
        {
            "ioc_value": "34.92.131.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-22 11:26:18",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Google LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "850706": [
        {
            "ioc_value": "87.246.7.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:58:14",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850701": [
        {
            "ioc_value": "cloudmicro.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850702": [
        {
            "ioc_value": "fregiyu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850704": [
        {
            "ioc_value": "microcloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-07-21 17:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850260": [
        {
            "ioc_value": "154.22.117.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-17 21:24:41",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Cogent Communications",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "849761": [
        {
            "ioc_value": "198.98.53.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-14 22:07:14",
            "last_seen_utc": "2026-07-21 17:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "847988": [
        {
            "ioc_value": "globallookclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:52",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847986": [
        {
            "ioc_value": "realfunsolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:50",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847972": [
        {
            "ioc_value": "www.service1app.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847975": [
        {
            "ioc_value": "youronlinesports.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847976": [
        {
            "ioc_value": "yourinfosolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847978": [
        {
            "ioc_value": "login.onemusic24.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847981": [
        {
            "ioc_value": "zx.jacollans.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847942": [
        {
            "ioc_value": "satorkar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847943": [
        {
            "ioc_value": "er.theinfoinc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847957": [
        {
            "ioc_value": "realmacnow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847958": [
        {
            "ioc_value": "onemusicllc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847959": [
        {
            "ioc_value": "ateliernow.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847960": [
        {
            "ioc_value": "er.dropklant.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847929": [
        {
            "ioc_value": "sprinthunter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847930": [
        {
            "ioc_value": "newstamagavk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-07-21 17:43:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847934": [
        {
            "ioc_value": "www.onestepstar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-07-21 17:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847124": [
        {
            "ioc_value": "115.75.66.68:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:17",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847123": [
        {
            "ioc_value": "115.75.66.68:6821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:16",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847122": [
        {
            "ioc_value": "115.75.66.68:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:14",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847121": [
        {
            "ioc_value": "115.75.66.68:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:40:24",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847028": [
        {
            "ioc_value": "barabezo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 18:29:19",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/08ec3f13e8637a08dd763af6ccb46ff8516bc46efaacb1e5f052ada634a90c0e/",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847018": [
        {
            "ioc_value": "alojun.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847019": [
        {
            "ioc_value": "asdder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-07-21 17:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847020": [
        {
            "ioc_value": "www.zominoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "846258": [
        {
            "ioc_value": "jevomukif.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-30 06:22:11",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-29-IOCs-for-Monster-Libra-TA551-IcedID-with-Cobalt-Stike.txt",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "844214": [
        {
            "ioc_value": "msdnupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-07-21 17:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "844215": [
        {
            "ioc_value": "msdupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "843958": [
        {
            "ioc_value": "caxoxc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-18 12:15:06",
            "last_seen_utc": "2026-07-21 17:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "843546": [
        {
            "ioc_value": "47.108.180.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-16 11:38:21",
            "last_seen_utc": "2026-07-21 17:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "842464": [
        {
            "ioc_value": "jahojahi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-11 06:03:19",
            "last_seen_utc": "2026-07-21 17:43:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-10-IOCs-for-IcedID-and-Cobalt-Strike.txt",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "841613": [
        {
            "ioc_value": "zambeziz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-06 07:00:06",
            "last_seen_utc": "2026-07-21 17:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltSrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "839793": [
        {
            "ioc_value": "zuyonijobo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-27 08:49:04",
            "last_seen_utc": "2026-07-21 17:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://isc.sans.edu/diary/28884",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "802793": [
        {
            "ioc_value": "digerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-06 05:36:04",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "796822": [
        {
            "ioc_value": "chitozx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-05 05:12:06",
            "last_seen_utc": "2026-07-21 17:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "750750": [
        {
            "ioc_value": "42.192.21.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-02 13:06:49",
            "last_seen_utc": "2026-07-21 17:43:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "730561": [
        {
            "ioc_value": "18.117.254.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-28 08:57:21",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "729038": [
        {
            "ioc_value": "blinkinuf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:33",
            "last_seen_utc": "2026-07-21 17:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "729037": [
        {
            "ioc_value": "malrok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:32",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720823": [
        {
            "ioc_value": "trumpiko.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720824": [
        {
            "ioc_value": "freygor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-07-21 17:43:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720826": [
        {
            "ioc_value": "sinjoan.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720827": [
        {
            "ioc_value": "afluix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720273": [
        {
            "ioc_value": "www.edge-chrome.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720276": [
        {
            "ioc_value": "www.hellomrsone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720260": [
        {
            "ioc_value": "we.topsmartservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720263": [
        {
            "ioc_value": "wpsserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720248": [
        {
            "ioc_value": "thedaily-news.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:18",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720239": [
        {
            "ioc_value": "sevenhungredbucks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720241": [
        {
            "ioc_value": "snccoupr-int.cf",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720247": [
        {
            "ioc_value": "telembank.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-07-21 17:43:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720230": [
        {
            "ioc_value": "ppew.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720231": [
        {
            "ioc_value": "pretunz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720236": [
        {
            "ioc_value": "rss.top-business-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720237": [
        {
            "ioc_value": "scarfaceserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720226": [
        {
            "ioc_value": "outlet-studio.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:15",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720208": [
        {
            "ioc_value": "js.msedgeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:14",
            "last_seen_utc": "2026-07-21 17:42:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720198": [
        {
            "ioc_value": "harborfreight.delivery",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-07-21 17:43:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720201": [
        {
            "ioc_value": "hityok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720203": [
        {
            "ioc_value": "jiguz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720204": [
        {
            "ioc_value": "jijuanjo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720206": [
        {
            "ioc_value": "jqueryupdatenow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720207": [
        {
            "ioc_value": "jqueryupneed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720188": [
        {
            "ioc_value": "fifacud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720189": [
        {
            "ioc_value": "filaspo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720193": [
        {
            "ioc_value": "gasienda.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720185": [
        {
            "ioc_value": "dreamkoks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:11",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720176": [
        {
            "ioc_value": "democrazzy.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:10",
            "last_seen_utc": "2026-07-21 17:43:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720156": [
        {
            "ioc_value": "cloud.sovarermscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:31",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720136": [
        {
            "ioc_value": "backupcreds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720140": [
        {
            "ioc_value": "biohazzzard.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-07-21 17:43:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720141": [
        {
            "ioc_value": "bksfinance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720143": [
        {
            "ioc_value": "boronab.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-07-21 17:43:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720132": [
        {
            "ioc_value": "araizx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-07-21 17:43:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720133": [
        {
            "ioc_value": "arminext.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "719898": [
        {
            "ioc_value": "aginij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-22 18:35:13",
            "last_seen_utc": "2026-07-21 17:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "606362": [
        {
            "ioc_value": "criobob.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-07-21 17:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606363": [
        {
            "ioc_value": "prozakx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606364": [
        {
            "ioc_value": "terroklo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606360": [
        {
            "ioc_value": "microdozz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:57",
            "last_seen_utc": "2026-07-21 17:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "549372": [
        {
            "ioc_value": "us189-hpgsgae5dva9fzch.z01.azurefd.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-10 18:53:07",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,threatview.io",
            "anonymous": 0,
            "reporter": "Malwar3Ninja"
        }
    ],
    "548951": [
        {
            "ioc_value": "artidomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-08 16:20:03",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/ian_kenefick/status/1523288477559062529",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "544836": [
        {
            "ioc_value": "116.62.185.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-30 19:45:18",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "540702": [
        {
            "ioc_value": "165.227.180.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-29 19:30:18",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "532916": [
        {
            "ioc_value": "120.26.240.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-25 12:31:07",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "530098": [
        {
            "ioc_value": "193.29.13.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-23 16:42:50",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "***************************************,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "523516": [
        {
            "ioc_value": "45.8.158.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-21 16:54:57",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASBAXETN,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "521565": [
        {
            "ioc_value": "115.29.171.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-19 13:44:33",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "521083": [
        {
            "ioc_value": "84.32.188.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-18 18:01:52",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "520317": [
        {
            "ioc_value": "137.184.42.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-15 22:57:51",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "519914": [
        {
            "ioc_value": "84.32.188.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 16:59:25",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "519792": [
        {
            "ioc_value": "furfen.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 10:30:57",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BumbleBee,Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "519116": [
        {
            "ioc_value": "175.41.21.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-13 16:57:52",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "518853": [
        {
            "ioc_value": "175.41.16.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-12 16:50:58",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "518404": [
        {
            "ioc_value": "138.68.110.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-10 17:05:31",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "516676": [
        {
            "ioc_value": "13.55.118.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-06 22:59:35",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "493695": [
        {
            "ioc_value": "185.186.143.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 22:55:20",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASKONTEL,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "492845": [
        {
            "ioc_value": "194.37.97.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 16:53:16",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247 Ltd",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "466600": [
        {
            "ioc_value": "blopik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-30 09:51:36",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "461231": [
        {
            "ioc_value": "borizhog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-29 08:36:59",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "448027": [
        {
            "ioc_value": "37.72.172.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 22:55:12",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "446029": [
        {
            "ioc_value": "1.14.76.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 10:56:07",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "443786": [
        {
            "ioc_value": "139.60.160.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 20:44:05",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "443190": [
        {
            "ioc_value": "apeduze.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 16:44:21",
            "last_seen_utc": "2026-07-21 17:43:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "438442": [
        {
            "ioc_value": "drimzis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "438443": [
        {
            "ioc_value": "blinkij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "398650": [
        {
            "ioc_value": "152.136.178.142:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 22:47:07",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "396104": [
        {
            "ioc_value": "dunclikf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 12:19:46",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393426": [
        {
            "ioc_value": "sifgu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393427": [
        {
            "ioc_value": "gfsert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393429": [
        {
            "ioc_value": "shizij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393430": [
        {
            "ioc_value": "zxerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393431": [
        {
            "ioc_value": "korunder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393424": [
        {
            "ioc_value": "chesft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393425": [
        {
            "ioc_value": "uktyl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-07-21 17:43:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393312": [
        {
            "ioc_value": "defenr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393313": [
        {
            "ioc_value": "fedij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393314": [
        {
            "ioc_value": "kejimn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393311": [
        {
            "ioc_value": "brikeb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:34",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393046": [
        {
            "ioc_value": "kapuleti.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-08 17:09:32",
            "last_seen_utc": "2026-07-21 17:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "392705": [
        {
            "ioc_value": "45.12.1.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-06 16:43:33",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "392630": [
        {
            "ioc_value": "45.12.1.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:45:53",
            "last_seen_utc": "2026-07-21 17:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "392595": [
        {
            "ioc_value": "45.12.1.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:43:28",
            "last_seen_utc": "2026-07-21 17:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDNETWORKS-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "391528": [
        {
            "ioc_value": "defegh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391530": [
        {
            "ioc_value": "klycnmik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391531": [
        {
            "ioc_value": "ngrety.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-07-21 17:43:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391111": [
        {
            "ioc_value": "lifegothistory.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-27 06:03:58",
            "last_seen_utc": "2026-07-21 17:43:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1497771037718724612",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "390123": [
        {
            "ioc_value": "192.241.133.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:44:41",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "390104": [
        {
            "ioc_value": "159.65.246.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:42:29",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389873": [
        {
            "ioc_value": "68.183.200.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:58:18",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389866": [
        {
            "ioc_value": "138.68.227.71:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:57:13",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389865": [
        {
            "ioc_value": "165.227.219.211:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:56:32",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389864": [
        {
            "ioc_value": "165.232.154.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:55:44",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389861": [
        {
            "ioc_value": "143.198.110.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:53",
            "last_seen_utc": "2026-07-21 17:43:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389860": [
        {
            "ioc_value": "178.128.171.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:15",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389853": [
        {
            "ioc_value": "165.227.23.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:53:10",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389850": [
        {
            "ioc_value": "161.35.137.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:52:19",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389847": [
        {
            "ioc_value": "64.227.0.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:51:26",
            "last_seen_utc": "2026-07-21 17:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389656": [
        {
            "ioc_value": "45.55.36.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-20 16:42:59",
            "last_seen_utc": "2026-07-21 17:43:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "384626": [
        {
            "ioc_value": "168.61.180.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-09 22:36:37",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "373668": [
        {
            "ioc_value": "bornometa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "373671": [
        {
            "ioc_value": "jenevabaiden.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "373673": [
        {
            "ioc_value": "sbronm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "362296": [
        {
            "ioc_value": "101.34.182.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-29 22:33:30",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "332687": [
        {
            "ioc_value": "192.227.155.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:30:16",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "332653": [
        {
            "ioc_value": "146.70.29.233:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:29:00",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "313943": [
        {
            "ioc_value": "107.172.219.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-22 22:25:42",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "299262": [
        {
            "ioc_value": "193.201.9.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 22:32:52",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SELECTEL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "298501": [
        {
            "ioc_value": "citrixseruritys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "298505": [
        {
            "ioc_value": "milanvar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-07-21 17:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "295525": [
        {
            "ioc_value": "23.227.198.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 22:26:20",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "295436": [
        {
            "ioc_value": "217.79.243.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 10:32:22",
            "last_seen_utc": "2026-07-21 17:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "295353": [
        {
            "ioc_value": "149.255.35.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-14 22:28:25",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "294999": [
        {
            "ioc_value": "81.68.225.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-13 22:28:33",
            "last_seen_utc": "2026-07-21 17:43:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "292303": [
        {
            "ioc_value": "39.98.48.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-10 16:24:49",
            "last_seen_utc": "2026-07-21 17:42:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "291740": [
        {
            "ioc_value": "39.104.25.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-07 10:30:52",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "276593": [
        {
            "ioc_value": "77.83.36.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-16 10:42:30",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ISI-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "275144": [
        {
            "ioc_value": "101.32.204.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-13 10:06:28",
            "last_seen_utc": "2026-07-21 17:43:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "252110": [
        {
            "ioc_value": "62.113.255.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-22 16:01:01",
            "last_seen_utc": "2026-07-21 17:43:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TTM",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "242948": [
        {
            "ioc_value": "107.173.89.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-04 17:48:48",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "240983": [
        {
            "ioc_value": "104.128.92.144:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-31 17:43:37",
            "last_seen_utc": "2026-07-21 17:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,IT7NET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "238207": [
        {
            "ioc_value": "fivepointschiro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-27 09:58:20",
            "last_seen_utc": "2026-07-21 17:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/mojoesec/status/1453040284686770185",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "236436": [
        {
            "ioc_value": "111.230.196.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-22 12:07:15",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "233476": [
        {
            "ioc_value": "23.224.152.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-13 17:43:22",
            "last_seen_utc": "2026-07-21 17:43:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "232821": [
        {
            "ioc_value": "139.198.183.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-11 23:27:10",
            "last_seen_utc": "2026-07-21 17:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YUNIFY-NET Yunify Technologies Inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "232263": [
        {
            "ioc_value": "121.37.255.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-09 23:36:53",
            "last_seen_utc": "2026-07-21 17:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HWCSNET Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "223357": [
        {
            "ioc_value": "47.95.207.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-09-18 17:39:24",
            "last_seen_utc": "2026-07-21 17:43:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ]
}